15 ms·
> If I try to spend $1000 on my credit card at IKEA, my bank usually calls me to confirm the transaction. However, we don't have such a system when handling our
by knz 9y ago
> If I try to spend $1000 on my credit card at IKEA, my bank usually calls me to confirm the transaction. However, we don't have such a system when handling our most important information? Why is this allowed to happen?
It's allowed to happen for the same reason the US uses credit cards without PIN numbers - a lack of desire to spend money on security/upgrades (it's easier to pass on the cost of fraud via the transaction fees), a weak regulatory structure for protecting consumers, a glacial rate of technology adoption in banking systems, and ignorance/unwillingness to evolve by customers/businesses/executives etc.
- skybrian 9y agoAt least we have cards with chips in them now, so there's some movement on this. Maybe gas stations will have them by 2020.
- gambiting 9y agoEven if they have newer terminals, they are still going to accept signature, so essentially there's zero security. The only way forward is to stop accepting the magnetic strip + signature altogether.
- a-priori 9y agoAre you sure about this? In Canada we've had chip-and-PIN for almost a decade now (2009 I believe?), and almost all merchants have chip-capable POS terminals. (Yes, really! I don't know what the delay is in the US.) These terminals still have a mag stripe reader, and our cards have mag stripes as well. But they're just for compatibility: if you try to use the mag stripe of a chip-capable card on a chip-capable terminal, it beeps at your angrily and tells you to use the chip.
- gambiting 9y agoYeah, and you just put some paint over the chip, it will beep 3 times and then let you use the signature, even for cards which are marked "electronic use only". It's a failsafe for situations when the chip is genuinely damaged, the terminal lets you sign for the transaction.
- redblacktree 9y agoWhy would you want to disable the chip?
- gambiting 9y agoI wouldn't - I'm saying someone can trivially damage the chip on a stolen card and just use the mag stripe and signature instead.
- redblacktree 9y agoAh, I get it. Thanks for the explanation.
- nucleardog 9y agoMy interac card doesn't - if the chip fails the terminal will occasionally tell me to use the magstripe but the transaction is always declined.
- rconti 9y agoAnd Canada was only, what, a decade behind Europe? :)
- u801e 9y agoI have a Sams Club credit card that has the chip & PIN feature. They state that the PIN is required when using it at Walmart and Sams Club, but I have used it in other places and have had the transaction go through with or without a signature (the latter of which was for a purchase under $50). Do the terminals have an order of preference in terms of what's required for payment. For instance, try chip+pin first, then try chip+signature, then try mag stripe+signature? If that's the case, then I don't see why all stores that have chip readers won't start using chip+PIN as a first preference for payments with chip enabled cards.
- _jal 9y agoThe chip implementation in the US provides zero incremental security. It was done as part of a liability struggle between shops and credit card providers, not to improve your life.
- snuxoll 9y agoI wouldn't say it provides NO incremental security, EMV defeats skimmers which is a pretty big issue - but until everywhere has it deployed and magstrips are no more we're still in a phase where the benefits are partial at best.
- _jal 9y ago> and magstrips are no more There is zero incremental security because of this. Why pick the lock on the door when the window is open?
- skybrian 9y agoSigh. You have to deploy the new stuff before getting rid of the old stuff. If everyone had this impatient attitude, instead of taking many years to improve credit card security it wouldn't happen at all.
- _jal 9y agoI don't know what to do with comments like this. I made a statement of fact. I'm making no normative claims, I'm describing reality. At this point in time, there is zero additional security provided by the implementation. Am I supposed to ignore reality and lie about it, because someday things will be better?
- cma 9y agoThere are already less skim targets as some stores only accept chip.
- nickbauman 9y agochips have just become another salvo in an arms race between merchants/consumers and fraudsters. A chip card is more prized than a non-chip card so the rewards for capturing one is higher so more work is justified in cracking into one.
- masklinn 9y agoDon't forget the odd US anti-fed/anti-state bend which led to your identity being smeared across thousands of untrustable private companies linked through a something never originally intended as an identification token (SSN) but having become done so for the sole reason of being nigh-universal. Had the US implemented a proper citizen's registry it could be managed as that with all the security and personal details isolation that entails, including but not limited to biometric and chipped ID cards.
- agentdrtran 9y agoThe US cannot implement a proper registry, large sections of the country would freak out.
- dforrestwilson 9y agoInteresting. What sections?
- querulous 9y agoevangelicals. they believe any sort of government issued identifier is synonymous with the biblical 'number of the beast' and a step towards biblical armageddon
- michel-slm 9y agodon't forget libertarians too.
- microcolonel 9y agoThe sane. Frankly people who use this kind of language to insist that the only way to achieve this is through the state are just looking for excuses to be mean to people who don't trust the state. We've had public key infrastructure for a long time, we have also had legal attestation; the reason we don't use these things to secure this information is that nobody cares. When the state does it, you get breaches, but nobody gets all that upset. Just look at what happened with the data breach and subsequent coverup in Sweden. One person had half a month's salary docked, and that was it.