6 ms·
Wouldn't it have been far nobler to approach the banks affected by the exploit with these findings rather than publishing schematics for the exploit into the pu
by Tarski 16y ago
Wouldn't it have been far nobler to approach the banks affected by the exploit with these findings rather than publishing schematics for the exploit into the public domain?
- ars 16y agoBased on their response it wouldn't be effective - they would just try to cover it up. Plus it's likely it's already being used secretly by those with nefarious purposes, publishing just means the average person knowns about it - it's not likely to change how many actually use it.
- wjy 16y agoI believe the article states they notified the banks before publishing the original work.
- Tarski 16y agoNo it doesn't? I'm not taking the side of the banks here, just trying to understand why the author took the approach he did. It's a shame that at times the HN community is one of single-mindedness where opposite views are met with immediate down-votes.
- drm237 16y ago> ... because it documented a well-known flaw in the chip-and-PIN system... The author of the article at least believes that it is a well-known flaw so responsible disclosure isn't really applicable.
- Tarski 16y agoWell I think you hit the nail on the head, that the disclosure isn't responsible. I'm all for bringing the flaws in chip-and-pin to the public attention, however I find it distasteful that a leading university publishing the schematics of a device that can be used to commit fraud, receives so much applause for this community. I get the impression that this has captured the public mood of "sticking it to the bankers", when really Cambridge have gone about this one the wrong way.
- foamdino 16y agoMy reading of the whole incident is that the exploit was disclosed (responsibly) to the banks 1 year ago and the banks have done nothing to fix the problem. Since then the professor (along with others) published a paper detailing the exploit. Finally the MPhil student cited the previously published paper in his thesis (it would be a crappy thesis to not reference current similar work) At no point do I get the indication that the MPhil student was acting in a way that was 'irresponsible' - I don't know how you have come to that conclusion.
- burgerbrain 16y ago"Responsible disclosure" is a term with a specific meaning in the field of security, using the term is not equivalent to agreeing with it's implied meaning. In fact, many would argue that responsible disclosure is anything but, since it has the tendancy tp maximize the amount of time the public is at risk. All of this is ignoring the fact that this paper wasnt even disclosure at al...
- yesbabyyes 16y ago"Third, Omar’s thesis does not contain any new information on the No-PIN vulnerability. That was discovered by Steven Murdoch, Saar Drimer and me in 2009, disclosed responsibly to the industry, and published in February this year. It is not expected that an MPhil thesis contain novel scientific work." http://www.cl.cam.ac.uk/~rja14/Papers/ukca.pdf http://www.cl.cam.ac.uk/~rja14/Papers/ukca.pdf
- tsycho 16y agoWouldn't have worked, in the same way that emailing Facebook and others, instead of releasing Firesheep wouldn't have worked (since they haven't fixed it even after Firesheep has been released, it's unlikely they would have paid much attention to a letter or email). given the letter says that this is a known vulnerability