I can't read anymore. Is there anymore technical explanation?
Was it actually 'printed' ... on paper?
Was it even an actual encryption key or just a password or something?
I can't read anymore. Is there anymore technical explanation?
Was it actually 'printed' ... on paper?
Was it even an actual encryption key or just a password or something?
What it means is that the master secret in the HSM is probably a 128bit AES key. The ways to generate this depend on the ceremony and the particular HSM, but the risk I have encountered in security consulting is the question of whether that master secret itself was just derived from simple components, like pbkdf2("secret phrase known to 3 people", 1000)
The consequence of compromising that key is that an attacker could use it to forge cards, or more usefully, instantiate a virtual card in software to fuzz cryptograms for different account numbers to get available balance information and then personalize cards for those.
> The advantage is that any security issues of USB interfaces or cameras are completely avoided.
There's also the section that enumerates all the downsides for each medium of storage: https://en.bitcoin.it/wiki/Cold_storage#Private_key_backup_s...
This is a huge failure.
So just exporting the private key so easily without some pretty involved hight-tech HSM key extraction sounds insane.
https://www.cloudflare.com/dns/dnssec/root-signing-ceremony/
They have a page for each signing ceremony:
https://www.iana.org/dnssec/ceremonies/41
With a script of everything done:
Because losing these keys can be very, very, very expensive.
For an example (somewhat similar to this Postbank case) see India Cosmos Bank 2018 incident (https://www.reuters.com/article/cyber-heist-india-idUSL4N1V5... is one link) where criminals generated fake cards to cash out some $13 million; and replacing 12M bank cards also has an huge cost to replace the cards (perhaps roughly $12M - $1 per card replacement is plausible though possibly on the cheap side) even if we ignore the reputation cost.
It was not for security. Ever.
Credit Cards were introduced as a less-secure-but-more-convenient-check.
The store then would have a stock of "blank checks" with absolutely no security features where they would imprint with carbon paper and a pressure roll the credit card information and pretty much "mint" the client a check on the spot.
Over time the raised letters for the crude minting press morphed into a magnetic strip, but the process was still 100% the same. Outside of the US in the last decade (2yrs in the US) some little security was added with encryption keys and PINs. Which is nothing more than a digital signature the bank may or may not check (like it did with the actual signature on the previous mentioned blank checks minted by the store). This is the step that was compromised with the stolen keys. In other words, the few places where you have to insert your card chip into a reader and type a pin had their security degraded to the same level as places where you simply use your magnetic strip or type your numbers on an online store.
Edit: also the pin is verified each Transaction unlike with receipt signatures, which as you say were rarely checked by anyone.
At least in my experience this has increased a great deal more in the US in recent years.
Unless something changed in the past few years, this is not the case. US debit cards are accepted through Visa or Mastercard's payment network which doesn't require a PIN (this is what it means when you process as credit in the US). Those transactions do not use the debit payment network. https://en.wikipedia.org/wiki/Interlink_(interbank_network).
EDIT: I will add that while POS systems don't have a way to do this up there, ATM's with their notoriously high fees do support cash access through a US debit card.
At the same time fees could be raised 2% for non-chip transactions to incentivize upgrades.
https://www.latimes.com/business/technology/story/2020-01-07...
I don't see a bank replacing its customers' forms of payment with a new form that isn't accepted in as many places as the old one.
Shops accepting mag stripe payments are liable for counterfeit fraud. If you use EMV (chip cards), then card brands protect you (Visa, MasterCard, etc.
You can Google it as "EMV liability shift" if you're interested in more details.
Exxon (pre-ExxonMobil) had chip-enabled pumps in the early 90's. Instead of a card, you had a little cylinder-shaped keyfob about the size of a few Tylenols strung together. I'm not sure what happened to that, I ended up moving out of an area served by Exxon.
These days I see gas pumps with the little wireless payment logo, and I have a card with the same logo, but it's never worked for me.
When NFC showed up, it was intended for plastic cards. This was pretty widely deployed. Then software companies integrated it with phones. This made the telcos unhappy, because these phones had a "secure element" that they did not control (traditionally the SIM card was the secure element, but these phones ignored that and that upset them; back then, a carrier being upset meant that your phone could not be used on their network). It also made processing networks unhappy, because they saw that they were losing control. (You don't need Mastercard and Visa when the phone can just use the Internet to ask Apple to authorize the transaction, after all.) So they flat-out stopped issuing cards with NFC. Then the final blow is that merchants were tired of paying credit card transaction fees, so they removed NFC readers from their stores, and banded together to make some shitty system to bill your purchase directly to your checking account. No more paying fees or pesky chargebacks.
The retail side blew up -- no consumer wanted it, and it was technologically bad. NFC readers are back in stores. The carrier side blew up -- SIM cards are gone and Apple or Samsung is your secure element provider. I am not sure what happened on the processing card network. I'm guessing they made some private deal with the NFC payment providers (Apple, Google, Garmin, Fitbit, etc.; enough companies in on the game that they can sit back and watch them fight each other while they profit).
I kind of got to watch this from both sides. I worked on Google Wallet when I started at Google in 2012. Used it pretty much every time I went to CVS. Then CVS removed their readers. Then Apple entered the market, and CVS once again accepts NFC cards.
So maybe gas pumps played a role; I don't drive so I don't interact with gas pumps ever. But there were much deeper problems. A lot of entrenched monopolies stood to lose a lot, so they were happy to impede progress wherever possible. There was never a good possible outcome, though -- let the incumbents keep their power, or let the upstart megacorps become the new incumbent. Plenty of VC money available if you think you can fix this problem, or become the new big guy ;)
Didn't help that thr superior user experience of NFC built into cards was drowned out by the klaxons of the media continuously warning customers of proximity theft.
Wrong threat model, the cheap mag skimmer or camera or unsecured database models were the real risks. It wasn't that someone will stand butt-to-butt with you to steal a NFC token.
You need to do a relay attack. Here's how that goes:
1. Jenny's payment card is in her jacket pocket.
2. Charlie walks into a store wearing a small NFC-capable computer and a medium distance radio (a cell phone might do) perhaps concealed inside his clothing
3. Charlie's friend Barry walks near Jenny, Barry is also wearing a similar setup to Charlie.
4. As Barry gets close to Jenny, Charlie "checks out" at the store, paying with NFC. The transaction travels from a machine near Charlie, through the radio, to Barry (now creepily close to Jenny) and then back over NFC to Jenny's card. Jenny's card agrees to the purchase - everything seems legit.
Jenny just paid for Charlie's purchases even though they've never met.
This attack isn't economically attractive because transaction sizes are limited. A complicated trick that sometimes allows you to get "free" pizza or coffee in exchange for risking time behind bars seems like a bad idea. If you could get a laptop, or a big TV then it might be more attractive, but you can't because those cost too much to allow mere NFC presence authorization.
An employee? Or the store owner?
These terminals don't offer a choice of destination bank account, if you type $16.94 into Walmart terminal and hold it near Jenny's card the card will authorize $16.94 payment... to Walmart.
For an independent merchant (including e.g. franchise operators) in some sense that's their money in the merchant account, so it makes a little bit more sense, but I still don't think it really adds up. It's like opening a bar so you can get cheap booze, the economics don't make sense.
There are opportunities for insider crooks. In the UK for example there were a rash of what are morally skimmers built into chip card terminals. Here's how that worked:
You own one or more stores with shiny new EMV payment terminals. From an instructional video you learn how to prise open a common model of terminal without setting off its tamper detection. Then you use the huge space inside the terminal left for an optional security feature (never implemented because features costs money) to add a board that taps the communication to the card and uses a cell phone connection to upload it. You seal up the tampered terminal and install it at one of your busier stores.
Customer puts their chip card in, the terminal works as expected but unknown to them your modification stores the card details and transmits them to other crooks half way around the world.
The other crooks are making old-fashioned magnetic stripe cards with details that have been uploaded. They send small fry out with these bogus cards to buy stuff in a country that doesn't have EMV yet. The stuff is fenced, and you, back in the country with EMV, get say 10% of the proceeds for your contribution to this international crime.
Some people in the UK got prison time for this. International card fraud is easier to spot (this person bought groceries just outside Luton, then forty minutes later they bought a laptop computer in Hyderabad or Houston?) but until EMV is rolled out everywhere similar tricks will be done.
First, it does not mean that you're getting any money. Such a charge is effectively "sending an invoice" to the issuing bank from the store which is supposed to have that terminal, and they will pay your merchant bank, which will give money to the institution who got issued that terminal. There's no way for the store clerk personally or someone else to get to these funds.
Second, the money is not coming today. You get an authorization message, but you'll receive the actual money later.. if ever. If the payment is disputed, you won't get that money. If it's disputed a month later, they'll take that money back from you. If many of your payments are disputed, then all your incoming funds will be frozen until they verify if all of them should be returned. If multiple payments are disputed, then the standard methods of tracing 'common point of purchase' will reveal the particular terminal as the culprit. Also, malicious merchants is a known threat, so the merchant bank will ensure that you can't just spam a day's worth of fraudulent purchases and run - standard terms will expect that some amount of money is frozen (e.g. rolling 15 days worth of transactions) so if you suddenly get a bunch of chargebacks, the customers will be paid back in full. Fake stores and shell companies are a thing, but there are reasonably effective measures to try and prevent that.
So there's no threat through collusion from a store employee - the fraudsters would get identified and would not get any money at all; and there's limited threat from collusion with a whole merchant - the fraudsters would get identified and can't get any meaningful amount of money. Extracting a couple hundred dollars could probably work - but you're "burning" the identities of multiple people and a company; the bank will 'eat' that loss if you succeed, but you can't repeat this trick.
Liability shift works like this: Historically the merchant is protected if they had good faith belief that the payment card was authorised via things like a mag stripe. After liability shift that goes away unless you use EMV. You checked the card was "real" with just a mag stripe? Not interested, the chargeback comes out of your money.
Your local gas station can keep using mag stripe readers for another decade if they like. But liability shift means places that see significant fraud will have an obvious economic incentive to go EMV, and that shifts the fraud onto nearby stations that didn't have fraud problems, so they go EMV and so on.
If you're a merchant with very low fraud rates it can make sense to do no Authorization step whatsoever. Any merchant, anywhere in the world, can do Settlement, which is the step that moves money from your account to theirs, based just on the card number. Only if it becomes a question as to whether this payment was authorized does it matter whether they did the Authorization step, a mag stripe read, the old fashioned impression machines, or a chip-and-PIN terminal.
Certain types of companies can find it makes sense to do no Authorization for groups of customers. One Click may be an example of that. You did a bunch of transactions, with a physical delivery address, what are the chances that a new transaction with the same delivery address and card details is fraud while the previous ones were not?
Yeah, no. Diners Club was the first credit card and was released in the 1950's to aggregate and streamline paying for things on account. It was, as the name suggests a line of credit. Checking accounts could become credit accounts if they allow overdrafts but this is not the normal intent.
It was not until First National of Seattle released a debit card (also now known as a check card) in 1978 that any of those plastic cards behaved as a check.
It's an important distinction because in one case (credit) the money transferred first is the bank's. This has important implications on who holds the liability and how long investigstions take into fraud allegations.
Chip security was added first overseas because online authorization was less ubiquitous. The US was able to have online terminals pretty much everywhere since the 1980's and knucklebusters became a rare sight in the 1990's. The chip security now is less to prevent card-present fraud in the US, more to prevent reauthorizations of stored CC information (see, target breach). With a chip or NFC the card generates a unique signature for every transaction so there's nothing a POS system could store to reauthorize future transactions.
This is why in the US for credit cards a pin is mostly unheard of and we are finally moving away from signatures which have been obsolete since the time offline batching mostly went away.
Edit: Consider 1980's America was under the monopoly of AT&T. This greatly influenced the design of payment card networks. Europe, for example, probably had probably over 100 different companies in dozens of countries, so universal online authorization was less feasible.
Credit cards, yes, started replacing the high APR credit-checks. And then moved to a mix of this and regular debit checks.
But the actual process, which was what i was describing, was still pretty much exactly the same used to validate a check (whichever type) at the bank branch. Where the bank will draw the funds from is not a important topic when we are talking about process of the transaction itself.