Hacker News new | ask | show | jobs
by qmarchi 387 days ago
Disc: Former Visa Employee

Generally, these devices will use the mp1 to do all of the cryptographic operations around the devices.

The biggest part of this is the keys defined between the terminal and the acceptance gateway (something like CyberSource or Authorize.net).

When the temper protection is tripped the keys that are used are immediately dropped from RAM and you can't recover them, they have to manually be input into the device again to reset the tamper protection.

(Side Note: keys are specific to a merchant. If you're able to extract them, it limits the blowback.)