In the late 1990s, a French engineer named Serge Humpich achieved a remarkable feat in the field of cryptography. He successfully factored a 320-bit RSA key, a type of encryption used to secure French bank cards. At the time, this was considered an impossible task by major banks, as RSA encryption was believed to be highly secure. Humpich, an electronics engineer with a deep interest in cryptography, demonstrated the vulnerability by using a counterfeit card to purchase metro tickets, proving that the flaw could be exploited in real-world situations.
Humpich intended to share his discovery responsibly, aiming to help the Groupement des Cartes Bancaires (GCB), the organization that manages French bank card systems, improve their security. He attempted to sell his findings to the GCB in a constructive way, hoping to address the issue before it could be exploited by malicious actors. However, during a meeting with the GCB, Humpich was arrested and prosecuted for fraudulent intrusion into an automated data system and for counterfeiting bank cards. His actions, while aimed at exposing a security flaw, were interpreted as illegal.
Humpich was sentenced to ten months in prison, with probation, and fined 12,000 francs. A symbolic payment of one franc in damages and interest was also made to the GCB. This case highlighted a legal gray area regarding how society treats security researchers who expose vulnerabilities in good faith. Despite no actual financial harm to banks or users, Humpich faced severe legal consequences, raising questions about the balance between security and justice.
In the wake of this case, the GCB took action by increasing RSA key lengths from 320 to 768 bits, a move aimed at making the encryption more secure. However, it wasn't until May 2007 that the underlying logical flaw in the system was fully corrected. The case remains a significant milestone in the history of applied cryptography and card payment security in France. It continues to spark discussions about how society should treat security researchers who uncover critical flaws in systems deemed secure.
French Engineer Exposes Banking Security Flaw in 1990s, Faces Legal Consequences
AI-rewritten from original reportingHow it works
cryptographyrsasecurityvulnerabilityfraudresearcher



