R E L A T E D   C O N T E N T
ADVERTISEMENT

Students hack for PIN money

Vulnerabilities discovered in high street banks' software

James Middleton and Andy McCue, vnunet.com 09 Nov 2001
ADVERTISEMENT

Security experts have warned that PIN codes and card details held by cash machines may be at risk from unscrupulous bank employees.

The warning comes after research by two Cambridge University students proved that IBM's 4758 cryptographic co-processor, as used in many high street banking systems, could be hacked.

Security firm @stake said that many high street banks could only be vulnerable to an inside attack because the researchers admitted that the technique required around 20 minutes of uninterrupted access to the device. However, this still leaves data vulnerable to internal corruption.

A case in point is Graham Browne, former head of the encryption unit at Barclays, who was yesterday acquitted of attempting to extort £25m from the bank after threatening to expose confidential security information.

The research carried out by computing students Michael Bond and Richard Clayton revealed that, although the IBM 4758 is an extremely secure crytographic co-processor, it is possible by "a mixture of sleight of hand and raw processing power" to persuade the device to export all its DES and 3DES encryption keys.

"The attack can only be performed by an insider with physical access to the cryptographic co-processor, but they can act alone," the students said.

.They emphasised that the most likely source of attack would be from a corrupt high level employee, as a "standard off-the-shelf $995 FPGA evaluation board from Altera" is needed to brute force the encryption scheme.

However, using such a device is "a reasonably straightforward task that does not require specialist hardware design knowledge and, since the board is pre-built and comes with all the necessary connectors and tools, it is entirely suitable for amateur use", they said.

But industry experts have hit back at the claims. "You would have to be in a position to launch that attack and a lot of these systems won't have direct connections to the internet," said Mark Read, network security analyst at MIS Corporate Defence Solutions, highlighting the fact that an outsider attack is very unlikely.

IBM also claims the hack can only be done under strict laboratory conditions and is not possible in real bank systems. "Normal bank practice and procedure would prevent any possibility of launching such an attack," said a spokeswoman.

"This academic study is based on specific laboratory conditions. In the real world there are too many physical safeguards and authority protections for such an attack to be successful," she added.

But Bond and Clayton maintain that, until IBM fixes the Common Cryptographic Architecture software, "banks are vulnerable to a dishonest branch manager whose teenager has $995 and a few hours to spend in duplicating our work".

See also:

Network managers have little to worry about, say security experts  16 Nov 2001
Vulnerability exposure could be just the thing to get it sorted  12 Nov 2001
Former IT security employee cleared of £25m blackmail attempt  08 Nov 2001
Barclaycard wants to protect its computer security  19 Oct 2001

All Applications

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Computer People
Working for a growing and ambitious Professional Services company, an exciting opportunity exists for a hands on Head of IT to lead a global team and implement a best practices. Based in the centre of ... more >
| Computer People
Fantastic new opportunity for an ICT Analyst who can work without supervision to join this exciting organisation providing a lead role in maintenance and operation of their IT infrastructure and Telephone networks. The successful candidate ... more >
| Computer People
A leading UK company in the Aerospace ... more >
| Computer People
Working for an innovative and creative software company, an opening has been created for a forward thinking UNIX expert to implement leading edge network solutions into a corporate environment. Working in a team of experts, ... more >
More job opportunities