"Alex" wrote
Even if their (potential) customers go somewhere else instead, which *does* use the shielding? Just because the first merchant didn't "like" it? Seems silly business sense to me...
"Alex" wrote
Even if their (potential) customers go somewhere else instead, which *does* use the shielding? Just because the first merchant didn't "like" it? Seems silly business sense to me...
Then the trader carries the risk. Well, perhaps the trader carries the risk even with physical goods delivered to registered address, I don't know, but the risk in that case is certainly smaller.
It's understandable that purveyors of intangibles are not too fussed about carrying higher risk, since software costs virtually nothing to copy, and any thief who would hire web space or domain names he actually wanted to use for any length of time, would be a fool to pay for it with a dodgy card, since the sale would be charged back to the merchant, who would then simply repossess the space/name.
Question is: Is it impossible to clone a new type Chip and PIN Card? For instance, the new type CHIP card will retain a Magstrip. Therefore these cards can still be cloned. This is concerning because shortly there will be millions of high value credit cards that will be targetted. Why? Get hold of a PIN with one of these cloned cards and in theory it could be used at non-chip compliant cash machines at home or abroad.
James.
"Alex" wrote
Can you read the contents of a mag stripe with your naked eye (ie without a machine to help) ? I guess not! Ergo, there *is* an element of encryption on a mag stripe ... the data is "encrypted" into magnetic pulses...
Without a hint of irony, snipped-for-privacy@tiscali.co.uk (James) astounded uk.finance on 21 Apr 2004 by announcing:
No. It's currently impractical, however. A bit like cloning DVDs used to be impractical when the cost of the writer was several thousands of pounds and, more importantly, the cost of the media was over twice as much as the cost of the film you were copying.
It is just as easy as it was to clone the MSR tracks, however. This is not a weakness of EMV, but of the original technology.
That's not encryption, that's obfuscation.
Neil
"Neil Jones" wrote
Tee hee. And there was me thinking that obfuscation was simply a form of encryption.
What is unique about "encryption" that is not found in "obfuscation" ?
They used to be, encrypted with a key which was inside every ATM...
I think they moved away from that scheme before the fact became known.
It could get written to the card next time you use it.
Actually, every smart card controller chip ever made has been cracked.
Obfuscation means it is just harder than normal to read, but it's still there unaltered.
With enryption you typically use a key to scramble it so that you need to decrypt it before it can be read.
Nah. That's encoding, not encrypting. The difference is that encrypting is a *cryptic* form of encoding.
So if you come across something like the mild form of "encryption" Fb vs lbh pbzr npebff fbzrguvat yvxr gur zvyq sbez bs "rapelcgvba" known as rot-13, it lacks cryptic subtlety to the extent that you xabja nf ebg-13, vg ynpxf pelcgvp fhogyrgl gb gur rkgrag gung lbh may as well just call it an encoding. znl nf jryy whfg pnyy vg na rapbqvat.
On the other hand, a subtle modification makes it rather more Bb ixv gmbzn eymd, b uxfyrl uxntrvqpjzgg gvgbq ht scwljx twao challenging to see what the **** is going on. Can you guess it? ntnzaueybhb pl qde xjdx ynl **** qb qzuau dd. Tsg sjq dsdst kw?
"Neil Jones" wrote
But also with encryption, surely the data is still there "unaltered" (albeit in a form which is coded in a different manner to usual - which is the same case with obfuscation) - and is also "harder than normal to read" (you *can* read it if you know/guess the key).
"Neil Jones" wrote
And again, with any form of obfuscation some "method" / "algorithm" / "key" has been used to scramble the data - which then needs to be "decrypted" (unscrambled) before it can be read. [Any simple algorithm or method being classed as a "key" to the data.]
Where exactly is the difference between the two?
Indeed and that appears to be whats going to happen with C&P.
Seems that PINS went from cards to computers and now back to cards (with the computer also knowing)
"obfuscation" ?
"decrypted"
The basic difference is that enryption involves a 'secret' (ie the key) which obfuscation doesn't.
encrypting
Rot-(n(i) = n(i-1)+1; n(1))?
>
"Ronald Raygun" wrote
vvvv Original letter vvvv A B C D E F G H I J K L M N O P Q R S T U V W X Y Z N O P Q R S T U V W X Y Z A B C D E F G H I J K L M ^^^^ Encrypted (encoded) letter ^^^^
"Ronald Raygun" wrote
Easy - just "roll-on" the key by one letter after you've used it each time. In effect, the key for the 27th letter is the same as the key for the 1st letter, but the key changes from each letter encoded as follows :-
Original letter: A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
1st Encrypted (encoded) letter: N O P Q R S T U V W X Y Z A B C D E F G H I J K L M 2nd Encrypted (encoded) letter: O P Q R S T U V W X Y Z A B C D E F G H I J K L M N 3rd Encrypted (encoded) letter: P Q R S T U V W X Y Z A B C D E F G H I J K L M N O 4th Encrypted (encoded) letter: Q R S T U V W X Y Z A B C D E F G H I J K L M N O P... and so on.
Both of your methods are certainly obfuscation. I would also call them encryption!
They are - they use different algorithms but the key is the same in each case (13).
rot-13 is encryption of a very simple kind with a very well known 'secret'.
"Neil Jones" wrote
Doesn't obfuscation *also* involve some sort of "method" or "algorithm" (in effect, a "key"!) to get from plain data to obfuscated data? If there is no system used to transform the plain data into obfuscated data, then the obfuscated data must necessarily be the same as the plain data.
If you don't know the method used to obfuscate, then you can't convert it back into original data. The method used *is* the key!
So, it must come down to the level of "secrecy" involved. Do you class a system as "obfuscation" if it is easy to guess the system, and "encryption" if you think it's difficult to guess?? Or do you have some other distinction?
"algorithm" (in
"encryption"
The difference between the algorithm and the key is that once the algorithm is known it can be applied to all messages. If there is no key involved as well, all the messages become readable.
Suppose the chosen method to convey a secret message is to tattoo it on the head of a slave, allow him to grown his hair and then send him to the recipient. Once the enemy discovers how you are getting your messages across (the algorithm) he intercepts all your slaves, shaves their heads and reads all your messages.
Instead, let's send each slave with letters which have been encrypted with the same algorithm but different keys. The enemy manages to intercept the first and crack it (he is lucky and guesses the key), but it doesn't give him any ability to read the subsequent messages because without the key he can't decrypt them.
Neil
Have something to add? Share your thoughts — no account required.
Ask the community — no account required