An astonishing news story has emerged in which the manager of a prestigious golf club had a card-counterfeiting ring copy the master key to the players’ lockers, enabling them to skim cash cards and cause total losses of ¥1 billion. And the manager having the master key copied is not the only astonishing part.
【List of Astonishing Things】
- The manager had the counterfeiting ring copy the locker key. This goes without saying.
- The locker design: inserting the master key caused the PIN to be displayed. The system should simply have opened the relevant locker when the master key was inserted. When storing something like a PIN or password, it is standard practice to encrypt it irreversibly using something like a one-way hash function. The system is hopelessly flawed.
- Japan’s financial sector: in Europe and the United States, it is standard practice to reimburse losses above a certain amount. The problem of Japanese financial institutions providing no compensation whatsoever had long been pointed out, yet it seems it had still been left unaddressed. To begin with, believing that the combination of a 4-digit PIN and a magnetic stripe provides sufficient security today is as anachronistic as believing that a personal seal can serve as a means of authentication. (Oh, wait—could a personal seal still count as a means of authentication???)
Even the Financial Services Agency apparently recognized that this was unacceptable and seems to be moving toward considering compensation or some other measure as a future issue. The Bank of Japan governor has also commented that converting cards to IC cards and using vein authentication (clearly influenced by MTFG) could be considered as countermeasures.
When one thinks about it, Japan has far too few means of proving identity. I hope this incident provides an opportunity to think seriously about the issue.
