BugTraq
Clear text password exposure in Datakey's tokens and smartcards Aug 04 2004 05:08AM
vuln hexview com (1 replies)
Re: [Full-Disclosure] Clear text password exposure in Datakey's tokens and smartcards Aug 04 2004 06:45AM
Lionel Ferette (lionel ferette belnet be) (1 replies)
Re: [Full-Disclosure] Clear text password exposure in Datakey's tokens and smartcards Aug 04 2004 08:11PM
Toomas Soome (Toomas Soome microlink ee) (2 replies)
Re: [Full-Disclosure] Clear text password exposure in Datakey's tokens and smartcards Aug 05 2004 01:03PM
Lee Dilkie (lee_dilkie mitel com) (1 replies)
Toomas Soome wrote:

> Lionel Ferette wrote:
>
>> Note that this is true for almost all card readers on the market, not
>> only for Datakey's. Having worked for companies using crypto smart
>> cards, I have conducted a few risk analysis about that. The
>> conclusion has always been that if the PIN must be entered from a PC,
>> and the attacker has means to install software on the system (through
>> directed viruses, social engineering, etc), the game's over.
>>
>> The only solution against that problem is to have the PIN entered
>> using a keypad on the reader. Only then does the cost of an attack
>> raise significantly. But that is opening another can of worms,
>> because there is (was?) no standard for card readers with attached
>> pin pad (at the time, PC/SCv2 wasn't finalised - is it?).
>>
>
> at least some cards are supporting des passphrases to implement
> secured communication channels but I suppose this feature is not that
> widely in use.... how many card owners are prepared to remember both
> PIN codes and passphrases...
>
> toomas

Perhaps I'm missing something here. As far as I can tell, no keys
located on the card were compromised, only the PIN was. Since this is a
two factor authentication system, possession of the PIN is of little
value without possession of the token itself.

Am I missing the point here?

regards,

-lee

--
__|__
--@--@--(_)--@--@--
"You can't be a real country unless you have a BEER and an airline. It
helps if you have some kind of a football team, or some nuclear weapons,
but at the very least you need a BEER."
--Frank Zappa
__|__
--@--@--(_)--@--@--

[ reply ]
Re: [Full-Disclosure] Clear text password exposure in Datakey's tokens and smartcards Aug 06 2004 11:31AM
Kevin Sheldrake (kev electriccat co uk)
Re: [Full-Disclosure] Clear text password exposure in Datakey's tokens and smartcards Aug 05 2004 10:39AM
Kevin Sheldrake (kev electriccat co uk) (1 replies)


 

Privacy Statement
Copyright 2010, SecurityFocus