6 ms·
The credit card industry is still on dial-up while thieves are using broadband
- digitalengineer 13y agoSecurity in Europe? We've had groups taking over unmanned gas stations and cash machines with our 'secure' pin. Their latest method of attack: Stand in line and spot the pin-code (just 4 numbers). Distract the person when the machine is about to give back their card and swap it for another card (a dummy that looks like it's theirs, nobody reads the card anyway). They now have your PIN and your card. With the card and the PIN they access your bank- and savings accounts. The target doesn't know it until they check their account (usually after some days). The bank will not block large transfers of money and won't notify you. What could the bank do? Well they already have my cellphone number. A SMS with you're about to transfer XXX to bank account YYYY would be nice. Or a MAC-adress savety? Allow me to add machines the way Apple does with their iPhone. Instantly block all other machines. Edit: Solutions
- darklajid 13y agoWhat's your point? That someone can get his/her card stolen? And that a PIN might be seen by an observer? That's still orders of magnitude better than 'No PIN'. And frankly, if you allow others to see your PIN you are not properly educated by your bank (I sometimes see elderly people do that and they get a pass from me) or reckless/careless (in which case I have no sympathy). Of course attack vectors exist. They always do. This very site talked about card skimmers a couple of times for example, which copy the magnetic stripe and record the PIN at the same time. As soon as you mix social engineering/clever people in the mix you have boundless opportunities. But that's a different terrain, attacking the person in front of the ATM and not the technology. In reply to your potential solutions: That 'Send SMS to phone' is implemented over here - I get my transaction codes for my mobile banking site via SMS and the message specifically restates amount and target before the TAN itself.
- digitalengineer 13y agoThey use miniature camera's in blind spots for the person using the machine, transparent foil on the numbers or even completely dummy covers on top of the real covers with prepaid phones sending the data immediately. My point is the bank can do so much more (and so easily) but they do not care. Your Credit Card act as a buffer if I understand correct. You can get the money back right? About my PIN? Yeah it doesn't work outside my country. In just 1.5 hours dive you can use that card abroad without the PIN. The banks have now blocked this by blocking the card abroad. So I need a Credit Card as well... My friend works for the biggest payment system we have around here. They do not care about these systems as they're focusing on a society without PIN/Credit Cards. Cool of course, but for now we're stuck in 1980.
- darklajid 13y agoIt seems (correct me if I'm wrong) you're assuming I'm not from Europe/not using DirectDebit. If that's the case: Both isn't true - I own a CC for roundabout 3 (4?) years, but don't trust it/don't use it a lot. That said: I see a weird trend over here as well - it seems stores are regularly switching between the card&pin method and the braindead 'just sign here' way of things. So my card can probably be abused, albeit not online and not at any ATM. I don't think we disagree a lot: There are still huge gaping holes that aren't hard to exploit. But that's still no reason _not_ to use the card&pin system (-> see article). We shouldn't stop there and wear a smug face, 'Europe is secure, we are done'. But in the light of this article we're still better off.
- digitalengineer 13y agoYou're right. But are we better off? Stolen money from Creit Cards is refunded if I'm correct. Stolen money from my Debit card is not refunded. I am to blame...
- bowlofpetunias 13y agoWait, what? What Debit Card do you use that works without PIN?
- cynwoody 13y ago> For years, consumers in Europe and many other countries have used a technology called EMV (for Europay, MasterCard and Visa), created in the mid-1990s that makes it possible for retailers to confirm payments locally instead of placing a call to your bank. That’s possible because of a chip on the card that requires you to tap in a PIN code at the point of purchase. Simple. Safe. Secure. Nope. All that proves is that you own the card. It doesn't imply that the transaction is worthy of approval by the bank. It needs to be a three-way conversation between the merchant, you, and your bank. The merchant is represented by his POS. You are represented by your phone. And the bank sits somewhere in the cloud. The merchant presents the bill to your phone. You approve the charge by entering a code on your phone. Then the bank approves your approval, and the transaction is complete. Everything is encrypted, and there is nothing to skim.
- deleted 13y ago[deleted]
- cynwoody 13y agoChip & PIN only solves part of the problem: authenticating that you are you. You could still be a deadbeat. There are three parties involved: the merchant, you, and the bank. You are ordering the bank to transfer funds to the merchant. Naturally, the bank has a say in the matter. After all, you might or not be able to afford the shiny Maybach. To keep out hackers, the whole interaction needs to be strongly encrypted. That requires the merchant, you, and the bank to be able to communicate securely. Mag stripes are not secure. But your phone, provided you are not a complete ditz, offers hope. Merchant presents bill to your phone. You approve (or not — maybe you stole the phone and don't know the code). Merchant presents your approval to the bank. The bank approves or declines, and the transaction completes or it doesn't. Eavesdroppers can intercept the encrpted interactions but can't replay them with any effect other than to raise alarms. Why isn't something like the above already in place? Because it will cost a bundle to convert, and current credit card fraud rates are at the single-digit basis point level. Actually, the reason improvements like chip and pin are not prevalent in the US is that the US has historically had better datacomm than other places, so the need to authenticate offline was less urgent. At least, that's the excuse I've heard.
- duhast 13y agoCosts of replacing infrastructure are higher than the costs of fraud. That is the reason why nothing happens. Financial institutions know how to count money.
- streetnigga 13y ago10 years of fraud cost less than the implementation of chip and pin? EU banks and finance firms must of folded half a decade ago under the crippling burden. Thankfully these wise financial institutions know how to count monies, offloading fraud costs into higher fees and fines for consumers and businesses. Else we'd all be in a bad spot.
- smackfu 13y agoCompletely depends on how much fraud there is. Maybe there is much more credit card fraud in the EU?
- andybak 13y agoWait - you're still using magnetic strip cards in the US? The recent mentions of EMV had me thinking there was some new type of security that improved on Chip and Pin but no - you haven't even had that yet. What was the hold-up? This was launched in the UK ten years ago.
- deleted 13y ago[deleted]
- cbhl 13y agoMerchant adoption. Nobody wants to pay for new EMV-capable payment terminals; heck, at a conference I went to two years ago, people were still using carbon copy credit-card processing machines (!). In the SF Bay Area, every merchant that uses Square as a payment processor can only process mag-stripe transactions. Square supports neither Chip and PIN nor NFC/PayPass/PayWave transactions -- by design. (This leads to a "better customer experience", IIRC.) OTOH, the huge machine-learning machinery built by credit-card processors in the US has helped mitigate much of this risk; I've had enough false positive declines that I'm confident that the fraud-prevention systems currently used, while expensive, work in 90+% of cases. Edit: I should mention that in Canada, Chip-and-PIN roll-out occurred concurrently with the roll-out of NFC/PayWave/PayPass, so the "increased" security of PIN was offset by the ability to read your credit card wirelessly. The banks mitigate this by limiting PayWave/PayPass transactions to ~$100 (it's meant to be used for things like going to McDonald's or Tim Horton's/Starbucks).
- bowlofpetunias 13y agoI think the problem is that the US never made the jump to instant Debit Card payments in the first place, and is still stuck with in a world of using either Credit or cash. In the Netherlands, cash is on the way out due to the massive adoption of instant Debit Card payments for even the smallest purchases. Merchants prefer not to handle cash because it's safer (robbing a store with no money is pointless) and cheaper (no dealing with money transports, deposits, counting the registers, having change on hand). Compared to all of that, getting card terminals is cheap. Using the same system for Credit Cards is mostly just a side-effect of the push to eliminate cash. It's also the reason Credit Card usage isn't all that widespread in the Netherlands. They're only used for big ticket items (sparingly), on vacation and for international online purchases.