6 ms·
The real solution here is to have contactless chip & pin systems at the pump, but apparently that is years away because of cost. In the meantime I find the best
by skeuo 11y ago
The real solution here is to have contactless chip & pin systems at the pump, but apparently that is years away because of cost. In the meantime I find the best way to monitor my CC expenses is to enable SMS/Push alerts for any transaction above $0. This way I always expect to get an alert at the point of sale for any transaction. Anything unknown is a red flag and it also works well for subscriptions that I may forget about and want to cancel.
- pki 11y agoIt's a shame that chip and signature is used in the states though..
- toast0 11y agoThe problem with chip and pin is: A) you want me to type my pin into a compromised device, the pinpad at the pump B) you expect me to remember seven pins, I carry seven credit cards (yes that's excessive) and each should have a separate pin for security, right?
- Retric 11y agoNo, an actual chip should be secure enough to make skimmers pointless. However, we somehow desided to built and roll out a completely insecure chip system. Ex of a simple and secure system. cc shows transaction cost, user clicks ok on the card. Card digitally signs a transaction with time stamp, vender ID, and amount. Want safe online transactions, add a USB dongle or Bluetooth.
- TwoBit 11y agoDo you have a reference for why it's "completely insecure"?
- Terr_ 11y agoI think the idea is that it's reasonably-secure against skimmers taking your data and then re-using that data in another session or location when the card is absent. But it won't save you from a compromised point-of-sale system that lies to you about how much you're paying or which commits fraudulent transactions while the card is still in the reader.
- lazaroclapp 11y agoWhich is why the amount should be displayed on a display embedded in the card itself. The control for authorizing the transaction should also be part of the card. Now, if only we carried around a device that included a display and some sort of input mechanism, plus a near-distance communication chip... (Ok, if the device is a general computing device, a special secure operation mode might be needed for this sort of use case, one which can't be subverted by normally installed software, but still...)
- pki 11y ago> special secure operation mode might be needed for this sort of use case, one which can't be subverted by normally installed software Now people will complain that "the app doesn't run on their rooted, bootloader unlocked, jailbroken phones"
- lazaroclapp 11y agoNo reason why it shouldn't. This is not DRM, is your own credit, secured on your behalf. It should just be resistant to software based tampering by default. Specially, as I said, "normally installed software". If you can make sure that rooting your device requires a explicit knowledgeable user interaction (say: rebooting, erasing all data, then re-keying your device to your bank account somehow - in person visit?), then I see no reason why you should be prevented from changing the secure operation mode code itself or building your own compatible device. I mean, you can mod the brakes on your car if you really want to, at your own risk. What is a bit strange is when your media player can affect your brakes without you even noticing. Same principle here, less lives on the line.
- xxpor 11y agothe pin is useless without the chip. it's only one half of the something you have + something you know.
- cballard 11y agoWhat is the point of the sigature? Mine never look even close to the same. Is this a serious security mechanism? If you're not going to do chip and PIN (and you should), why not just chip and nothing?
- jon-wood 11y agoWhen working a retail job I once (and only once) saw a credit card with a photo of the person it was issued to on the back. It was also about the only card I really bothered to check ownership on because signatures were useless. Thankfully we've now got chip & pin, completely removing the need for minimum wage retail staff to verify ownership of credit cards.
- deleted 11y ago[deleted]
- icebraining 11y agoIs this a serious security mechanism? NPR's Planet Money recently did a story on the signature in CC payments. The answer seems to be "not really".
- nickt 11y agoHere it is, Planet Money Ep. 564: The Signature (16:20) "Today on the show: the signature. It's supposed to say, "This is me." But where did the idea come from? And why are we still using it? We consult a rabbi, a lawyer and a credit card executive." http://www.npr.org/sections/money/2014/08/29/344034815/episode-564-the-signature http://www.npr.org/sections/money/2014/08/29/344034815/episo...
- knughit 11y agoThe signature is just a bit of evidence to check if you dispute a charge. It isn't a 99.99% key like in encryption.
- superdude 11y agoWhat service or cards offer SMS alerts for any transaction? The best I have it American Express which will alert me only when I have a transaction over $10. V.me by Visa used to offer an alert service for any amount and it was great, but unfortunately that service got shut down.
- thrownaway2424 11y agoDoes it have to be SMS? My Simple card notifies me every time the card is used. https://www.simple.com/ https://www.simple.com/
- superdude 11y agoAny push notification would be ok, but SMS is preferred because it's more reliable for me. The Visa service V.Me was great because you could use any card, even all the specialty rewards cards, and they didn't even have to be Visa cards!
- jlgaddis 11y agoI have "in-app" alerts (push notifications) enabled for a Discover card and two AmEx cards but they are set at relatively high amounts ($500, IIRC). I haven't checked to see how low they can be set. That requires you have their apps installed, however. I'm not sure if you can get them via SMS.
- e40 11y agoAll the banks I deal with offer it. Chase. USAA. Citibank. Capital One.
- cortesoft 11y agoI just checked (and enabled) the texts for any amount over $0 on my Chase card.
- dmourati 11y agoSame, but I chose $1.
- cbhl 11y agoI wonder if it would be secure enough/cheaper to retrofit these pumps with NFC readers.
- bonestamp2 11y agoWhen I lived in Canada almost 10 year ago, most pumps have contactless readers... so if Canada can do it then it's probably doable here. (It wasn't NFC exactly, but similar technology)
- braythwayt 11y agoCanada has an oligopoly of banks, so there are things Canada can do that seem to be difficult for the US, and vice versa. In this case, when all five banks decided to go to pin-enabled credit cards, they just did it. Retailers were given a certain amount of time to switch over, “or else.” There are few alternatives, so the entire country moved forward. Whereas, south of the 49th parallel, there is all kinds of competition for credit cards and for merchant services, so if a few banks don’t feel like sending out cards with chips an PINs, they don’t. And if a few retailers don’t want to go to the expense of upgrading their systems, they don’t have to. On the flip side... There is nearly zero Apple Pay up here.
- jon-wood 11y agoAlmost all recent snack vending machines in the UK support contactless payment. if it's economical to do for £0.50 snacks, it'll work for fuel pumps.
- brewdad 11y agoIs this really necessary though? Personally, none of my cards will allow me to dispute a transaction until it posts as a charge not merely an authorization. Seeing as you have 60 days after posting to dispute a charge, immediate notification seems like overkill. I could see the usefulness for subscriptions or to shutdown a shopping spree before it gets out of hand I guess.
- 13of40 11y agoIt would be nice if you could have some kind of "leading edge" trigger on it, so if there's a transaction from a merchant that's unique in, say, the last two months, you get an SMS. If someone steals your credit card and goes on a shopping spree they're unlikely to do it at the same stores you go to.
- tzs 11y ago> Seeing as you have 60 days after posting to dispute a charge, immediate notification seems like overkill. It's often much more than 60 days. We had a chargeback at work that was a couple months over a year old. That surprised me...I had thought that a year was the limit. That's not actually the most surprising thing I learned about credit cards last year, though. We got a notification from the payment processor near the end of the year that a charge from March had been reported as a success but actually failed. By "reported as a success" I do not just mean that the API had reported success on the charge. The payment processor had also reported later that it had successfully settled. They just never actually transferred any money to us. While talking to them on the phone the payment processor rep then told me that the same thing had happened on the charges on this customer's monthly subscription for all subsequent months. According to the payment processor rep, the customer had told his bank that he no longer wanted our service (but neglected to tell us...). The card was still good, and so the bank still said "approved" when we would try to charge it, then would apparently later notice that the customer did not want the charge and somehow arrange to block settlement, and the payment processor apparently has no way to report this. Notice how messed up this is: you can put through a charge on a credit card, have the issuing bank and payment processor tell you it went through, have it settle according to the payment processor, have it show up as successfully settled in all reports from the payment processor...but the money just doesn't show up. Unless the payment processor tells you about this, the only hint you'll have that something is wrong is that there will be a discrepancy between what is supposed to have shown up in your bank account and what actually showed up, and you won't have any way to tell which charge is the one that silently failed.