Saw this item in an australian newspaper
Chip & Pin problems?
In message , Jonathan Bryce writes
If you read the article it only refers to magstripe technology and its reference to Uk is when magstripe users from ozz are using their magstripe cards with PIN here.
This isnt a C&P problem, its an old technology problem. Thats why we now have C&P in UK.
It's neither C&P nor magnetic stripe problem. Equally, it is neither Canadian nor UK problem. The third party (OfficeMax say it were not them) stored encrypted PIN data plus decryption keys when they were not allowed to. The payment system have been broken into, giving away the info that should had been erased.
The original article was in NY Times: There was another one in Russian news.
Vadim
At 01:12:24 on 14/03/2006, Vadim Borshchev delighted uk.finance by announcing:
Then it *is* a magnetic stripe problem. Decryption keys in C&P are stored in only two places; on the card and in the bank's HSM, never by a third party.
Alex you wrote "...Decryption keys in C&P are stored in only two places; on the card and in the bank's HSM, never by a third party."
I agree with you on the HSM part. For the IC are you talking about the Issuer's key used during SDA or DDA ?
What's your definition of a 3rd party? Because I can think of 3rd party embossers having to have the issuers crypto keys to encrypt the IC.
Also crypto keys are stored at the payment scheme level as well, for example: Acquirer/Issuer Working Keys and what about the ZMK that's used between two entities sharing information?
At 09:05:16 on 17/03/2006, snipped-for-privacy@zeda.co.uk delighted uk.finance by announcing:
In the context of the post, I'm referring to the banks' PEKs.
Join the Discussion
Have something to add? Share your thoughts — no account required.
Didn't find your answer?
Ask the community — no account required