Krebs has a post on this as well: https://krebsonsecurity.com/2017/01/atm-shimmers-target-chip... “The only way for this attack to be successful is if a [bank card] issuer neglects to check the CVV when authorizing a transaction,”
I have not had the largest confidence in banks abilities to understand security. I've personally dealt with: 1) 'Two factor auth is on, you have to answer two security questions to access your account!' 2) 'Your password is limited to exactly 8 characters ... for security' 3) 'Oh, we now support SMS two factor auth' -- 4 months in, I've received 1 SMS challenge 4) 'You don't want a chip card, they are more hassle' 5)…
> 1) 'Two factor auth is on, you have to answer two security questions to access your account!'
That's awful! By using the two-factor wording it's deliberately misleading people who don't know much about it.
I'm having a surprising amount of trouble finding this information online: does the "chip" include some functionality (maybe called iCVV or dCVV) that allows it to individually "sign" transactions using internal secret keys, or does it not? This was my understanding of why the new system was supposed to be safer. If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the sig…
The answer is yes, most chip cards can do public key cryptography to sign a transaction without compromising the secret key burned in. Also, more frequently than I would wish banks or payment processors ask payment terminal operators for a "simpler", meaning less secure, transaction protocol. Most often it's for compatibility with some legacy system from the 80's somewhere in their payment validation backend. From my…
A good number of the supermarkets and other retailers around me are still just swiping cards. Gas pumps of course as well.
I'm guessing the added cost of the fraud liability for swiped cards is turning out to be lower than the cost to convert to chip readers.
Not all terminals in the States support chip functionality, so for the time being chip & pin cards here still have normal mag strips and can be run as older, regular cards - the mag strips can still be read/stolen & used.
And it's unlikely that this will change anytime soon due to the lack on incentives on all sides. Funny as it may be my debit card for some reason has a $500 (unmodifiable) limit on chip&pin purchases, but it has no such limit for swipe purchases. When I asked them how is that more secure, I got a verbal shoulder shrug. Banks are in the business of underwriting. I believe at least on the corporate level they probably…
Can you explain what you mean by "unmodifiable"? I have a limit, but on the banks app and website I can lower it (and I keep it very low) in the hope that any issues I have would be limited by this. Is this not actually worth doing?
In France it always has been 100% chip & pin, but if you have a hardware like this device between your card and the card reader, it can apparently intercept any signal, including the pin code. I don't know how exactly the protocol and how they get the pin, but they get it according to this article. (would it be possible to implement a SSL-like protocol to avoid this type of MitM attack?) An old school version of this…
In a proper EMV solution, hardware like this can not intercept the PIN code even if it can interpret any signal, as the unencrypted PIN is not sent anywhere beyond the keypad - even if you do MITM on the wires between the keypad and POS terminal, you would get only an encrypted version that then gets sent to the bank for online verification or to the chip for offline verification. You can get the PIN code by cameras…
Defcon 24 vid about skimming EMV cards at ATMs and withdrawing cash from the skimmed account at a different remote ATM (cashout): https://m.youtube.com/watch?v=FgIk_oIK2SM
The answer is yes, most chip cards can do public key cryptography to sign a transaction without compromising the secret key burned in. Also, more frequently than I would wish banks or payment processors ask payment terminal operators for a "simpler", meaning less secure, transaction protocol. Most often it's for compatibility with some legacy system from the 80's somewhere in their payment validation backend. From my…
A good number of the supermarkets and other retailers around me are still just swiping cards. Gas pumps of course as well. I'm guessing the added cost of the fraud liability for swiped cards is turning out to be lower than the cost to convert to chip readers.
It's not the cost of conversion, it's that the fraud just vanishes in the insane rents American credit card processors extract. In the EU, these fees are limited to 0.3% for CC and 0.2% for debit cards, so there is less margin to just keep paying the fraudsters instead of updating systems.
I'm having a surprising amount of trouble finding this information online: does the "chip" include some functionality (maybe called iCVV or dCVV) that allows it to individually "sign" transactions using internal secret keys, or does it not? This was my understanding of why the new system was supposed to be safer. If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the sig…
Not all terminals in the States support chip functionality, so for the time being chip & pin cards here still have normal mag strips and can be run as older, regular cards - the mag strips can still be read/stolen & used.
IMO it's super dumb that we're going through the whole business of replacing card readers to get chip support but NOT getting pin requirements. I've had a few CCs stolen from my mailbox (apartment with a large shared mailbox with simple padlocks). The new chip-only doesn't protect against this at all. MasterCard SecureCode was also a step in the right direction IMO, but the adoption rate seems very low. Basically, I want to require a second factor for every purchase. There's no way to do that right now with US cards that I know of. Debit cards can do it in person, but the fraud liability is different from CCs, and I don't get the fat 3% back or help my credit score. The best option online seems to be PayPal, which again loses the CC benefits. Thus, I just accept the inconvenience of getting my CC stolen a few times per year, since I'm not liable for the fraud, but it makes me cringe how this is currently the best solution available because of how messed up the incentives in the payment industry are here.
Can we not make certain parts of the ATM from a transparent material, like clear plastic? I'm thinking it would be more obvious when the keypad or card slot have been tampered with.