6 ms·
encouraging that they are using this as a motivator to "roll out EMV "Chip and PIN" to all U.S. stores by the end of this year" ahead of the prescribed deadline
by ryanburk 12y ago
encouraging that they are using this as a motivator to "roll out EMV "Chip and PIN" to all U.S. stores by the end of this year" ahead of the prescribed deadline.
edit: "Chip and PIN" is taken directly from the sec filing that is linked.
the described deadline of october 2015 for the liability shift comes from banks[1] and not a US law or similar.
[1] http://en.wikipedia.org/wiki/EMV#United_States http://en.wikipedia.org/wiki/EMV#United_States
- dublinben 12y agoIs there actually a timetable for "chip and pin" in the US? I'm only aware of banks issuing chip + signature style EMV cards.
- mfrommil 12y agoPCI deadline for US retailers to implement chip + pin is October 2015. Mentioned in the Home Depot link above
- happyscrappy 12y agoMany don't read the article and just start commenting.
- jobu 12y agoIn all fairness, SEC filings are a rather incomprehensible format to read, even one this short.
- happyscrappy 12y ago"Responding to the increasing threat of cyber-attacks on the retail industry, The Home Depot previously confirmed it will roll out EMV "Chip and PIN" to all U.S. stores by the end of this year, well in advance of the October 2015 deadline established by the payments industry." Don't excuse laziness.
- Johnie 12y agoYes, they may say that. However, Home Depot is not the one that is determining what technology the issuers use. Most issuers are using Chip&Signature. Home Depot may support Chip and Pin, but if your bank doesn't use Chip&Pin, the fact that Home Depot supports it is worthless to you.
- cmurf 12y agoI'm pretty sure the merchant equipment is going to support either chip&signature or chip&pin, seeing as we already have signatures for credit card, and PINs for debit card transactions. The difference will be up to the card issuers. And I for one hate digital "esignatures" talk about all kinds of fraud waiting to happen with that bullcrap. I want to use either PIN or ink on paper signature. Make me use a screen to sign my name, and I'm signing it mickey mouse.
- ryanburk 12y agoI took that straight from the article / filing. and been impressed by the downvotes!
- serf 12y agowhile I don't condone blind commenting like you described, I have encountered threads with titles such that they conveyed the entire article accurately enough to comment on from just the title alone, so I can understand that with certain topics.
- zippergz 12y agoWhen will banks actually start issuing chip + pin cards in the US? It doesn't help US consumers much if the retailers accept them, but the banks don't issue them. I have credit cards with four banks (probably the biggest 4 in the US, but I don't know exactly how they stack up). One is chip+signature, and the rest don't have chips at all. Including a brand new one I got from a huge bank less than a month ago.
- bdb 12y agoAfter the EMV liability shift date (October 2015), the fraud liability for a card-present, non-EMV transaction falls on the party which was noncompliant, the issuer or the merchant. Hopefully this will be a significant driver of EMV adoption by both issuers and merchants.
- zrail 12y agoBoth cards that I recently received have a chip. One of them is a debit card so it already has a pin, and presumably at some point I'll at least have the option to get a pin for my credit card.
- zippergz 12y agoMy understanding (and it's entirely possible I'm mistaken) is that chip+pin and chip+signature cards are not interchangeable. In other words, I don't think you can just take a chip+signature card and "get a pin" for it. And the one card I've received with a chip (from Bank of America) is definitely chip+signature. I'd love to be told I'm wrong, and that this can be made into a chip+pin card without physically swapping the card.
- zrail 12y agoI had no idea that it wasn't possible to get a pin, but now having done some research it looks like I was wrong. I wonder if it has something to do with them using the existing pin infrastructure for ATM cash advances.
- 12y ago
- Johnie 12y agoIt's not clear if US is going to be Chip+Pin or Chip+Signature. This is going to add some confusion come next year.
- terinjokes 12y agoWhen I enquired my bank about my EMV card, they informed it that it preferred Chip+Signature, but that it also supported online (aka "realtime") Chip+Pin authorization. It is not configured to support offline Chip+Pin like many european cards.
- JimmaDaRustla 12y agoPIN verification is performed against the chip first, not online. Although Chip+Signature is possible, it really doesn't make sense. Edit: Chip cards provide a Cardholder Verification Method List (CVML) to the terminal. The terminal then decides what method it'd like to use. Options are PIN online, PIN offline plain text, PIN offline enciphered, Signature, or No Authentication.
- olentangy 12y agoMost US banks are going for chip and signature. I've received two new cards in the last month with a chip in them - both were chip and signature.
- cmurf 12y agoI had an AMEX Blue Business card with an RF chip in it, transaction receipts had a completely different last 4 digits using RF vs magnetic. I called to see if I could get a chip+pin and they said yes except it's chip+signature. So at least U.S. AMEX is chip+signature. However, the card's chip "pin out" area is shaped smaller and differently arranged than the one on my bank issued card. So we apparently have two different "chip" standards and I don't know which one is actually going to get used.
- hellbanTHIS 12y agoI got into an argument about that with the guy at the Home Depot paint counter today. I blamed the hack on Home Depot probably running XP on their POS machines and he blamed the banks not doing something that they do in Europe, I'm assuming it's this EMV chip because it sounded like he was repeating something he was told.
- ams6110 12y agoWhy on earth would you argue this issue with the guy at the paint counter? He clearly has nothing to do with either the cause or any remedy they might decide to offer.
- unclebucknasty 12y agoNo kidding. Until now, I'd have been hard-pressed to imagine any sentence that started with "I got into an argument with the guy at the Home Depot paint counter", but didn't end with "because my paint color didn't match".
- hellbanTHIS 12y agoAll the computers for the paint mixing machines in every Home Depot were screwed up today, which brought up the topic of the hack and he got excited when I suggested it was probably outdated software on the point of sales machines that was to blame. The interesting part to me was it sounded like the managers explained to them that it was all the bank's fault. Not that Home Depot was too cheap and lazy to update their software. And ya got to talk about something while the paint's shakin
- heywire 12y agoDo you have reason to believe that Windows 7 instead of Windows XP would have prevented this attack? It sounds like weak credentials and overall lax security are more to blame. edit: Also, keep in mind that some retailers are running POSReady 2009 / POSReady 7, which may look just like Windows XP at first glance.
- ufmace 12y agoWould it actually have helped, though? I was under the impression that the Chip and PIN POS terminals don't do anything differently as far as the part between themselves and the authorizer goes - if somebody hacks one, they can still get everything they need to charge against the card. If so, it's more of an issue of firewalling properly at the individual store and corporate level.
- gergles 12y agoYour impression is incorrect. Current EMV cards do something called DDA, so charging the card (as a card-present transaction) requires the card to be physically present or you to have cloned the application off the card (which the card is designed to prevent you from doing.) You can still get the magstripe data if you compromise the terminal, but the network will (eventually) reject magstripe transactions made by a chip-capable card in a chip-capable reader. You can get the transaction certificate for one transaction, but that TC is protected from replay attacks.
- amckenna 12y agoYup you are correct. The chip acts as a proof of presence and a second factor of authentication. It is technically possible to export the cert off of the chip but it would cost several hundred thousand dollars and a lab with a Focused Ion Beam :)
- JimmaDaRustla 12y agoYou're supposed to say CDA now - combined data authentication.