OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Muscle] PIN transfer within T0/T1 encrypted

From: Karsten Ohme (widerstandt-online.de)
Date: Thu Aug 14 2008 - 15:29:46 CDT


Fabian Bertholm schrieb:
> Hi,
> Hi,
>
> I am just a smartcard greenhorn thus it might be a stupid question...
> Is the PIN transfer from the reader to the card encryted in any way or
> can I "sniff" it with some hardware attached?

You can sniff it.

> Would be cool if the "Transport Key" of those Cyberflex cards is doing
> something like this.

But: Some cards support the Global Platform specification. You can use
the secure channel capability (called Runtime Messaging Support in GP
2.1.1) of a Security Domain. But to so it would
be necessary This might be impossible.

Or create you own secure channel. Choose some standard.

Regards,
Karsten
>
> Greetings,
> Fabe
>
>
> ------------------------------------------------------------------------
>
> _______________________________________________
> Muscle mailing list
> Musclelists.musclecard.com
> http://lists.drizzle.com/mailman/listinfo/muscle

_______________________________________________
Muscle mailing list
Musclelists.musclecard.com
http://lists.drizzle.com/mailman/listinfo/muscle