Re: Unique number generation

From: none (_at_(none))
Date: 05/02/05

  • Next message: xz: "Re: couple more Q's on basic public key encryption techniques"
    Date: Tue, 03 May 2005 08:22:08 +1200
    
    

    Jean-Luc Cooke wrote:
    [snip]
    > In short, his design goals arn't in lign with security. The parking
    > meters in Ottawa have the same problem. They issue smart cards that
    > help you save carrying change, but the meters don't talk back to home
    > base to verify the smart card is valid. You can just:
    > dd if=/dev/smartcard1 of=myFullSC.img
    >
    > And once you've spent your $25 on the SCard, you:
    > dd if=myFullSC.img of=/dev/smartcard1
    >
    > And bob's your uncle.
    >
    > JLC
    A little OT.

    Well i'm in NZ so its not illegal to point out a security flaw.

    We had almost the same thing with magnetic cards and vending machines.
    Since in the hostel you practically live out of the vending machine, its
      still about a bit of cash. The strip was encrypted, but some guy just
    put some credit on *one* card, and copied the image to the other cards.
    Took them months b4 they worked it out. Police and everything turned up.
    but nothing happed.

    Of course not paying for the food from the vending machine is illegal.

    OTOH a heap of salt water down the coin slot on coke machines worked as
    well, but getting 240 volts through you was a possibility.

    Nobody...;)


  • Next message: xz: "Re: couple more Q's on basic public key encryption techniques"

    Relevant Pages

    • Re: about SecuriID on mobile devices
      ... )> implementing most security devices, ... Tokens to assert identity or status were widely used long before the ... message that mentioned Grid Cards and S/Key lists, ... Physical OTP tokens ...
      (sci.crypt)
    • Re: about SecuriID on mobile devices
      ... )> implementing most security devices, ... Tokens to assert identity or status were widely used long before the ... message that mentioned Grid Cards and S/Key lists, ... Physical OTP tokens ...
      (sci.crypt)
    • Re: Have Any Notable Pros Commented on the Absolute Poker Scandal?
      ... A cheater could find out what the turn and river cards were going to ... of possible shuffles was way too low. ... be handy for security purposes to view the room/players surreptitiously ... Poker or not. ...
      (rec.gambling.poker)
    • Re: [fw-wiz] Kinkos Waning Security
      ... representative of the department of Homeland Security. ... > your overall risk very significantly at all in terms of real-world attacks. ... > employee X instead of employee Y?" ... >> cards at another store, access the auth page, and let the store buy the ...
      (Firewall-Wizards)
    • Re: Have Any Notable Pros Commented on the Absolute Poker Scandal?
      ... A cheater could find out what the turn and river cards were going to ... There was another problem with PRNGS having too small a number of possible shuffles, but it is relatively unclear that this makes a difference in most holdem games where only the top half of the deck is used. ... This would be handy for security purposes to view the room/players surreptitiously for various reasons. ... Poker or not. ...
      (rec.gambling.poker)