OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Muscle] Protecting a PIN with keyed hashing?

From: Ludovic Rousseau (ludovic.rousseaugmail.com)
Date: Fri Jul 17 2009 - 08:33:02 CDT


2009/7/17 Joao Pedro <countzerosapo.pt>:
> Hi all,

Hello,

> Recently, I've been wondering about ways to mitigate the problem of the
> PINs, in the Muscle applet, being transmitted in clear text from the
> terminal to the card. The reason is we are seeing more and more wireless
> smart card readers and sniffing is a threat that can not be dismissed.

What wireless smart card readers do you have in mind? I don't know any
wireless readers.

> What do you think of it? Is it stupid/flawed/insecure/reinventing the wheel
> and serves no purpose at all. Or could it be used in real life?

How it is supposed to work with a pinpad reader?

Bye

--
 Dr. Ludovic Rousseau
_______________________________________________
Muscle mailing list
Musclelists.musclecard.com
http://lists.drizzle.com/mailman/listinfo/muscle