<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>Comments on: Cards are OK, but is Chip &amp; PIN OK ?</title>
	<atom:link href="http://javacard.vetilles.com/2007/02/11/cards-are-ok-but-is-chip-pin-ok/feed/" rel="self" type="application/rss+xml" />
	<link>http://javacard.vetilles.com/2007/02/11/cards-are-ok-but-is-chip-pin-ok/</link>
	<description>A weblog on Java Card, security, and other things personal</description>
	<lastBuildDate>Thu, 18 May 2017 07:26:32 +0000</lastBuildDate>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=4.0.32</generator>
	<item>
		<title>By: marcelo rodrigues</title>
		<link>http://javacard.vetilles.com/2007/02/11/cards-are-ok-but-is-chip-pin-ok/#comment-3067</link>
		<dc:creator><![CDATA[marcelo rodrigues]]></dc:creator>
		<pubDate>Mon, 30 Jul 2007 02:51:31 +0000</pubDate>
		<guid isPermaLink="false">http://javacard.vetilles.com/2007/02/11/cards-are-ok-but-is-chip-pin-ok/#comment-3067</guid>
		<description><![CDATA[I guess if some expert programm a javaCard and install an EMV Fake Applet on it which could have been stolen from a &quot;real&quot; card (SDA), this migth work. 
So card skimming should not be so difficult as they say, I mean, you only need a smart reader and some java cards.]]></description>
		<content:encoded><![CDATA[<p>I guess if some expert programm a javaCard and install an EMV Fake Applet on it which could have been stolen from a &#8220;real&#8221; card (SDA), this migth work.<br />
So card skimming should not be so difficult as they say, I mean, you only need a smart reader and some java cards.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric VÃ©tillard</title>
		<link>http://javacard.vetilles.com/2007/02/11/cards-are-ok-but-is-chip-pin-ok/#comment-600</link>
		<dc:creator><![CDATA[Eric VÃ©tillard]]></dc:creator>
		<pubDate>Fri, 02 Mar 2007 10:07:32 +0000</pubDate>
		<guid isPermaLink="false">http://javacard.vetilles.com/2007/02/11/cards-are-ok-but-is-chip-pin-ok/#comment-600</guid>
		<description><![CDATA[Just like you, I don&#039;t believe that the attack is feasible exactly as it is presented. However, it is nevertheless interesting for at least two reasons.

First, banking terminals can be fake, and this opens many other attacks. Then, card-like payment is being deployed in many new ways, like contactless payment and mobile payment, and similar may be easier in such settings.

More generally about the Cambridge guys, they are indeed publicity-hungry geeks. They may not be the best security researchers either, but their cheap stunts are useful to remind us about security.]]></description>
		<content:encoded><![CDATA[<p>Just like you, I don&#8217;t believe that the attack is feasible exactly as it is presented. However, it is nevertheless interesting for at least two reasons.</p>
<p>First, banking terminals can be fake, and this opens many other attacks. Then, card-like payment is being deployed in many new ways, like contactless payment and mobile payment, and similar may be easier in such settings.</p>
<p>More generally about the Cambridge guys, they are indeed publicity-hungry geeks. They may not be the best security researchers either, but their cheap stunts are useful to remind us about security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nigel Beatty</title>
		<link>http://javacard.vetilles.com/2007/02/11/cards-are-ok-but-is-chip-pin-ok/#comment-599</link>
		<dc:creator><![CDATA[Nigel Beatty]]></dc:creator>
		<pubDate>Fri, 02 Mar 2007 08:53:42 +0000</pubDate>
		<guid isPermaLink="false">http://javacard.vetilles.com/2007/02/11/cards-are-ok-but-is-chip-pin-ok/#comment-599</guid>
		<description><![CDATA[Why describe this as a &quot;nice&quot; attack? It&#039;s complete nonsense and nothing remotely like it would ever have a chance of performing a fraud in the real world. Those so-called researchers at Cambridge are just publicity-hungry geeks who should spend their research budgets on something of benefit instead of cheap stunts like this.]]></description>
		<content:encoded><![CDATA[<p>Why describe this as a &#8220;nice&#8221; attack? It&#8217;s complete nonsense and nothing remotely like it would ever have a chance of performing a fraud in the real world. Those so-called researchers at Cambridge are just publicity-hungry geeks who should spend their research budgets on something of benefit instead of cheap stunts like this.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
