Online and Digital Identification, Securing Web 2.0, PKI and Digital Certificates

EMV hack may be overstated

Monday, February 15, 2010

Researchers at the University of Cambridge in the UK released a report claiming to have identified vulnerabilities with the EMV payment scheme. Industry organizations are meanwhile defending the technology, saying the hack would be difficult to pull off in the real world.

The attack uses a fake chip card connected with wires to custom electronics, a computer with specially designed software, and a stolen EMV chip & PIN card. The fake card and equipment sit between the stolen card and the point-of-sale terminal; the attack fools the terminal into thinking that the correct PIN had been presented and makes the stolen card believe that no PIN was required.




The Smart Card Alliance has reviewed the hack along with other industry organizations and concluded that widespread implementation of this attack is unlikely and that there is no evidence that the attack described has happened in the real world.


These conclusions are supported by the following points:

  • The attack requires the use of a stolen EMV card that has not yet been reported as stolen; this limits the scalability of this type of fraud since it must be done with one card at a time and in a potentially short window of time.
  • The combination fake card and stolen chip & PIN card cannot be used in an ATM for a cash withdrawal, as ATMs rely on an online PIN verification.
  • The fraud requires using a fake chip card with wires coming out of it, running up the sleeve of the fraudster and connecting to a hidden circuit board, computer and stolen EMV card, making detection likely at an attended merchant point-of-sale.
  • The attack is technically difficult, requiring highly sophisticated software and customized hardware that could only be created by individuals with extensive knowledge of EMV protocols.
  • Countermeasures are already available, either in EMV, within payment system products and networks, or within issuer host systems.
  • Electronic audits of data from suspected transactions would protect cardholders and merchants from responsibility for fraudulent charges made to their card with this type of attack, if reported properly.

Additionally, such an attack would not compromise the smart card as the PIN would still remain secure inside the card. [end] 

StarChip and CEA-Leti have inked a partnership agreement to develop a contactless front end for smart card applications.

The partnership includes technology and know-how transfer to StarChip. With this combined experience in secure integrated circuit development and contactless technology, StarChip will roll out state-of-the-art smart card products to enable applications in transport, banking and identity.

read more »

In an effort to reduce fraud, the Association of Banks in Singapor announced that it has set guidelines regarding the implementation of smart chips in ATM cards in Singapore.

read more »

Credit Agricole, a retail banking group based in Paris, is teaming up with Gemalto to launch a large-scale deployment of contactless EMV banking cards in France.

read more »

XDA-Developers, an online community of Android and Windows Phone enthusiasts and developers, has uncovered a way to get Google Wallet on Google’s new Galaxy Nexus handset – no hacking required, according to the International Business Times.

read more »

Gemalto announced that 10 million Financial Inclusion Network & Operations (FINO) customers in India now benefit and take part in micro-banking, using Gemalto smart cards, as part of FINO’s broader branchless banking program.

read more »

Javelin Strategy & Research has released a report detailing the latest trends that are expected to transform the banking, payments, mobile and security sector for 2012.

read more »