Are some petrols better than others?

May 19, 2012 39 Replies

Yes - but I'm not sure it's that simple - AC being the summer extra, especially in this weather.

Many might disagree but personal experience has shown that

What problems does it give? Poor starting/performance/misfire/consumption? Or moral objection?

Rob

How do you know if they have cloned your card?

Safest way now is the only go to the places that use the onboard chip and not the magnetic strip.

Too much of a coincidence, with cards in question were never used online and always kept in my possession. Card details were used for mobile topups in the UK hundreds of miles away from my location in places I'd never visited.

From what I can tell from the questions asked of me by the card issuer in both cases the fraudsters had the card number and expiry date, the pin and the three digit code on the signature stripe, yes everything but the 'chip' and a bit of coloured plastic. It was almost certainly a chip and pin transaction with a hacked terminal and they got the lots with a cash till that 'needed the card to be swiped' I wouldn't be surprised if they had cctv and OCR reading the three digit code in real time as well.

Despite new card numbers on every occasion I had one account repeatedly compromised over a three year period and it was only by looking at my transactions I eventually worked out where it was probably being copied, the card company didn't confirm it but once I stopped using those two filling stations the problems stopped. It's tempting to get a new card and use it only once at one of these bent outfits - one site has possibly changed ownership but the other is still run by the same 'family'

Water in fuel buggering up a fuel injector pump in the mid 70's on my dads car. Shell denied responsibility.

Weeks with fouled plugs when they dumped 'formula shell' on the UK market in the 80's. Less than one tank of fuel was enough to turn a near perfect car into a bag of nails. Of course Shell denied responsibility again eventually the truth came out as thousands were affected by their hairbrained experiment and they dropped the formulation. If they had done even one days worth of testing on a used vehicle they would have realised how bad an idea it was.

One of the biggest security flaws are the wireless terminals, the infomation although encrypted can still be recieved when transmitted.

The next flaw is simple you buy something with your own card, you already know the amount, the pin the security number , mercant number and card number day date and time of transaction so yuo have the unencryted answer

Right. So you've now got the plaintext and encrypted version. What next? Wo= rking out the cypher and key from those two is anything but straightforward= for any system worthy of being called 'encryption' in the modern sense of = the term; indeed it should be a practical[1] impossibility if the algorithm= and key length are selected correctly regardless whether you have both the= plaintext and encrypted results.

I'm not saying there may or may be flaws in these terminals, but you haven'= t pointed one out in what you've said.

Mathew

[1] It may still be theoretically possible, e.g. through bruteforce but you= would select the cipher/keylength such that the risk is for all intents an= d purposes effectively nill

Time consuming with one computer yes, but with millions of computers no, at any one time there are millions of bots round the world.

with several transactions knowing all the details of both the encrypted and unencryted infomation a pattern will exist and it wil be found.

No cipher is unbreakeable as these terminals become more common they are going to be an easy target

What cipher do they use? Is it susceptible to a known-plaintext attack? If = you do not know the answer to these questions then you are just guessing at= what vulnerabilities exist.

More to the point, you don't appear to understand how chip-and-PIN works. F= or example, the PIN is transferred only between the card reader and the car= d - it is never transmitted to the till, the bank, anywhere but the card it= self. It doesn't have to - it serves only to access the crypto module in th= e card.

I suspect you are just spreading FUD, but why exactly I am not sure.

Mathew

Yes i do know the answer to these questions, you plainly do not

I am well aware how the chip and pin system works, the reader access the chip it reads the pin , you enter the pin if the two match the transaction is authorised

That's right; I don't. Care to enlighten me?

So what made you think that the PIN would ever be sent over a wireless link?

Mathew

I never said the pin would be

On modern engines, with knock sensors and all the bollocks, true.

Oh dear; Hugh the redneck spouts s**te - again.

Hum. Oddly enough, for the past decade I've been using the one filling station locally for my diesel. A couple of months ago, because of price, I changed to another local one, which is more of an agri supplier, and off the beaten track. I wasn't looking for, and didn't expect any difference, but there was. The car had noticeable extra grunt, ran smoother and got an extra couple mpg. It's not so much the new filling station stocks great stuff, it's that the other one stocks s*it stuff.

For all practical purposes some are

ye cannae change the laws of physics

formatting link

Having 'more' of them doesn't reduce security of the encryption

It's FAR easier to get the data by more direct means.

formatting link

formatting link

[...]

formatting link
;-)

Chris

formatting link
>

I was (temporarily) banned from a "non public" online security forum for pointing out the existence of rubber hose cryptography. Apparently asking "how many of your child's digits would someone have to send to you before you gave away all your passwords" was deemed going too far. But none of the silly buggers had even thought of it as a possibility.

formatting link
>>

The only fingers required seem to be those made of fudge;

formatting link

formatting link
>

Yep, that works, but all I was suggesting was either CCTV (because people don't always cover up the keypad) or addtional circuitry in the terminal that logged the keypress directly from the keyboard.

The chip itself is the only bit that hasn't been (knowingly) hacked in the wild although some at Cambridge University have a proof of concept workaround.

formatting link

I found the same with my 2010 Triumph Bonneville. Filled it up with Tesco petrol and it was not firing properly, ride became jerky, the feel of the bike changed. As a rider you are much more sensitive to the engine noises and the feel of the bike as it pulls away, more so than sitting in a car.

So I drained the tank, put the Tesco stuff into my car, refilled the bike from one of the major forecourt filling stations.. it was running OK again.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required