A Merry Christmas to all Bankers

Found on Light Blue Touchpaper on Friday, 24 December 2010
Browse Hardware

The bankers' trade association has written to Cambridge University asking for the MPhil thesis of one of our research students, Omar Choudary, to be taken offline. They complain it contains too much detail of our No-PIN attack on Chip-and-PIN and thus "breaches the boundary of responsible disclosure"; they also complain about Omar's post on the subject to this blog.

The bankers also fret that "future research, which may potentially be more damaging, may also be published in this level of detail".

So basically the banks want to hide a known security flaw by trying to censor research on it instead of coming up with a more secure solution.