Why on earth is the PIN located ON THE CARD?
It's not.
'Shimmers' are the newest tool for stealing credit card info
61–70 of 88 posts
Re: 'Shimmers' are the newest tool for stealing credit card info
#62Earlier quoted context omitted.
They have the new readers but they don't use them
Notable the article is from Canada. Here in Canada virtually all retailers have been using chip+pin for a good number of years now. The same in the UK, where they have been using it for over 10 years. Retailers have to use chip+pin to avoid fraud liability. In the USA, however, a lot of retailers were still using signatures up until a year or two. It seems to be only in the last year that retailers are starting to mo…
Now, the internet being a bigger share of retail every year, chip and pin is not an improvement: what we need is 2FA across the board. You have my CC number? Great. Without my 2FA secret, you won't be able to charge me anyway.
This 2FA beats a pin, and would make payment fraud so much smaller, it'd become a minor thing, but good luck finding a bank in the US offering such feature for all charges.
Re: 'Shimmers' are the newest tool for stealing credit card info
#63Earlier quoted context omitted.
It's not.
Then is the article inaccurate when it says, "Once installed, the microchips on the shimmer record information from chip cards, including the PIN."?
The card decides if the PIN is correct, but it might be possible to record all the PINs that were tried.
Re: 'Shimmers' are the newest tool for stealing credit card info
#64Krebs has a post on this as well: https://krebsonsecurity.com/2017/01/atm-shimmers-target-chip... “The only way for this attack to be successful is if a [bank card] issuer neglects to check the CVV when authorizing a transaction,”
I have not had the largest confidence in banks abilities to understand security. I've personally dealt with: 1) 'Two factor auth is on, you have to answer two security questions to access your account!' 2) 'Your password is limited to exactly 8 characters ... for security' 3) 'Oh, we now support SMS two factor auth' -- 4 months in, I've received 1 SMS challenge 4) 'You don't want a chip card, they are more hassle' 5)…
As a consumer, I am indemnified by my bank, per Regulation E, against fraud from swipes. I get no benefit from the slower chip + sig system.
Re: 'Shimmers' are the newest tool for stealing credit card info
#65Earlier quoted context omitted.
Notable the article is from Canada. Here in Canada virtually all retailers have been using chip+pin for a good number of years now. The same in the UK, where they have been using it for over 10 years. Retailers have to use chip+pin to avoid fraud liability. In the USA, however, a lot of retailers were still using signatures up until a year or two. It seems to be only in the last year that retailers are starting to mo…
They are not moving to chip and pin, but chip and signature: very different. Now, the internet being a bigger share of retail every year, chip and pin is not an improvement: what we need is 2FA across the board. You have my CC number? Great. Without my 2FA secret, you won't be able to charge me anyway. This 2FA beats a pin, and would make payment fraud so much smaller, it'd become a minor thing, but good luck finding…
No, that's not quite true. They are moving to chip+pin, but some card issuers are not currently issuing PINs. However the machines themselves fully support chip+pin (and I can confirm this, as most places in the USA now require me to enter a PIN for my card).
http://www.creditcards.com/credit-card-news/emv-faq-chip-car...
Re: 'Shimmers' are the newest tool for stealing credit card info
#66Earlier quoted context omitted.
Not all terminals in the States support chip functionality, so for the time being chip & pin cards here still have normal mag strips and can be run as older, regular cards - the mag strips can still be read/stolen & used.
IMO it's super dumb that we're going through the whole business of replacing card readers to get chip support but NOT getting pin requirements. I've had a few CCs stolen from my mailbox (apartment with a large shared mailbox with simple padlocks). The new chip-only doesn't protect against this at all. MasterCard SecureCode was also a step in the right direction IMO, but the adoption rate seems very low. Basically, I…
Re: 'Shimmers' are the newest tool for stealing credit card info
#67Earlier quoted context omitted.
They are not moving to chip and pin, but chip and signature: very different. Now, the internet being a bigger share of retail every year, chip and pin is not an improvement: what we need is 2FA across the board. You have my CC number? Great. Without my 2FA secret, you won't be able to charge me anyway. This 2FA beats a pin, and would make payment fraud so much smaller, it'd become a minor thing, but good luck finding…
>They are not moving to chip and pin, but chip and signature: very different. No, that's not quite true. They are moving to chip+pin, but some card issuers are not currently issuing PINs. However the machines themselves fully support chip+pin (and I can confirm this, as most places in the USA now require me to enter a PIN for my card). http://www.creditcards.com/credit-card-news/emv-faq-chip-car...
Re: 'Shimmers' are the newest tool for stealing credit card info
#68Earlier quoted context omitted.
They are not moving to chip and pin, but chip and signature: very different. Now, the internet being a bigger share of retail every year, chip and pin is not an improvement: what we need is 2FA across the board. You have my CC number? Great. Without my 2FA secret, you won't be able to charge me anyway. This 2FA beats a pin, and would make payment fraud so much smaller, it'd become a minor thing, but good luck finding…
>They are not moving to chip and pin, but chip and signature: very different. No, that's not quite true. They are moving to chip+pin, but some card issuers are not currently issuing PINs. However the machines themselves fully support chip+pin (and I can confirm this, as most places in the USA now require me to enter a PIN for my card). http://www.creditcards.com/credit-card-news/emv-faq-chip-car...
Re: 'Shimmers' are the newest tool for stealing credit card info
#69Earlier quoted context omitted.
From the issuer side, the solution to remove this risk is simple (and I believe I was told it in an EMV implementation seminar 10 years ago): If the incoming transaction lists that the terminal is chip&pin capable, so you'd simply automatically reject a magstripe transaction with a code that should result in POS showing "please insert card in the chip reader"; If the incoming transaction lists that the terminal is no…
If you try to swipe a chip card then yes, the terminal will reject the swipe and tell you to insert the chip. If your chip fails three successive tries, the terminal will accept a mag swipe instead. I don't know if this is true everywhere but I have seen it in multiple retailers across the US. Point is, if attackers are cloning mag cards from chip data, those cards can still be used in chip terminals.
Re: 'Shimmers' are the newest tool for stealing credit card info
#70I'm having a surprising amount of trouble finding this information online: does the "chip" include some functionality (maybe called iCVV or dCVV) that allows it to individually "sign" transactions using internal secret keys, or does it not? This was my understanding of why the new system was supposed to be safer. If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the sig…
They probably just steal data from the magnetic stripe + detect key-presses somehow for a PIN.