Cambridge team exposes EMV card vulnerabilities
(Phys.org)—At a cryptography gathering in Leuven, Belgium, on Tuesday, Cambridge University researchers made it known that they do not like what they see in chip and pin systems. Banks rely on customer confidence in their word that chip and pin systems are safe, but the researchers tell quite a different story. Part of the problem has to do with the number generators, which the researchers give a failing grade. Each time a customer is involved in a chip and pin transaction, withdrawing cash or buying goods, a unique unpredictable number is created to authenticate the transaction. The unpredictable number, generated by software, is supposed to be chosen at random. But researchers say the number is highly predictable, because dates or timestamps had been used.