All the latest UK technology news, reviews and analysis

Bank hack 'a death blow' for security

by James Middleton

12 Nov 2001

Be the first to comment

  • Tweet this

Security experts have said that last week's hack of the IBM 4758 cryptographic co-processor is a death blow for single Data Encryption Standard (DES) encryption.

Although the hack devised by Cambridge computing students Michael Bond and Richard Clayton does not attack the IBM 4758 machine itself, rather the Common Cryptographic Architecture (CCA) API used by the device, it reveals an inherent weakness in the security system.

Dr Nicko van Someren, chief technology officer of security firm nCipher, said the attack was a "crushing death blow" for DES.

"It does not work in all cases but it does work in the way that IBM are using DES. Single DES is dead," he said.

Someren claims that all the IBM 4758 units on banking applications that are not running custom software, are using the vulnerable CCA and this attack will extract any 112bit triple-DES key from the system.

But Phil Huggins, manager of security architecture for @stake, pointed out that the DES standard had already been broken in 1998, and many vendors had moved over to the Advanced Encryption Standard (AES) standard instead.

Huggins explained that the IBM 4758 was the only cryptographic processor to achieve Federal Information Processing Standards Publications 140-1 at levels 3 and 4, "and still is," he said. "But the entire system was designed to be tamper proof and to remove the necessity of placing trust in the hands of an employee."

He said that because the hack circumvented the anti-tamper system, that extra layer of security had been removed, effectively forcing the bank to trust a potentially unscrupulous member of staff.

"What the hack did point out is that we need to take a more holistic view of security," he said.

"The vulnerability has been known about since February when Ross Anderson of Cambridge University published a document detailing the flaw," Huggins added. "But it has only caused problems since Bond and Clayton published the hack. The exposure may well get the problem sorted."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

30%

1%

10%

59%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Buyer/Procurement Specialist

Buyer/Procurement Specialist x 8 £30,000 - £40...

Systems Analyst/Architect

Systems Analyst/Architect £30,000 - £40,000 + excellent...

Software Developer

Software Developer Up to £27,000 + excellent...

Software Engineer/Developer (C#, C++)

Software Engineer/Developer (C++) £25,000 - £40...

To send to more than one email address, simply separate each address with a comma.