5 ms·
AFAIK it only beats magnetic stripe cards, not EMV chip cards
by kaszanka 2y ago
AFAIK it only beats magnetic stripe cards, not EMV chip cards
- lxgr 2y agoEMV chip cards still contain your card number and expiry date. Skimmers would need a way to also learn the CVC2 from the back of the card to use it at most (but not all!) online merchants, but that's feasible using a small camera or a waiter/cashier accomplice doing the skimming. With Google Pay and Apple Pay, and similar mobile wallets, that number is never shared during payments (and in fact not even stored on the device).
- jjmarr 2y agoThey do, but you can't get the card number from reading the chip. The protocol is a challenge-response one based on a private key stored within the chip. https://en.wikipedia.org/wiki/Chip_Authentication_Program https://en.wikipedia.org/wiki/Chip_Authentication_Program You need to read the entire card number + cvc2 + expiry date with your camera. That's not skimming, that's just taking a photo of the card.
- worewood 2y agoYeah, and it's easily solvable with a sticker or a dremel to scrape the number off
- lxgr 2y agoYou can't dremel it out of the chip, though.
- justinclift 2y agoWell technically you can. The card won't be so usable after that though. ;)
- lxgr 2y agoDestroying the chip is easy, actually chiseling away the correct trapped electrons making up the PAN in the EEPROM is the challenge ;)
- lxgr 2y agoNo, you can most certainly get the card number and expiry via the chip and even over contactless, as it’s a vital part of transaction routing/processing. There are Android apps that can do it.
- jjmarr 2y agoIf I could I'd delete my original comment since I did more research and you're right. https://stackoverflow.com/questions/14861908/apdu-command-to-read-card-number https://stackoverflow.com/questions/14861908/apdu-command-to...
- M95D 2y agoAny responsible user will learn the CVC, like any other password, and then erase it from the card.
- lxgr 2y agoThat seems like a lot of extra effort for something that's arguably not your opsec problem, but that of the card payment industry. In the end, you'll always have to enter it on payment websites anyway.
- didntcheck 2y agoI can certainly remember mine from repeated use, but I can't say I've ever heard of someone erasing it
- catlikesshrimp 2y agoI have done it since many years ago
- justsid 2y agoYou can always tell what part of the HN regularly goes outside and interacts with normal people. I’m sorry but “just memorize the CVV and erase it from the card” isn’t something anyone really does. The comment that Google Wallet is more secure is a generally applicable comment.
- M95D 2y agoYou can always tell which part of HN does things right and which part does things easy.