Sunday 30 May 2010

German Police publishes ATM Crime Numbers

The german federal police has published the 2009 numbers for ATM fraud. 964 ATM machines have been manipulated, that#s 20% more than 2008. Usually the PIN is spied out and the magnetic stripe data of the banking card is read. The data is transferred via a wireless connection who make a copy of the card and use that at another ATM.

Usually customers won't note the manipulations. Removing the magnetic stripe would improve the situation, but note that the cards must be authenticated with a real challenge-response protocol if a real security improvement is the target.

Monday 24 May 2010

Bumping Telephones for small Payments

Bump is an API and service that allows people to initiate a data transfer between their telephones by bumping them together. The service matches location, time and kinetics of the bump between the phones. Then contact data may be exchanged or, more interesting, small amounts of money my be sent.
The bump procedure ensures that users understand what's happening and privacy may be added by adding a PKI to the bump matching service: if the match is made, the service can send public keys of the bump partner.