Главная
Study mode:
on
1
Intro
2
The EMV protocol suite
3
Concept of operations
4
Fraud history, UK
5
Attack the crypto
6
Attack the optimisations
7
What about a false terminal?
8
Attacks in the real world
9
A normal EMV transaction
10
Blocking the 'No-PIN' attack
11
Card Authentication Protocol
12
CAP attacks through wicked shops
13
The preplay attack
14
Back end failures too...
15
Attack scale
16
Broader lessons
Description:
Explore the vulnerabilities and failures of EMV smartcard payment systems in this Black Hat conference talk. Delve into the history of EMV implementation, its theoretical security benefits, and the practical challenges that have led to increased fraud. Examine fascinating attack vectors, including supply chain Trojans, protocol flaws enabling PIN bypass, and exploitation of freshness mechanisms. Analyze the governance and regulatory issues contributing to these security shortcomings. Learn about specific attacks like the "preplay" method, which mimics card cloning and undermines tamper-resistant electronics. Gain insights into the complex interplay between vendors, banks, merchants, and regulators in the EMV ecosystem. Understand the broader implications of these security failures as EMV technology expands globally, particularly focusing on its rollout in the United States.

How Smartcard Payment Systems Fail

Black Hat
Add to list
0:00 / 0:00