Important!

Blog moved to https://blog.apdu.fr/

I moved my blog from https://ludovicrousseau.blogspot.com/ to https://blog.apdu.fr/ . Why? I wanted to move away from Blogger (owne...

Friday, January 6, 2012

MUSCLE mailing list statistics for 2011

A new year is a good time for analysis of the past. As I did in 2009 and 2010 I propose some statistics of the MUSCLE mailing list usage.

I also note that the number of messages is increasing each year:
Year Total number of messages Progression
2009603
2010718+19%
2011999+39%



Statistics from 3.1.2011 to 31.12.2011
for muscle@lists.musclecard.com



People who have written most messages:

 Author  Msg  Percent 
1ludovic.rousseau@gmail.com29529.53 %
2jmpoure@gooze.eu787.81 %
3martin@martinpaljak.net626.21 %
4squalyl@gmail.com202.00 %
5aquamaniac@gmx.de202.00 %
6ruckuus@gmail.com181.80 %
7wrosenauer@gmail.com181.80 %
8mstjohns@comcast.net161.60 %
9kalevlember@gmail.com161.60 %
10kgo@grant-olson.net141.40 %
11s.ferey@wanadoo.fr141.40 %
12Alexei.Soloview@intech.natm.ru121.20 %
13listen@kapune.de121.20 %
14chris@boyle.name121.20 %
15aj@dungeon.inka.de121.20 %
16malte.gell@gmx.de101.00 %
17=?UTF-8?Q?Jes=C3=BAs_J=2E_Guerrero_Botella?=101.00 %
18kalev@smartlink.ee101.00 %
19widerstand@t-online.de101.00 %
20opensc@secure-edge.com101.00 %
21sebastien@lorquet.fr101.00 %
22hardik.shah@jetmobile.com90.90 %
23fracting@gmail.com80.80 %
24michaelbender@me.com80.80 %
25hpj@urpla.net80.80 %
26a_s_y@sama.ru80.80 %
27stef.hoeben@zetes.com80.80 %
28anze.stojilkovic@policija.si80.80 %
29vickylinuxer@gmail.com80.80 %
30deengert@anl.gov80.80 %
other24724.72 %

Best authors, by total size of their messages (w/o quoting):

 Author  KBytes 
1hardik.shah@jetmobile.com261.2
2ludovic.rousseau@gmail.com247.6
3jmpoure@gooze.eu178.8
4lyall.pearce@hp.com109.7
5kgo@grant-olson.net97.8
6marc_m@gmx.at83.4
7lyall.pearce@gmail.com83.1
8kalev@smartlink.ee79.6
9ruckuus@gmail.com78.8
10Alexei.Soloview@intech.natm.ru76.6
11squalyl@gmail.com64.5
12martin@martinpaljak.net58.5
13mariano.benedettini@qmas.com50.6
14anze.stojilkovic@policija.si48.9
15Christophe.Troestler@umons.ac.be42.9
16stef.hoeben@zetes.com41.1
17atlanticoglobal@gmail.com39.8
18cpfigueiredo@gmail.com39.4
19helpcrypto@gmail.com29.9
20hannu.kotipalo@iki.fi26.0
21kabuba.gachugu@gmail.com23.1
22vickylinuxer@gmail.com21.4
23hpj@urpla.net20.8
24jeffcapanan@gmail.com19.7
25fgoulart@fmagj.com.br19.5
26chris@boyle.name19.0
27=?UTF-8?Q?Jes=C3=BAs_J=2E_Guerrero_Botella?=18.5
28aquamaniac@gmx.de18.2
29listen@kapune.de16.9
30detlef.graef@yahoo.de16.4

Best authors, by average size of their message (w/o quoting):

 Author  bytes 
1hardik.shah@jetmobile.com29719
2lyall.pearce@hp.com28091
3lyall.pearce@gmail.com21277
4marc_m@gmx.at14239
5fgoulart@fmagj.com.br9974
6mariano.benedettini@qmas.com8632
7detlef.graef@yahoo.de8402
8kalev@smartlink.ee8148
9pwt@iosis.co.uk7460
10Christophe.Troestler@umons.ac.be7324
11kgo@grant-olson.net7150
12atlanticoglobal@gmail.com6786
13cpfigueiredo@gmail.com6730
14Alexei.Soloview@intech.natm.ru6532
15anze.stojilkovic@policija.si6262
16rodneygroups@gmail.com5941
17kabuba.gachugu@gmail.com5913
18edgardovaz@gmail.com5839
19stef.hoeben@zetes.com5263
20kmichelx@gmail.com5127
21ruckuus@gmail.com4481
22hannu.kotipalo@iki.fi4429
23helpcrypto@gmail.com4380
24veeru_d2001@yahoo.co.in3896
25sschwab@hidglobal.com3877
26sebastien.lorquet@gmail.com3712
27jeffcapanan@gmail.com3360
28squalyl@gmail.com3300
29kristen.eisenberg@yahoo.com3195
30venkat.meritup@gmail.com3155

Table showing the most successful subjects:

 Subject  Msg  Percent 
1[Muscle] Access to multiple contactless cards using PCSC-Lite363.60 %
2[Muscle] PCSC Daemon cannot access Cyberjack reader303.00 %
3[Muscle] PC/SC workgroup, November 2011 meeting303.00 %
4[Muscle] GlobalPlatform Library & GPShell documentation now online262.60 %
5[Muscle] PCSCD got segmentation fault on ARM v5 with uClibc262.60 %
6[Muscle] Woxter SmartCard reader202.00 %
7[Muscle] Speed detection patch when reader has no baud rates181.80 %
8[Muscle] [PATCH 3/3] Install systemd service files181.80 %
9[Muscle] Re: Need help with G&D USB-Shield161.60 %
10[Muscle] Where to buy a compact reader with secure PIN entry?161.60 %
11[Muscle] Systemd support161.60 %
12[Muscle] ERROR: proto-t1.c:479:t1_transceive() CT sent S-block141.40 %
13[Muscle] Confused about libccid forks and ACS PINPAD support141.40 %
14[Muscle] SafeNet Smartcard 330141.40 %
15[Muscle] [PATCH 2/3] Add --disable-autostart option141.40 %
16[Muscle] reading sims121.20 %
17[Muscle] I'm trying to get libccid to support an ACR83 reader121.20 %
18[Muscle] segfault with 1.6.7 (1.7.0 valgrind)121.20 %
19[Muscle] Re: pcscd: Open Port 0x200001 Failed121.20 %
20[Muscle] Cardman 4040 support in libccid121.20 %
21[Muscle] (no subject)121.20 %
22[Muscle] I need help a diagnosis of a smart card (or pcscd)121.20 %
23[Muscle] How to identify a java card?121.20 %
24[Muscle] issues with CCID with AU9540 and MAC121.20 %
25[Muscle] SCard Transmit Transaction Failed121.20 %
26[Muscle] libmusclecard and muscleframework removed from Debian101.00 %
27[Muscle] Problem writing an IFD Driver101.00 %
28[Muscle] Re: PCSC Daemon cannot access Cyberjack reader101.00 %
29[opensc-devel] [Muscle] Setting reader speed when only one101.00 %
30[Muscle] IFD_RESPONSE_TIMEOUT for PHSetProtocol101.00 %
other52152.15 %

Most used email clients:

 Mailer  Msg  Percent 
1(unknown)54854.85 %
2Mozilla/5.x16816.82 %
3KMail707.01 %
4Evolution 2.32.3 525.21 %
5QUALCOMM Windows Eudora161.60 %
6Microsoft Office Outlook 12.0141.40 %
7Apple Mail (2.1082)121.20 %
8Apple Mail (2.1084)121.20 %
9Evolution 2.32.2 101.00 %
10Apple Mail (2.936)101.00 %
11Evolution 2.30.3 80.80 %
12git-send-email 1.7.5.480.80 %
13Evolution 3.0.3-2 80.80 %
14Mew version 6.3.50 on Emacs 23.3 / Mule 6.0 (HANACHIRUSATO)60.60 %
15Lotus Notes Release 8.560.60 %
16Zarafa 6.40.5-2486060.60 %
17Apple Mail (2.1244.3)40.40 %
18YahooMailWebService/0.8.113.31361940.40 %
19Evolution 3.0.2- 40.40 %
20YahooMailClassic/11.4.20 YahooMailWebService/0.8.107.28525920.20 %
21Alpine 2.00 (LNX 1167 2008-08-23)20.20 %
22YahooMailClassic/14.0.1 YahooMailWebService/0.8.111.30309620.20 %
23YahooMailClassic/14.0.3 YahooMailWebService/0.8.112.30774020.20 %
24YahooMailRC/572 YahooMailWebService/0.8.112.30774020.20 %
25Internet Messaging Program (IMP) H4 (5.0.10)20.20 %
26WWW-Mail 6100 (Global Message Exchange)20.20 %
27YahooMailClassic/14.0.5 YahooMailWebService/0.8.113.31562520.20 %
28Internet Messaging Program (IMP) H4 (5.0.11)20.20 %
29QQMail 2.x20.20 %
30Alpine 2.00 (LFD 1167 2008-08-23)20.20 %
other111.10 %

Table of maximal quoting:

 Author  Percent 
1jesus.guerrero.botella@gmail.com81.57 %
2deengert@anl.gov77.50 %
3extramrdo@gmail.com75.88 %
4fabeisageek@googlemail.com73.39 %
5s.ferey@wanadoo.fr72.48 %
6sebastien@lorquet.fr71.47 %
7michaelbender@me.com64.76 %
8fundu_1999@yahoo.com63.71 %
9richter@ecos.de62.73 %
10andreas.schwier@cardcontact.de59.27 %
11widerstand@t-online.de54.61 %
12bjoernk2@googlemail.com53.67 %
13opensc@secure-edge.com50.88 %
14ffred69@gmail.com50.08 %
15vladimir.davydov@promwad.com49.51 %
16tomas@primekey.se48.09 %
17ludovic.rousseau@gmail.com46.60 %
18vdsrst@gmail.com43.55 %
19squalyl@gmail.com41.25 %
20kmichelx@gmail.com41.06 %
21kabuba.gachugu@gmail.com39.46 %
22anze.stojilkovic@policija.si39.33 %
23martin@martinpaljak.net38.74 %
24kalevlember@gmail.com37.34 %
25aj@dungeon.inka.de36.72 %
26tarun.khandelwal@jetmobile.com35.92 %
27vickylinuxer@gmail.com34.93 %
28mstjohns@comcast.net34.43 %
29venkat.meritup@gmail.com33.56 %
30wrosenauer@gmail.com32.81 %
average23.92 %

Graph showing number of messages written during hours of day:

msgs35
|
4
|
8
|
10
|
2
|
2
|
0
|
8
|
23
|
73
|
73
|
82
|
52
|
80
|
72
|
101
|
71
|
47
|
56
|
22
|
41
|
44
|
51
|
42
|
hour 01234567891011121314151617181920212223

Graph showing number of messages written during days of month:

msgs33
|
18
|
25
|
34
|
34
|
14
|
18
|
66
|
28
|
22
|
20
|
32
|
46
|
14
|
8
|
22
|
26
|
36
|
23
|
44
|
32
|
42
|
26
|
26
|
90
|
42
|
46
|
40
|
32
|
30
|
30
|
day 12345678910111213141516171819202122232425262728293031

Graph showing number of messages written during days of week:

msgs114
|
159
|
142
|
187
|
228
|
96
|
73
|

MonTueWedThuFriSatSun


Maximal quoting:

Author : extramrdo@gmail.com
Subject : [Muscle] issues with CCID with AU9540 and MAC
Date : Sat, 27 Aug 2011 11:14:08 -0400
Quote ratio: 92.45% / 4453 bytes

Longest message:

Author : ludovic.rousseau@gmail.com
Subject : PC/SC workgroup, November 2011 meeting
Date : Tue, 25 Oct 2011 14:31:08 +0200
Size : 46138 bytes

Most successful subject:

Subject : [Muscle] Access to multiple contactless cards using PCSC-Lite
No. of msgs: 36
Total size : 232036 bytes

Final summary:

Total number of messages: 999
Total number of different authors: 100
Total number of different subjects: 158
Total size of messages (w/o headers): 3187940 bytes
Average size of a message: 3191 bytes


Input file last updated: Fri Jan 6 09:29:07 2012Generated by MailListStat v1.3

Sunday, December 18, 2011

new version of pcsc-tools: 1.4.18

I just released a new version of pcsc-tools. No new feature but some enhancements.

If you do not know what pcsc-tools is, it contains 4 tools:
  • pcsc_scan(1) regularly scans every PC/SC reader connected to the host if a card is inserted or removed a "line" is printed.
  • ATR_analysis(1) is a Perl script used to parse the smart card ATR. This script is called (by default) by pcsc_scan.
  • scriptor(1) is a Perl script to send commands to a smart card using a batch file or stdin.
  • gscriptor(1) the same idea as scriptor.pl(1) but with a Perl-Gtk2 GUI.

An equivalent of ATR_analysis is available online http://smartcard-atr.appspot.com/

Changes:
1.4.18 - 18 December 2011, Ludovic ROUSSEAU
  • gscriptor: Display hex dumps in lines of 16 bytes instead of 17
  • gscriptor: Display bytes of value 0x20 as ' ' instead of '.'
  • scriptor: Display lines of 16 bytes instead of 24
  • 223 new ATRs
  • pcsc_scan: Correctly detect reader Plug and Play support

Wednesday, December 14, 2011

Short APDU readers supporting limited extended APDUs

Because of a bug report on the OpenSC mailing list I discovered that some CCID readers declare to support Short APDU only but can in fact accept APDU with more than 256 bytes of data.

I found only 2 readers with this particularity in my list:

Technical details

These 2 readers declare in the USB descriptor (the .txt file):
  • Short APDU level exchange in dwFeatures
  • a dwMaxCCIDMessageLength greater than 271 bytes

Effects

These readers declare to be short APDU so they should not be able to send or receive more than 256 bytes of data. 256 bytes of data + 5 bytes of header (CLA, INS, P1, P2, Lc) = 261 bytes. With the 10 bytes of CCID header we have the 271 bytes indicated in dwMaxCCIDMessageLength for all the (normal) Short APDU readers.

Up to version 1.3.12 (May 2010) my CCID driver would not support APDU bigger than 261 bytes with these readers. For example Mac OS X provides the CCID driver version 1.3.8 (June 2008). But in version 1.3.12 I modified the buffer size from 261 bytes to 64k bytes. This was needed for extended APDU readers.

The side effect of the change in version 1.3.12 is that the CCID driver will not reject APDU commands greater than 261 bytes.

Results

The Xiring MyLeo reader will support APDU of up to 512 bytes (522 minus 10 bytes for the CCID header).

The TianYu CCID SmartKey reader/token will support APDU of up to 502 bytes (512 minus 10 bytes for the CCID header).

If you want to use (limited) extended APDU with these readers on Mac OS X you have to upgrade the CCID driver to at least version 1.3.12.

Conclusion

These two readers are using a strange CCID combination. I do not say it is illegal but it is clearly a hack to support some form of (limited) extended APDU.

Monday, December 12, 2011

PC/SC workgroup, November 2011 meeting results

The PC/SC workgroup, November 2011 meeting is now over. The meeting minutes are available to PC/SC members. But this document is not public.

Here are the results about issues I reported for the meeting.

Extended APDU support reported by PC/SC

See the previous article Extended APDU support reported by PC/SC. The idea to for an application to be able to know if a reader+driver do support extended APDU.

The new version of PC/SC v2 part 10 describing the solution is not yet available. But the solution works like this:
  • The application uses SCardControl(FEATURE_GET_TLV_PROPERTIES, ...) and look for the tag dwMaxAPDUDataSize.
  • The value of dwMaxAPDUDataSize gives the maximum APDU data size supported by the reader+driver.
This proposal has been accepted.

Identifying a reader model

See the previous article Identifying a reader model. The idea is to be able to precisely identify a reader model before sending (potentially dangerous) SCardControl() commands.

The new version of PC/SC v2 part 10 describing the solution is not yet available. But the solution works like this:
The application uses SCardControl(FEATURE_GET_TLV_PROPERTIES, ...) and look for the tags PCSCv2_PART10_PROPERTY_idVendor and PCSCv2_PART10_PROPERTY_idProduct. These are the USB vendor ID and product ID of the device.

This proposal has been accepted.

Changes in PC/SC workgroup documents

Request: The PC/SC workgroup specifications contain a "Revision History" section with a brief description of the changes. It would be even better to have all the changes directly visible within the document.

The documents will be available as Word files in the member only area of the web site. Changes will be available as track changes.

No good news for non PC/SC workgroup members. You will have to compare two versions of the specification by hand (as before).

Firewalled pinpad

Request: The PC/SC workgroup should define the status word (SW1 and SW2) to be reported by the reader if a command is rejected by the firewall.

This is outside the scope of the PC/SC workgroup.

FEATURE_WRITE_DISPLAY, FEATURE_GET_KEY and FEATURE_VERIFY_PIN_START

Request: Document how FEATURE_WRITE_DISPLAY, FEATURE_GET_KEY and FEATURE_VERIFY_PIN_START should or could be implemented at the CCID level.

A subcommittee will be created to work on the question.

Unblock PIN feature and PIN merge feature

This is outside the scope of the PC/SC workgroup. You should contact the manufacturer if the reader is not working as expected.

Conclusion

My two main issues have been accepted.

The other requests have been discussed but rejected. It is not really surprising since the proposals were not described in details. For example the code returned by PC/SC when a command is refused by a firewalled pinpad may be accepted at a later meeting if correctly presented and described.

Saturday, December 3, 2011

libusb-1.0.9-rc3

The libusb 1.0.9 adventure is still ongoing. In a previous article "libusb 1.0.9-rc1" I announced that the 1.0.9 official/stable version was expected for 21st of September 2011. Of course this did not happen :-(

With the upgrade of the Linux kernel in lots of distributions it looks like the 60 seconds delay issue is more present and/or occurs more often. So I get more bug reports. The problem is not pcsc-lite or the CCID driver. The bug is in libusb.

History of the bug #56


This is the 4th article about this libsub bug. We already had:

How to get a fixed libusb?

$ git clone git://git.libusb.org/libusb.git
$ cd libusb
$ git branch testing origin/testing
$ git checkout testing

If you want to use an already prepared .tar.bz2 archive I provide one at http://ludovic.rousseau.free.fr/softwares/pcsc-lite/libusb-1.0.9-rc3.tar.bz2.

Conclusion

A lot of time and energy is lost by users of smart cards reporting bugs, and by me answering to bugs.

The bad news is that I don't see any positive signal for the future of libusb. I will continue to refer to the this article for any bug report mentioning a 60 seconds delay.

Thursday, December 1, 2011

EMV-CAP article now available online

In a previous article "EMV-CAP in MISC Magazine n°56" I presented a paper published in the French magazine MISC. The paper is now available online.

Thanks to Philippe Teuwen, co-author of the article, for the info.