I haven't actually physically inserted my card into a machine for at least 2 years now. It's contactless everywhere. If the transaction is more than ~$50 it just asks for my pin and that's it. Maybe we should just introduce this everywhere and then see how criminals can possibly break it?
'Shimmers' are the newest tool for stealing credit card info
71–80 of 88 posts
Re: 'Shimmers' are the newest tool for stealing credit card info
#72Earlier quoted context omitted.
IMO it's super dumb that we're going through the whole business of replacing card readers to get chip support but NOT getting pin requirements. I've had a few CCs stolen from my mailbox (apartment with a large shared mailbox with simple padlocks). The new chip-only doesn't protect against this at all. MasterCard SecureCode was also a step in the right direction IMO, but the adoption rate seems very low. Basically, I…
How were thieves able to activate cards stolen from your mail box?
Re: 'Shimmers' are the newest tool for stealing credit card info
#73> "Businesses really need to be checking for these kinds of devices and consumers need to be aware of them." Disagree. Consumers and businesses (ultimately) pay the interchange fees, and this class of problem is the domain of payment infrastructure providers. I'm not interested in keeping vigilant against the latest exploit, and unless the responsibility for dealing with the problem lies with credit card networks and…
Re: 'Shimmers' are the newest tool for stealing credit card info
#74Earlier quoted context omitted.
Not all terminals in the States support chip functionality, so for the time being chip & pin cards here still have normal mag strips and can be run as older, regular cards - the mag strips can still be read/stolen & used.
IMO it's super dumb that we're going through the whole business of replacing card readers to get chip support but NOT getting pin requirements. I've had a few CCs stolen from my mailbox (apartment with a large shared mailbox with simple padlocks). The new chip-only doesn't protect against this at all. MasterCard SecureCode was also a step in the right direction IMO, but the adoption rate seems very low. Basically, I…
(though mostly because they don't want credit card payments to be easier than debit or cash).
Re: 'Shimmers' are the newest tool for stealing credit card info
#75Earlier quoted context omitted.
> the chip used to contain all the information present on the magstripe Not all of it - the chip has a dynamic CVV that differs from the one on the magstripe. This only works if the bank isn't checking CVVs.
> This only works if the bank isn't checking CVVs. Source please? Because if you're right, my bank lied to me when they said they couldn't see whether I paid by chip or by magstripe.
Re: 'Shimmers' are the newest tool for stealing credit card info
#76Re: 'Shimmers' are the newest tool for stealing credit card info
#77Krebs has a post on this as well: https://krebsonsecurity.com/2017/01/atm-shimmers-target-chip... “The only way for this attack to be successful is if a [bank card] issuer neglects to check the CVV when authorizing a transaction,”
I have not had the largest confidence in banks abilities to understand security. I've personally dealt with: 1) 'Two factor auth is on, you have to answer two security questions to access your account!' 2) 'Your password is limited to exactly 8 characters ... for security' 3) 'Oh, we now support SMS two factor auth' -- 4 months in, I've received 1 SMS challenge 4) 'You don't want a chip card, they are more hassle' 5)…
Re: 'Shimmers' are the newest tool for stealing credit card info
#78So at some level there is an issue with the "inside" aspect of card readers. If you had four guide posts and you just pressed your card against the pogo pins would it make it harder to interpose?
Re: 'Shimmers' are the newest tool for stealing credit card info
#79I haven't actually physically inserted my card into a machine for at least 2 years now. It's contactless everywhere. If the transaction is more than ~$50 it just asks for my pin and that's it. Maybe we should just introduce this everywhere and then see how criminals can possibly break it?
Re: 'Shimmers' are the newest tool for stealing credit card info
#80I haven't actually physically inserted my card into a machine for at least 2 years now. It's contactless everywhere. If the transaction is more than ~$50 it just asks for my pin and that's it. Maybe we should just introduce this everywhere and then see how criminals can possibly break it?
Contactless is even less secure than chip and pin. You can literally read card details out of someone's wallet without them having any way to tell. Even if someone uses a wallet that guards against this sort of attack, they're still vulnerable at the point of use. http://youtu.be/x3S_6EJCjn0 http://youtu.be/vmajlKJlT3U
I'm talking about Visa PayWave/Mastercard PayPass - both work through NFC and won't surrender any data to a normal reader, you need an authorized terminal that can give an authorization key valid for a given time. There were some attacks against it, but you can't just swipe a card through a wallet, it's extremely time sensitive and requires access to a valid terminal.