⚠️ This forum has been restored as a read-only archive so the knowledge shared by the community over many years remains available. New registrations and posting are disabled.

All times are UTC + 8 hours




Post new topic Reply to topic  [ 4 posts ] 
Author Message
 Post subject: A whole new HSM...
PostPosted: Apr 15th, '09, 23:37 
Legend Member
Legend Member
User avatar

Joined: Dec 20th, '07, 04:29
Posts: 711
Images: 23
Gender: Female
Are you human?: Take me 2 ur leader
Location: Minnesota, US
From this article: PIN Crackers Nab Holy Grail of Bank Card Security

Quote:
Sartin says the latter attacks involve a device called a hardware security module (HSM), a security appliance that sits on bank networks and on switches through which PIN numbers pass on their way from an ATM or retail cash register to the card issuer. The module is a tamper-resistant device that provides a secure environment for certain functions, such as encryption and decryption, to occur. (emphasis mine)

Except they're not secure:

Quote:
"Essentially, the thief tricks the HSM into providing the encryption key [for the PIN]," says Sartin.

:shock:
Holy Shit Module?


Top
 Profile Personal album  
Reply with quote  
    Advertisement
 
 Post subject: Re: A whole new HSM...
PostPosted: Apr 16th, '09, 06:12 
Almost divorced
Almost divorced
User avatar

Joined: Apr 20th, '08, 12:07
Posts: 1409
Location: Baton Rouge Louisiana. USA
Gender: Male
Are you human?: Take me to ya leader
Location: USA, Louisiana, Baton Rouge, Gonzales.
You weren't a victim were you? :shock:


Top
 Profile  
Reply with quote  
 Post subject: Re: A whole new HSM...
PostPosted: Apr 16th, '09, 07:06 
Legend Member
Legend Member
User avatar

Joined: Dec 20th, '07, 04:29
Posts: 711
Images: 23
Gender: Female
Are you human?: Take me 2 ur leader
Location: Minnesota, US
Nope.


Top
 Profile Personal album  
Reply with quote  
 Post subject: Re: A whole new HSM...
PostPosted: Apr 16th, '09, 10:08 
Valued Contributor
Valued Contributor
User avatar

Joined: Nov 17th, '08, 22:57
Posts: 95
Gender: Male
Location: Cleveland OH, USA
That sounds like a badly setup HSM, we use these where I work and like anything if you give an idiot control to run the thing it won't be very secure. However if you follow the best practices it will be more secure that most stuff you will run across.

However it seems there are more and more idiots in the marketplace these days, I guess if you have enough certifications you must be good right??? :shock:


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

All times are UTC + 8 hours


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  

Powered by phpBB® Forum Software © phpBB Group
Portal by phpBB3 Portal © phpBB Türkiye
[ Time : 0.071s | 13 Queries | GZIP : Off ]