Inducing Authentication Failures to Bypass Credit Card PINs
Offered By: USENIX via YouTube
Course Description
Overview
Explore a critical security vulnerability in credit card transactions using the EMV standard in this conference talk from USENIX Security '23. Learn how researchers from ETH Zurich discovered a flaw in the offline data authentication mechanism that allows bypassing PIN verification for high-value Mastercard transactions. Understand the technical details of how integrity checks using RSA signatures and keyed MACs can be exploited, and see a demonstration of an Android app that modifies unprotected card-sourced data to trick real-world terminals. Gain insights into the potential risks of this vulnerability and the researchers' recommendations for addressing this security issue in payment systems.
Syllabus
USENIX Security '23 - Inducing Authentication Failures to Bypass Credit Card PINs
Taught by
USENIX
Related Courses
Never Been KIST - Tor’s Congestion Management Blossoms with Kernel-Informed Socket TransportUSENIX via YouTube Eclipse Attacks on Bitcoin’s Peer-to-Peer Network
USENIX via YouTube Control-Flow Bending - On the Effectiveness of Control-Flow Integrity
USENIX via YouTube Protecting Privacy of BLE Device Users
USENIX via YouTube K-Fingerprinting - A Robust Scalable Website Fingerprinting Technique
USENIX via YouTube