Live data from Hacker News

'Shimmers' are the newest tool for stealing credit card info

cbc.ca

51–60 of 88 posts

Re: 'Shimmers' are the newest tool for stealing credit card info

#51

Earlier quoted context omitted.

From the issuer side, the solution to remove this risk is simple (and I believe I was told it in an EMV implementation seminar 10 years ago): If the incoming transaction lists that the terminal is chip&pin capable, so you'd simply automatically reject a magstripe transaction with a code that should result in POS showing "please insert card in the chip reader"; If the incoming transaction lists that the terminal is no…

If you try to swipe a chip card then yes, the terminal will reject the swipe and tell you to insert the chip. If your chip fails three successive tries, the terminal will accept a mag swipe instead. I don't know if this is true everywhere but I have seen it in multiple retailers across the US. Point is, if attackers are cloning mag cards from chip data, those cards can still be used in chip terminals.

That can be true, but then the transaction is considered "fallback" and most issuer Banks that have any brains will be examining these very closely with their real time fraud systems. Some deny fallback outright, but I am not sure if this is within scheme rules, it may depend on the region.

Re: 'Shimmers' are the newest tool for stealing credit card info

#52

This happened to me recently when my card data was stolen in a very respectable place where I've been a long time patron. It was totally unpleasant surprise. Right the next day the fraudulent transactions on my card started to popup all over the world - Beijing, North Carloina, etc. My bank promptly blocked the card - but I had to deal with the pain of calling in, going over my transactions list, verifying my identit…

Future tip: If you really need the card (or even if you don't), you can usually get the replacement card overnighted to you if you're insistent on the phone, at least in my experience.

Re: 'Shimmers' are the newest tool for stealing credit card info

#53
post #49

Earlier quoted context omitted.

> the chip used to contain all the information present on the magstripe Not all of it - the chip has a dynamic CVV that differs from the one on the magstripe. This only works if the bank isn't checking CVVs.

> This only works if the bank isn't checking CVVs. Source please? Because if you're right, my bank lied to me when they said they couldn't see whether I paid by chip or by magstripe.

Your Bank is lying, or more correctly has either poorly trained front end staff or a rubbish interface to their EFT system.

Source: 25 years of EFT development on Bank transaction systems.

Re: 'Shimmers' are the newest tool for stealing credit card info

#54

Earlier quoted context omitted.

It's not the cost of conversion, it's that the fraud just vanishes in the insane rents American credit card processors extract. In the EU, these fees are limited to 0.3% for CC and 0.2% for debit cards, so there is less margin to just keep paying the fraudsters instead of updating systems.

They have the new readers but they don't use them

Notable the article is from Canada. Here in Canada virtually all retailers have been using chip+pin for a good number of years now. The same in the UK, where they have been using it for over 10 years. Retailers have to use chip+pin to avoid fraud liability.

In the USA, however, a lot of retailers were still using signatures up until a year or two. It seems to be only in the last year that retailers are starting to move to chip+pin. I think it is simply the large number of credit card terminals, and the cost of upgrading them all.

Re: 'Shimmers' are the newest tool for stealing credit card info

#55

Earlier quoted context omitted.

If you try to swipe a chip card then yes, the terminal will reject the swipe and tell you to insert the chip. If your chip fails three successive tries, the terminal will accept a mag swipe instead. I don't know if this is true everywhere but I have seen it in multiple retailers across the US. Point is, if attackers are cloning mag cards from chip data, those cards can still be used in chip terminals.

That can be true, but then the transaction is considered "fallback" and most issuer Banks that have any brains will be examining these very closely with their real time fraud systems. Some deny fallback outright, but I am not sure if this is within scheme rules, it may depend on the region.

From what I can determine, the retailer is liable for fraud when using magnetic strip, whether or not the chip has failed:

http://www.emvcanada.com/forum/what-happens-when.html

Re: 'Shimmers' are the newest tool for stealing credit card info

#56
post #5

Earlier quoted context omitted.

Not all terminals in the States support chip functionality, so for the time being chip & pin cards here still have normal mag strips and can be run as older, regular cards - the mag strips can still be read/stolen & used.

IMO it's super dumb that we're going through the whole business of replacing card readers to get chip support but NOT getting pin requirements. I've had a few CCs stolen from my mailbox (apartment with a large shared mailbox with simple padlocks). The new chip-only doesn't protect against this at all. MasterCard SecureCode was also a step in the right direction IMO, but the adoption rate seems very low. Basically, I…

Given that the transition from magstripe to chip-and-sign hasn't been so smooth (confusion among customers and cashiers for a few months), I can see why we haven't moved towards it yet. Merchants would be more nervous about additional lost sales because of customers not knowing what to do or not being used to having to memorize PINs for their credit cards.

PINs really only just deter someone from physically stealing your card and then using it, so until card theft becomes a problem, I don't think we're going to be moving to chip-and-PIN any time soon.

(On the bright side, Android/Apple Pay are generally good enough to function as chip-and-pin: it's as secure as a chip card, and don't allow thieves to use your cards unless they're either sophisticated enough to get past the fingerprint sensor, or they know your passcode. It's just a bit awkward to set up.)

Re: 'Shimmers' are the newest tool for stealing credit card info

#58
post #4

I'm having a surprising amount of trouble finding this information online: does the "chip" include some functionality (maybe called iCVV or dCVV) that allows it to individually "sign" transactions using internal secret keys, or does it not? This was my understanding of why the new system was supposed to be safer. If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the sig…

They probably just steal data from the magnetic stripe + detect key-presses somehow for a PIN.

Re: 'Shimmers' are the newest tool for stealing credit card info

#59
post #45
post #40

Can we not make certain parts of the ATM from a transparent material, like clear plastic? I'm thinking it would be more obvious when the keypad or card slot have been tampered with.

Would the majority of people actually notice though?

Probably not normal people using cards, but it wouldn't be hard to train cashiers/managers what to look for. However, this would probably just lead to shimmers made out of clear plastic
Post reply on HN