[Full-disclosure] Re: Fedex Kinkos Smart Card Authentication Bypass

Michael Holstein michael.holstein at csuohio.edu
Wed Mar 1 14:10:49 GMT 2006


> According to Fedex Kinko's:
> "Our analysis shows that the information in the article is inaccurate
> and not based on the way the actual technology and security function.
> Security is a priority to FedEx Kinko's, and we are confident in the
> security of our network in preventing such illegal activity."

Presumably they're depending on the ever-vigilant eye of the highschool 
copyjocky behind the counter to notice somebody inserting a card that's 
trailing some ribbon cable into one of the readers.

Actually, a lot of "security protocols" depend on just such things :)



Full-Disclosure is hosted and sponsored by Secunia.