Hacker News new | ask | show | jobs
by drdaeman 4419 days ago
Chip-and-PIN as a very broad concept¹ is fine. It's EMV implementation has issues - requirement to trust POS terminal, MITM, legacy magnetic tracks and so on.

¹) When we mean just that there's a card with secured microprocessor holding the keys and some method that card's owner use to authenticate with that microprocessor.

1 comments

Is it even EMV that has issues? This attack rather assumes a bad RNG. No doubt some hardware with bad RNGs exist, but this would cause problems for any crypto system. It's not like EMV is somehow uniquely vulnerable to bad RNGs when other systems using cryptography aren't.