Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Web-App-Sec
[Top] [All Lists]

Re: Smart card proposal

Subject: Re: Smart card proposal
Date: Tue, 25 Jan 2005 08:28:32 +0100
Hugo Fortier wrote:
On Mon, 24 Jan 2005 21:39:08 +0100, Rogan Dawes <discard@dawes.za.net> wrote:

Rishi Pande wrote:

   I like Rogan's solution. But, I think by putting these card-readers
at internet cafes (a rarity in my town - and I stay about an hour away
from NYC) you are basically circumventing the solution that online
banking offers- ease of use - it's 4 am let me go and check my bank
account.

The idea behind installing them in the Internet Cafe's is that people who are mobile can expect to find at least one smart card reader at an Internet Cafe, sot hey don't have to worry about whether the place they will be at can use their smart card . . .


Could you trust a smart card reader found in a Internet Cafe? People
are doing fake ATM front end to steal your NIP and magnetic strip,
don't you think they could do a smart card reader with a backdoor?

There is a big difference between stealing a magnetic strip and a smart card. One you can copy, the other you cannot. That's one of the reasons to use a smart-card, rather than a magnetic strip, other than capacity, built-in CPU, etc, etc.


You should't be trusting a Internet Cafe computer to access your
online bank account anyway...

True enough. But users will do it, regardless of what we tell them to do. And if the bank's don't "seed" the internet cafes with smart card readers, they will install them themselves, eventually. I was just suggesting it as a mechanism for accelerating the uptake. It is certainly better to do your internet banking from an internet cafe using a smart-card, than with just a username and password.


At least any transactions have to be simultaneous to others that you are performing, and I'm pretty sure that people will remember where it happened, and be able to track back to the PC that was compromised, and start with a forensics investigation, etc, etc . . .


And the consequence of getting your online banking account compromised are a lot worst than getting your debit card comprimised...

True.

Hugo

Rogan -- Rogan Dawes

*ALL* messages to discard@dawes.za.net will be dropped, and added
to my blacklist. Please respond to "lists AT dawes DOT za DOT net"

<Prev in Thread] Current Thread [Next in Thread>