NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Technology

Hole-in-the-wall digits showing cracks

Juha Saarinen
By Juha Saarinen
Tech blogger for nzherald.co.nz.·
6 Mar, 2003 07:55 AM4 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

By JUHA SAARINEN

A paper published by Cambridge University Computer Laboratories researchers Mike Bond and Piotr Zelinski details a method that allows automatic teller Machine PIN numbers to be readily cracked.

PINs are generated from customers' account numbers, and stored in a hardware security module (HSM) in encrypted form in banking
systems to ensure that nobody apart from the customer knows their PIN.

But Bond and Zelinski's Decimalisation Table attack allows anyone who can capture the responses from a commonly used HSM made by IBM to recover a four-digit PIN with an average of 15 guesses. Normally, it would take around 5000 guesses.

This means a bank "insider" could capture some 7000 PINs in 30 minutes, by interfacing a notebook computer to the HSM.

They could then create duplicate ATM cards to fraudulently withdraw money from cash machines. Blank ATM cards, and card readers/writers are readily available.

The sums involved could be huge: with 7000 PINs, a daily limit of $800 and an average of two days before such frauds are discovered, an attacker could gain $11.2 million.

Bond and Zelinski are not alone in their work: last October South African researcher Jolyon Clulow of the University of Natal, Durban, held a seminar at Cambridge, called "I Know Your PIN".

A court case is under way in South Africa, involving some £50,000 ($40,000) withdrawn from a man's account in Britain, even though he was not there.

How worried are the banks? Diner's Club and Citibank have asked the High Court in Britain to impose a "gagging order" on Bond and his assistant Ross Anderson, banning them from discussing developments in the case, and excluding the public and the press from the court room.

ASB Bank head of retail banking and marketing Barbara Chapman said the bank had systems to detect any such activity by a staff member.

She said the systems involved were among the most protected areas within the bank.

"Only a very small number of specialist systems staff have access to this kind of system.

"We have never had the security of these systems compromised"

National Bank spokeswoman Cynthia Brophy said that the methodology it used for PIN validation was not the same as that covered in the Cambridge report.

"We have no reason to think that the integrity of either our staff or systems could be compromised in any way by this report," she said.

New Zealand Bankers Association chief executive Errol Lizamore did not want to comment.

The BNZ, Westpac and equipment vendor Eftpos New Zealand were also approached, but wanted to study the vulnerabilities in detail before issuing any official comment.

Eftpos terminals use the same cards as ATMs, and would therefore seem open to attack.

But James Munro of Superbank - an offshoot of St George Bank operating in Foodstuff's supermarkets - said it would be difficult to exploit the Eftpos network, which Superbank would initially use for transactions, to crack PINs, because the terminals concerned were in public view.

Whose responsibility is it?

Banking Ombudsman Liz Brown says the Banking Code of Practice limits customer liability in the case of fraudulent transactions to $50, provided the customer has not been negligent in keeping the PIN safe.

If a "phantom withdrawal" takes place, it's hard to prove that you weren't negligent, as there is no direct evidence of fraud (the ATM thinks the card and PIN are OK) and you cannot know if the PIN has been captured from the HSM.

So isn't that the bank's problem?

Yes. ASB Bank head of retail banking and marketing Barbara Chapman confirms "a customer will not bear the loss where there has been fraudulent conduct by employees or agents of the bank, or where through no fault of the customer unauthorised transactions have occurred". Parnell law firm IT Law Associate Averill Parkinson says while it might be "tricky" to determine liability, it would be difficult for banks to put the onus on customers if research shows PINs can be cracked.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.
Save

    Share this article

Latest from Technology

World

Why sharing too much with chatbots could backfire on you

20 Jun 09:20 PM
Premium
Technology

They asked an AI chatbot questions. The answers sent them spiralling

20 Jun 08:00 PM
World

Trump gives TikTok 90 more days to find buyer, again delayed ban

19 Jun 05:53 PM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Technology

Why sharing too much with chatbots could backfire on you

Why sharing too much with chatbots could backfire on you

20 Jun 09:20 PM

Some people accidentally use Meta AI as a public diary, sharing personal info.

Premium
They asked an AI chatbot questions. The answers sent them spiralling

They asked an AI chatbot questions. The answers sent them spiralling

20 Jun 08:00 PM
Trump gives TikTok 90 more days to find buyer, again delayed ban

Trump gives TikTok 90 more days to find buyer, again delayed ban

19 Jun 05:53 PM
On The Up: 'Geeks and creatives' hope award shows rangitahi they 'belong in tech'

On The Up: 'Geeks and creatives' hope award shows rangitahi they 'belong in tech'

19 Jun 03:10 AM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP