3DSecure not secure

You may have seen in various places that “3-D Secure” (aka “Verified by Visa” or “Mastercard Securecode”) is not as secure as it says. The original paper is here (PDF). Unfortunately, having implemented the 3-D Secure system via a third-party somewhere in Europe, I have to agree with the authors. I will insist here on one aspect - the inline frame - but the authors are giving more aspects and some solutions worth considering in their paper. ...

January 28, 2010 · 2 min · jepoirrier

Proton transactions history

Did you know that the last 3 transactions you made with a Proton card (the Belgian electronic purse) are stored in the chip? I simply used the card reader/challenge solver given by my bank to have access to the online banking system. Usually, you press on the “M1” button. If you press on the “Info” button, you’ll get the last 3 transactions you made with Proton, the reader EPCI number, battery level and embedded software version. ...

April 7, 2007 · 1 min · jepoirrier