File:DEF CON 14 - Strom Carlson - Hacking FedEx Kinko's - How Not To Implement Stored-Value Card Systems.webm

Summary

Description
English: Strom Carlson: Hacking FedEx Kinko's: How Not To Implement Stored-Value Card Systems

"ExpressPay is a stored-value cash card system which utilizes the Infineon SLE4442 chip; it was developed by enTrac Technologies of Toronto, Ontario, and its largest application is as the pre-paid cash card system in use at FedEx Kinko's. Analysis of a few dozen cards reveals that the data stored on the card is unencrypted and poorly protected against fraud, and a simple attack can be used to obtain the security code necessary to alter the data on the card. This talk will step the audience through the analysis, research, attack, and subsequent tests performed on the ExpressPay system, and conclude with recommendations on how to implement a more secure stored-value card system.

Bio: Strom Carlson is a hardware security researcher at Secure Science Corporation, the organizer of the Los Angeles area Defcon Groups chapter (DC213), and the co-host of Binary Revolution Radio. He enjoys tinkering with technology, playing with telephones, and having a good time with whatever he happens to be involved in.
Date
Source YouTube: Analysis of FedEx ($FDX) - Stock Investment Research – View/save archived versions on archive.orgCategory:Media from YouTube
Author Ostrich Investing
Social network tags
InfoField
YouTube Tags:.
Genre
InfoField
Science & Technology
Family Friendly
InfoField
True
This video, screenshot or audio excerpt was released under the Creative Commons license option on YouTube before August 2025. (YouTube changed the license version from CC BY 3.0 to 4.0 on August 1; this was not retroactive.)
For videos uploaded or licensed after July 2025 use {{YouTube CC-BY 4.0}}
To the uploader: You must provide a link (URL) to the original file and the authorship information if available.
w:en:Creative Commons
attribution
This file is licensed under the Creative Commons Attribution 3.0 Unported license.
Attribution:
You are free:
  • to share – to copy, distribute and transmit the work
  • to remix – to adapt the work
Under the following conditions:
  • attribution – You must give appropriate credit, provide a link to the license, and indicate if changes were made. You may do so in any reasonable manner, but not in any way that suggests the licensor endorses you or your use.
Category:CC-BY-3.0#DEF%20CON%2014%20-%20Strom%20Carlson%20-%20Hacking%20FedEx%20Kinko's%20-%20How%20Not%20To%20Implement%20Stored-Value%20Card%20Systems.webm Category:Media from YouTube#DEF%20CON%2014%20-%20Strom%20Carlson%20-%20Hacking%20FedEx%20Kinko's%20-%20How%20Not%20To%20Implement%20Stored-Value%20Card%20Systems.webm
YouTube logo This file, which was originally posted to YouTube: Analysis of FedEx ($FDX) - Stock Investment ResearchCategory:Media from YouTube (archive), was reviewed on 10 November 2020 by the automatic software YouTubeReviewBot, which confirmed that this video was available there under the stated Creative Commons license on that date. This file should not be deleted if the license has changed in the meantime. The Creative Commons license is irrevocable.

The bot only checks for the license, human review is still required to check if the video is a derivative work, has freedom of panorama related issues and other copyright problems that might be present in the video. Visit licensing for more information. If you are a license reviewer, you can review this file by manually appending |reviewer={{subst:REVISIONUSER}} to this template.

Creative Commons logo
Category:License reviewed by YouTubeReviewBot#DEF%20CON%2014%20-%20Strom%20Carlson%20-%20Hacking%20FedEx%20Kinko's%20-%20How%20Not%20To%20Implement%20Stored-Value%20Card%20Systems.webm Category:FedEx Category:Computer security Category:Videos in English Category:WebM videos Category:Video display resolution 720 x 480
Category:CC-BY-3.0 Category:Computer security Category:FedEx Category:License reviewed by YouTubeReviewBot Category:Media from YouTube Category:Video display resolution 720 x 480 Category:Videos in English Category:WebM videos