home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky sci.crypt:3231 alt.security:4367 comp.security.misc:1249
- Path: sparky!uunet!mcsun!uknet!mucs!nessie!nessie!segr
- From: segr@nessie.mcc.ac.uk (Simon Read)
- Newsgroups: sci.crypt,alt.security,comp.security.misc,local.crypto
- Subject: Re: ATM fraud
- Message-ID: <1992Sep14.085441.28829@nessie.mcc.ac.uk>
- Date: 14 Sep 92 08:54:41 GMT
- References: <1992Sep8.115050.8694@cl.cam.ac.uk>
- Sender: segr@nessie (Simon Read)
- Organization: UMIST
- Lines: 33
-
- Surely those of us that know about the banks electronic security measures (and
- often shocking lack of them) have known that this could happen at any time. There
- must be hundreds of variations on this scam!
-
- Unfortunately the banks are not interested in security. I was involved at one
- time in a project with the UK banks to provide point-of-sale use of swipe cards
- (the project/company etc will remain nameless). The project provided a high
- degree of security (physical and electronic) to prevent fraud on the part of the
- retailer and the customer (and to some extent the bank!). The banks were simply
- not interested in bearing the cost of the fraud protection, they wanted to pass it
- on to someone. The project collapsed!
-
- A similar system with much poorer security exists called SWITCH. Despite having a
- card to access this system (it's just my bank card), I will not use it! Typing my
- PIN in at a terminal in a supermarket knowing that it is not properly secure, even
- with the added security of those bits of paper banks love, is not something I am
- willing to do.
-
- The only security a bank customer has is the security of his PIN. The banks do
- say "TREAT THIS CARD LIKE CASH" (from an ATM here); they don't provide advice on
- keeping your PIN safe though. The naivete of Joe Public is immense, as is
- illustrated by password/PIN frauds; but the banks and others must have some duty
- of care surely? Why don't they provide more advice on when to use your PIN and
- when not to? How to prevent the guy behind you in the ATM queue from seeing your
- PIN?
-
-
- Simon Read
- ----------
- Simon.Read@umist.ac.uk
-
- Disclaimer: The above expresses my *personal* opinion. Not necessarily those of
- any organisation I currently work for or have worked for in the past.
-