Smart cards not security liabilities

 

Summary

Smart cards "highly secure and intelligent" and recent attack should not deter governments or organizations from utilizing tech to safeguard sensitive information, say observers.

Events

IBM Technology Conference & Expo 2012
May 23, 2012

Convention Centre B2 Room at 22nd Floor, Centara Grand @ Central World, 999/99 Rama I Road, Pathumwan, Bangkok 10330

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

Government agencies and organizations need not shun the use of smart cards despite reports of security breaches targeting such cards as manufacturers are increasing their emphasis on digital and mobile security, observers noted.

Jafizwaty Ishahak, research director of Asia-Pacific ICT practice at Frost & Sullivan, pointed out that what makes smart cards secure are the integrated circuit (IC) modules and applications on it. These cards have various security elements such as the triple data encryption system (DES) and is not easy to hack, she told ZDNet Asia in an e-mail.

Additionally, these cards are typically made from multi-chip unit-based (MCU) cards that are contact, contactless or a combination of both interfaces, and are considered "highly secure and intelligent", she stated.

With this in mind, she said governments need not move away from using smart cards as a security measure for employees despite the recent hacking incident in the United States that targeted secure information from the Department of Defense and other related agencies.

"Instead of moving away [from smart cards], governments should [keep] their options open and aim to associate themselves only with trusted service managers (TSMs) or secure IC providers," Ishahak said.

Chinese hackers reportedly adopted a malware variant called Sykipot to deposit into the authentication machine. Once in, the malware uses a keylogger to steal personal identification numbers (PINs) for the smart cards. When a card is inserted into the reader, the malware then acts as the authenticated user and can access sensitive information, an earlier report stated.

Smart cards not weakest link
Commenting on the incident, Andy Kellett, senior analyst at Ovum, said Sykipot had been around for some time and the attack was believed to be well-funded and motivated to acquire specific, high-value information. He noted that for the keylogger to be successful once it identified user passwords and smart card-generated PIN, it has to be able to access sensitive information and pass it on.

"Therefore, there needs to be a failure of data loss prevention (DLP) technology. The smart card element is only one aspect of a general data protection failure," Kellett stated.

Steve Owen, vice president of global sales identification at NXP Semiconductors, agreed with Ishahak and Kellett that governments should not boycott the use of smart cards as the vulnerability did not originate from the card but from the keylogger in the card reader.

He added that the IC modules not only add hardware security to smart cards but also to devices such as mobile phones, computers and servers. Both card makers and semiconductor companies are continuously improving the security of their offerings, too, he said.

One country that is not deterred from utilizing smart card tech for its security measures is Singapore. A spokesperson from the country's Ministry of Defense (Mindef) added it would continue to leverage the use of smart cards in light of the U.S. attack, but declined to reveal which smart card chip it uses or how the tech is implemented within the organization.

Ishahak did warn that hybrid smart cards represent the highest risk of being hacked because these cards combine both old and new technology, though.

Elaborating, she said the interface of these hybrid cards were developed during the migration of credit and banking cards from pure magnetic to EMV-based cards. As such, the vulnerability lies in these cards' magnetic strip, he noted.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

Homegrown smartphone OSes gaining favor in China: 59 Jakarta 10350, Indonesia Locally-made mobile operating syst... http://t.co/BruP98Es

RT @MDMGeek: Big data acquisitions pave way to fast, effective innovation - ZDNet Asia http://t.co/ky8YgPAn #Bigdata #analytics via @ciropuglisi

Integration, focused investments to propel Windows Phone http://t.co/6JkDa9sB

RT @AsianFashionLaw: Malaysia offers some manufacturing benefits over China http://t.co/bMquIFiX

Acquisitions in the Big Data market increasingly important to enterprises… http://t.co/Br4BkXyZ

Experience trumps content in apps monetization http://t.co/iaCY5ebX

Malaysia offers some manufacturing benefits over China http://t.co/bMquIFiX

RT @MDMGeek: Big data acquisitions pave way to fast, effective innovation - ZDNet Asia http://t.co/ky8YgPAn #Bigdata #analytics via @ciropuglisi

Thats it.Im digging up an old bus plan i wrote around acquisition of #bigdata talent. http://t.co/gpkha5A1 Any investors want2 read/discuss?

Integration, focused investments to propel Windows Phone: By Kevin Kwang , ZDNet Asia on May 23, 2012 (2 mins ag... http://t.co/aaa0Cb73

Homegrown smartphone OSes gaining favor in China http://t.co/lOBVp1T6

Homegrown smartphone OSes gaining favor in China: 59 Jakarta 10350, Indonesia Locally-made mobile operating syst... http://t.co/gHypbdIY

Integration, focused investments to propel Windows Phone - ZDNet Asia http://t.co/7sZi6Dhb

RT @zdnetasia: Homegrown smartphone OSes gaining favor in China. http://t.co/lL8KbccW

Big data acquisitions pave way to fast, effective innovation - ZDNet Asia http://t.co/ky8YgPAn #Bigdata #analytics via @ciropuglisi

So much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...

1 day ago by y15822137359 on 5 SaaS adoption speed bumps to avoid

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

2 days ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

3 days ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

5 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

5 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

5 days ago by wykoong on Drop the egos, copy ideas, then innovate