Row over bank card loophole thesis

&Tab;&Tab;<div class&equals;"wpcnt">&NewLine;&Tab;&Tab;&Tab;<div class&equals;"wpa">&NewLine;&Tab;&Tab;&Tab;&Tab;<span class&equals;"wpa-about">Advertisements<&sol;span>&NewLine;&Tab;&Tab;&Tab;&Tab;<div class&equals;"u top&lowbar;amp">&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;<amp-ad width&equals;"300" height&equals;"265"&NewLine;&Tab;&Tab; type&equals;"pubmine"&NewLine;&Tab;&Tab; data-siteid&equals;"111265417"&NewLine;&Tab;&Tab; data-section&equals;"2">&NewLine;&Tab;&Tab;<&sol;amp-ad>&NewLine;&Tab;&Tab;&Tab;&Tab;<&sol;div>&NewLine;&Tab;&Tab;&Tab;<&sol;div>&NewLine;&Tab;&Tab;<&sol;div><p><a href&equals;"http&colon;&sol;&sol;londonglossy&period;com&sol;wp-content&sol;uploads&sol;2010&sol;12&sol;row-over-bank-card-loophole-thesis&period;jpg"><img class&equals;"alignnone size-full" title&equals;"A row has erupted over an academic thesis which examines an apparent loophole in chip and PIN technology" src&equals;"http&colon;&sol;&sol;londonglossy&period;com&sol;wp-content&sol;uploads&sol;2010&sol;12&sol;min-row-over-bank-card-loophole-thesis&period;jpg" alt&equals;"A row has erupted over an academic thesis which examines an apparent loophole in chip and PIN technology"&sol;><&sol;a><&sol;p>&NewLine;<p>A Cambridge University professor has accused the bank cards industry of making a &&num;8220&semi;very nasty attempt at censorship&&num;8221&semi; over a flaw in chip and PIN technology&period;<&sol;p>&NewLine;<p>The UK Cards Association &lpar;UKCA&rpar;&comma; which represents the country&&num;8217&semi;s biggest banks&comma; wrote to the university to try to remove the online publication of research which shows how a £20 hand-held device could be used to buy goods without entering the correct PIN&period;<&sol;p>&NewLine;<p>Ross Anderson&comma; professor of security engineering at Cambridge University&&num;8217&semi;s Computer Laboratory&comma; said&colon; &&num;8220&semi;This was absolutely unacceptable&period; It was a very&comma; very nasty attempt at censorship&period;&&num;8221&semi;<&sol;p>&NewLine;<p>Melanie Johnson&comma; a former Labour Treasury minister who is now chair of the UKCA&comma; wrote to the university&&num;8217&semi;s director of communications earlier this month saying the publication &&num;8220&semi;oversteps the boundaries of what constitutes responsible disclosure&&num;8221&semi;&period;<&sol;p>&NewLine;<p>She said the paper&comma; The Smart Card Detective&comma; by MPhil research student Omar Choudary&comma; &&num;8220&semi;places in the public domain a blueprint for building a device which purports to exploit a loophole in the security of chip and PIN&&num;8221&semi;&period; She said the type of attack described was &&num;8220&semi;difficult to undertake&&num;8221&semi; and &&num;8220&semi;unlikely to interest genuine fraudsters&&num;8221&semi; but said the &&num;8220&semi;level of detail&&num;8221&semi; published was worrying and asked for the research to be removed and said police had expressed concern the student &&num;8220&semi;was allowed to falsify a transaction in a shop in Cambridge without first warning the merchant&&num;8221&semi;&period;<&sol;p>&NewLine;<p>But Mr Anderson said exposing vulnerabilities in the system was an example of &&num;8220&semi;responsible disclosure&&num;8221&semi; and said the industry had been guilty of &&num;8220&semi;sitting on their butts and doing nothing&&num;8221&semi; since he and fellow scientists first revealed the flaw in late 2009&period;<&sol;p>&NewLine;<p>In a response letter&comma; he wrote&colon; &&num;8220&semi;You seem to think that we might censor a student&&num;8217&semi;s thesis&comma; which is lawful and already in the public domain&comma; simply because a powerful interest finds it inconvenient&period; This shows a deep misconception of what universities are and how we work&period; Cambridge is the University of Erasmus&comma; of Newton&comma; and of Darwin&semi; censoring writings that offend the powerful is offensive to our deepest values&period;&&num;8221&semi;<&sol;p>&NewLine;<p>He continued&colon; &&num;8220&semi;You complain that our work may undermine public confidence in the payments system&period; What will support public confidence in the payments system is evidence that the banks are frank and honest in admitting its weaknesses when they are exposed&comma; and diligent in effecting the necessary remedies&period; Your letter shows that&comma; instead&comma; your member banks do their lamentable best to deprecate the work of those outside their cosy club&comma; and indeed to censor it&period;&&num;8221&semi;<&sol;p>&NewLine;<p>Prof Anderson said he had authorised the thesis to be issued as a Computer Laboratory technical report&period; He said there was no basis for police concern as there was no intent to commit fraud&comma; as the card holder gave his consent and the merchant was paid&period; He added that Barclays Bank did appear to have closed the technological loophole although other banks were yet to fix the problem&period;<&sol;p>&NewLine;<p>A UKCA spokeswoman said&colon; &&num;8220&semi;The UK Cards Association has written to Cambridge not to challenge the work of the university&&num;8217&semi;s security academics but only to challenge whether publishing explicit details of how to attempt a fraud &&num;8211&semi; specifically one which there is no evidence of a fraudster yet undertaking &&num;8211&semi; is necessary and serving the public&&num;8217&semi;s best interest&period; We remain hopeful that the academics concerned will work with us rather than against us to help defeat the fraudsters &&num;8211&semi; as unfortunately it is only the fraudsters who stand to gain from any lack of cooperation between us&period;&&num;8221&semi;<&sol;p>&NewLine;&Tab;&Tab;&Tab;<div style&equals;"padding-bottom&colon;15px&semi;" class&equals;"wordads-tag" data-slot-type&equals;"belowpost">&NewLine;&Tab;&Tab;&Tab;&Tab;<div id&equals;"atatags-dynamic-belowpost-69e33d129373d">&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;<script type&equals;"text&sol;javascript">&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;window&period;getAdSnippetCallback &equals; function &lpar;&rpar; &lbrace;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;if &lpar; false &equals;&equals;&equals; &lpar; window&period;isWatlV1 &quest;&quest; false &rpar; &rpar; &lbrace;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&sol;&sol; Use Aditude scripts&period;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;window&period;tudeMappings &equals; window&period;tudeMappings &vert;&vert; &lbrack;&rsqb;&semi;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;window&period;tudeMappings&period;push&lpar; &lbrace;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;divId&colon; 'atatags-dynamic-belowpost-69e33d129373d'&comma;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;format&colon; 'belowpost'&comma;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&rcub; &rpar;&semi;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&rcub;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&rcub;&NewLine;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;if &lpar; document&period;readyState &equals;&equals;&equals; 'loading' &rpar; &lbrace;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;document&period;addEventListener&lpar; 'DOMContentLoaded'&comma; window&period;getAdSnippetCallback &rpar;&semi;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&rcub; else &lbrace;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;window&period;getAdSnippetCallback&lpar;&rpar;&semi;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&rcub;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;<&sol;script>&NewLine;&Tab;&Tab;&Tab;&Tab;<&sol;div>&NewLine;&Tab;&Tab;&Tab;<&sol;div>


Discover more from London Glossy Post

Subscribe to get the latest posts sent to your email.

- Advertisement -