Chip and PIN
tombell93.co.uk
tombell93.co.uk
To me, the article seems (at least) incorrect at two points:
1. The number of PIN retries cannot be reset. The command described to perform this reset in the blog post is the same as for checking the tries. Checking the tries just doesn't reset the number of tries, only providing the correct PIN does. But please prove me wrong by supplying the correct command to reset the PIN tries...
The original paper about this http://fc13.ifca.ai/proc/9-2.pdf describes a way to have 2 'free' guesses, but after those 2 guesses, you'll need to try again with a correct PIN. On a hacked reader, you could eventually find out someones PIN if the person uses the reader enough. Once the retries are exhausted, the card is blocked. Beware you'll need up-to 10.000 guesses, so up-to 5000 usages of the card. (note it is actually a little bit less, because not all PIN codes are allowed on production cards)
2. With EMV cards issued the last few years, the Track2 equivalent data on the EMV chip does not contain correct, usable data to create a magstripe card from. The Pin Verification Value in the EMV Track2 Equivalent data record is set to all zeros instead of the original PVV on the magstripe, rendering it pretty useless. So in short, you cannot create a working magstripe card with PIN by using data from the EMV chip.
It provides all that you need to create a magstripe card from the PAN stored in the Chip. That is ALL you can do. You can't clone the card and can't get cryptograms. Any sane issuer will decline transactions made with the magstripe at a chip-capable terminal, so this doesn't help much. In any event, a lot of the information you need to clone the magstripe is... on the magstripe.
The rest of the attacks are on the offline functionality of the card which won't be used in almost any US implementations and is being phased out of most of the other places where it is in use.
> Any sane issuer will decline transactions made with the magstripe at a chip-capable terminal, so this doesn't help much.
Regarding this... Where I live and use Chip-and-PIN cards every day (Canada), it's extremely common for a chip-capable terminal to fail on a chip card for a variety of reasons and immediately instruct the cardholder and/or merchant to "please swipe card". Customer swipes and places a signature-resembling mark on paper. Merchant and issuer accept this. And so it goes.
Anecdotal data: We've had Chip-and-PIN for years here. Currently, despite my Amex being Chip-and-PIN, more than 50% of terminals fail with the chip ("it's an Amex thing," we're told, years into this) and revert to swiping, and my Visa Chip-and-Pin still fails as a chip card and falls back to a swipe transaction approximately 10% of the time.
So the easy fraud vector is still there with magstripes even in a mature Chip-and-PIN environment.
Or, more commonly, they're with a POS provider that bought, and then rolled out, chip-and-pin terminals as part of its standard four-year-replacement cycle, but who don't even support chip-and-pin yet.
Either way, usually the merchant knows ahead of time that their terminal won't accept your (or anyone's) chip, and could put up a sign to that effect.
But for the Visa chip failures I experience, it's generally happening at my regular haunts where chip cards work (mine and others). The occasional chip failure is accompanied by the stock service industry script of, "oh, yeah, that terminal has been having problems all day -- just swipe it and sign, sorry."
I do wonder if the merchant is charged higher discount rates or fees on those transactions because of higher fraud likelihood.
There is a phenomenon related to this, that I would almost describe as being like an inorganic physical virus.
Sometimes plastic or lint from a wallet solidifies onto the chip on your card—and then rubs off on the contacts inside the POS terminal when you insert it. Now the terminal can't read the card, because there's goop in the way. So you take your card out (which is now slightly cleaner, and thus likely to work on the next terminal.)
Next, someone else puts theirs in. Now the gunk is on the terminal contacts, and gets rubbed onto that person's card, and once again, the card doesn't work. Now that person's card is dirty as well.
It seems that there's less card->terminal gunk transfer than terminal->card gunk transfer, but every once in a while you'll take your card out of one non-working terminal and then it won't work in any other terminal—until you notice there's a smudge on the chip, rub it off, and then it starts working again.
Perhaps they need "cleaning cards" for these terminals that are like the old VHS head cleaners.
In my experience if you try to use a broken chip+pin card you will almost always be allowed to use the magstripe "bypass" instead.
Of course, me being stateside, I still have to deal with antiquated magstrips and /their/ various faults. I've got cards with chips in them, but no one is taking them yet, and the bank I'm with (Wells Fargo) isn't even planning on rolling out chips on their debit card line until the end of the year, and even then, by request only. The whole financial security system is just ridiculous.
I recall reading a few years ago about auto insurance companies denying claims on stolen cars because it was "impossible" for the car to be stolen due to the new key tech at the time. They were ignoring that the dealerships help the master keys, and car thieves would just attack that as the weak point (i.e. get an insider to cut the keys, and give you the address for the owner). The real reason that the insurers were denying claims is that they want to just push all of the risk onto the consumer, while still taking their money to 'insure' them.
http://en.wikipedia.org/wiki/Chip_and_PIN#Banks.27_liability
I can't recall a single time I've had to enter a PIN or sign for an EMV transaction.
Are the PINs assigned by the card issuer and unchangeable, or can the user change the PIN?
If the user can change them, couldn't she change the PIN to something that isn't arbitrary to her?
The way this works in GSM SIM cards is the following: If an operation needs authentication you have to provide your PIN to the chip.
This operation returns OK or not. There's no counter to be checked (IIRC) and it can't be reset.
If you got the PIN right then operations will succeed (like listing SMSs, Phone book, or making a call) otherwise they'll return a "needs auth" error code
GSM 11.11
And also the discretionary data field on both magnetic stripe and track image data stored on chip is usually not used as "PIN Verification Value", but is either unused or used as CVC/CVV1. Even when these data were the real PVV, this information is mostly useless for deducing the PIN. (and the fact that the magstripe image stored on chip does not match the real magstripe is mostly to be expected)
Don't let someone get your card, and if you think they do, report it to your bank. At least since 2009 you won't be liable for any fraud.
http://media.ccc.de/browse/congress/2014/31c3_-_6120_-_en_-_...
There have been multiple posts showing how to get around it or otherwise compromise these cards. That coupled with banks trying to move all liability to the user makes me sick. All of this coming at a time that I swipe my card (physically) way less than ever before. Chip and Pin seems to mean nothing for online purchases AFAICT, feels a lot like failing to solve a problem that is slowly going away and ignoring online purchases.....
This is the key part for me. Being able to brute-force a pin is a huge vulnerability.
Here's a video of them applying the exploit: https://www.youtube.com/watch?v=JPAX32lgkrw