3 ms·
I don't understand how these help mitigate fraud in any way. You still have to sign afterwards, there is no PIN which is the way it works in Europe. How is this
by blahkins 10y ago
I don't understand how these help mitigate fraud in any way. You still have to sign afterwards, there is no PIN which is the way it works in Europe. How is this ANY different other than harder to implement a scanner which would steal the swipe, and those are bound to get implemented sooner or later anyway.
- dkopi 10y agoThese chips are actually smartcards - ASICs that perform cryptographic operations based on a secret key inside of them. "Visa chip cards are not only more secure, they are also simple to use. Chip cards and terminals work together to protect in-store payments. A unique one-time code is generated behind-the-scenes that is needed for the transaction to be approved - a feature that is virtually impossible to replicate in a counterfeit card." Magnetic cards can be easily duplicated. A Smartcard is virtually impossible to duplicate (The NSA might be able to. A criminal won't). The Pin code is used in Europe to provide 2 factor authentication. Something you have (the card) with something you know (the PIN). Its only to prevent people from using your smart card if it's physically stolen.
- wlesieutre 10y agoNot that chip-and-pin has been invincible: http://arstechnica.com/tech-policy/2015/10/how-a-criminal-ring-defeated-the-secure-chip-and-pin-credit-cards/ http://arstechnica.com/tech-policy/2015/10/how-a-criminal-ri... Certainly harder than cloning a magnetic stripe, but the PIN verification was as simple as the reader saying "Is 1111 the right pin?" and the card responding "Yep, that's the right pin." So they took apart the cards and MITMed the response to always confirm, no matter what pin was entered. Hopefully that's been fixed by now, but with the number of readers that would need to be upgraded, I wouldn't count on fixes rolling out quickly. And who knows if there are other weaknesses?
- rconti 10y agoUnique transaction IDs
- a-saleh 10y agoThe chip is a copy-protection mechanism. This means you can't do a man in the middle attack (in your words 'steal he swipe') because the chip on the card has challenge-response protocol to authenticate. Even if you somehow steal a single response, next time the challenge will be different. That is not to say it is impossible to get the secret inside of the chip, but it is hard, often requiring partial disassembly, some sort of side-channel and you will often destroy the card in the process.
- Veratyr 10y agoThe purpose of EMV isn't really to counter physical theft, it's to counter passive theft using devices like skimmers. > How is this ANY different other than harder to implement a scanner which would steal the swipe [...] The magnetic stripe on the card is essentially just a barcode read by magnets. Like a regular barcode, it's trivial to copy. The chip on a card is actually a very low power computer that uses cryptography to produce an authentication token the scanner can present to a bank to authenticate a single purchase. It's essentially impossible to recreate the entire chip and the token can only be used on the purchase it was intended for so skimmers are pretty much dead. You can read a little more about it here http://www.firstdata.com/downloads/thought-leadership/EMV-Encrypt-Tokenization-WP.PDF http://www.firstdata.com/downloads/thought-leadership/EMV-En...
- dikdik 10y agoWhile this sounds great, I was just given a debit card with a chip in it. While extra protection is afforded at terminals built for cards with chips, I still only use the magnetic strip on my card at the 90%+ of terminals that are not built for chipped-cards.