Flutterby™! : same key across all terminals

Next unread comment / Catchup all unread comments User Account Info | Logout | XML/Pilot/etc versions | Long version (with comments) | Weblog archives | Site Map | | Browse Topics

same key across all terminals

2015-12-22 18:47:06.239332+01 by Dan Lyke 0 comments

European Credit Card Terminals Are Plagued with Serious Vulnerabilities:

The researchers were able to do this by extracting the key used for signing messages from their test terminals. But it turns out every single terminal provided by a payment processor uses the same key.

Dafuq? And then it gets worse!

comments in ascending chronological order (reverse):