Earlier quoted context omitted.
From the issuer side, the solution to remove this risk is simple (and I believe I was told it in an EMV implementation seminar 10 years ago): If the incoming transaction lists that the terminal is chip&pin capable, so you'd simply automatically reject a magstripe transaction with a code that should result in POS showing "please insert card in the chip reader"; If the incoming transaction lists that the terminal is no…
If you try to swipe a chip card then yes, the terminal will reject the swipe and tell you to insert the chip. If your chip fails three successive tries, the terminal will accept a mag swipe instead. I don't know if this is true everywhere but I have seen it in multiple retailers across the US. Point is, if attackers are cloning mag cards from chip data, those cards can still be used in chip terminals.
'Shimmers' are the newest tool for stealing credit card info
51–60 of 88 posts
Re: 'Shimmers' are the newest tool for stealing credit card info
#52This happened to me recently when my card data was stolen in a very respectable place where I've been a long time patron. It was totally unpleasant surprise. Right the next day the fraudulent transactions on my card started to popup all over the world - Beijing, North Carloina, etc. My bank promptly blocked the card - but I had to deal with the pain of calling in, going over my transactions list, verifying my identit…
Re: 'Shimmers' are the newest tool for stealing credit card info
#53Earlier quoted context omitted.
> the chip used to contain all the information present on the magstripe Not all of it - the chip has a dynamic CVV that differs from the one on the magstripe. This only works if the bank isn't checking CVVs.
> This only works if the bank isn't checking CVVs. Source please? Because if you're right, my bank lied to me when they said they couldn't see whether I paid by chip or by magstripe.
Source: 25 years of EFT development on Bank transaction systems.
Re: 'Shimmers' are the newest tool for stealing credit card info
#54Earlier quoted context omitted.
It's not the cost of conversion, it's that the fraud just vanishes in the insane rents American credit card processors extract. In the EU, these fees are limited to 0.3% for CC and 0.2% for debit cards, so there is less margin to just keep paying the fraudsters instead of updating systems.
They have the new readers but they don't use them
In the USA, however, a lot of retailers were still using signatures up until a year or two. It seems to be only in the last year that retailers are starting to move to chip+pin. I think it is simply the large number of credit card terminals, and the cost of upgrading them all.
Re: 'Shimmers' are the newest tool for stealing credit card info
#55Earlier quoted context omitted.
If you try to swipe a chip card then yes, the terminal will reject the swipe and tell you to insert the chip. If your chip fails three successive tries, the terminal will accept a mag swipe instead. I don't know if this is true everywhere but I have seen it in multiple retailers across the US. Point is, if attackers are cloning mag cards from chip data, those cards can still be used in chip terminals.
That can be true, but then the transaction is considered "fallback" and most issuer Banks that have any brains will be examining these very closely with their real time fraud systems. Some deny fallback outright, but I am not sure if this is within scheme rules, it may depend on the region.
Re: 'Shimmers' are the newest tool for stealing credit card info
#56Earlier quoted context omitted.
Not all terminals in the States support chip functionality, so for the time being chip & pin cards here still have normal mag strips and can be run as older, regular cards - the mag strips can still be read/stolen & used.
IMO it's super dumb that we're going through the whole business of replacing card readers to get chip support but NOT getting pin requirements. I've had a few CCs stolen from my mailbox (apartment with a large shared mailbox with simple padlocks). The new chip-only doesn't protect against this at all. MasterCard SecureCode was also a step in the right direction IMO, but the adoption rate seems very low. Basically, I…
PINs really only just deter someone from physically stealing your card and then using it, so until card theft becomes a problem, I don't think we're going to be moving to chip-and-PIN any time soon.
(On the bright side, Android/Apple Pay are generally good enough to function as chip-and-pin: it's as secure as a chip card, and don't allow thieves to use your cards unless they're either sophisticated enough to get past the fingerprint sensor, or they know your passcode. It's just a bit awkward to set up.)
Re: 'Shimmers' are the newest tool for stealing credit card info
#57Re: 'Shimmers' are the newest tool for stealing credit card info
#58I'm having a surprising amount of trouble finding this information online: does the "chip" include some functionality (maybe called iCVV or dCVV) that allows it to individually "sign" transactions using internal secret keys, or does it not? This was my understanding of why the new system was supposed to be safer. If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the sig…
Re: 'Shimmers' are the newest tool for stealing credit card info
#59Can we not make certain parts of the ATM from a transparent material, like clear plastic? I'm thinking it would be more obvious when the keypad or card slot have been tampered with.
Would the majority of people actually notice though?
Re: 'Shimmers' are the newest tool for stealing credit card info
#60Why on earth is the PIN located ON THE CARD?