[48609] in Cypherpunks

home help back first fref pref prev next nref lref last post

Re: FV Demonstrates Fatal Flaw in Software Encryption of Credit Cards

daemon@ATHENA.MIT.EDU (Jeff Weinstein)
Tue Jan 30 03:12:14 1996

Date: Tue, 30 Jan 1996 00:03:31 -0800
From: Jeff Weinstein <jsw@netscape.com>
To: Weld Pond <weld@l0pht.com>
Cc: cypherpunks@toad.com

Weld Pond wrote:
> Programs needing secure entry create a "secure entry field" which is
> really just an imagemap with the digits (and alphas if required) placed
> randomly about.  The user then uses the mouse to click on these numerals.
> Ideally the graphics that represent the numerals would be drawn from a
> random pool and are misformed to thwart any OCR attempts. The graphics
> could be made even more difficult to OCR by mixing in words and pictures
> to represent the numbers.

  The web page could be implemented with javascript, which could collect
the keyclicks without any round trips to the server, and just send the
encrypted credit card number.

	--Jeff

-- 
Jeff Weinstein - Electronic Munitions Specialist
Netscape Communication Corporation
jsw@netscape.com - http://home.netscape.com/people/jsw
Any opinions expressed above are mine.

home help back first fref pref prev next nref lref last post