PKC

Ross Anderson ukcrypto at maillist.ox.ac.uk
Thu, 28 Sep 2000 11:56:39 +0100


> There is a smartcard with a FIPS 140-1 level 3 certification, 
> though, so breaking it should be reasonably difficult.

I've held in my hands a FIPS 140-1 level 3 device that could be
hacked with my Swiss army knife. All level 3 requires is that
the device be potted in a hard opaque material such as epoxy.
However, there's usually nothing to stop you scraping it off 
and dropping a logic analyser probe on a bus line

> The problem comes when you start being able to buy other 
> things with the cards

Or to sign away your house

Ross