Comments

Clive Robinson July 11, 2008 1:55 PM

If Ross Anderson and his team are correct then he could do it in less than thirteen guesses (if I remember correctly) if he was talking to the bank security hardware (due to a mistake in protocols)…

Jonadab the Unsightly One July 11, 2008 9:24 PM

The problem with that attack (from the attacker’s perspective) is that if you want to get away with it you need to figure out how to rent a booth inside an amusement park in a way that will not be traceable back to you later. I’m sure that’s possible with a combination of social engineering and forgery, but the profit-to-risk ratio is not particularly appealing compared to other kinds of attacks.

clvrmnky July 13, 2008 2:03 PM

“if you want to get away with it you need to figure out how to rent a booth inside an amusement park in a way that will not be traceable back to you later.”

You are going to find a carnie the day after the carnival leaves town?

Leave a comment

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.