Live data from Hacker News

'Shimmers' are the newest tool for stealing credit card info

cbc.ca

81–88 of 88 posts

Re: 'Shimmers' are the newest tool for stealing credit card info

#81
post #62

Earlier quoted context omitted.

Notable the article is from Canada. Here in Canada virtually all retailers have been using chip+pin for a good number of years now. The same in the UK, where they have been using it for over 10 years. Retailers have to use chip+pin to avoid fraud liability. In the USA, however, a lot of retailers were still using signatures up until a year or two. It seems to be only in the last year that retailers are starting to mo…

They are not moving to chip and pin, but chip and signature: very different. Now, the internet being a bigger share of retail every year, chip and pin is not an improvement: what we need is 2FA across the board. You have my CC number? Great. Without my 2FA secret, you won't be able to charge me anyway. This 2FA beats a pin, and would make payment fraud so much smaller, it'd become a minor thing, but good luck finding…

Some European banks implement that second factor, although most commonly using an SMS or phone call.

Mine only does it when the transaction is large, or unusual. I get a call asking me to confirm the transaction. Maybe they ask some other information, I can't remember.

Re: 'Shimmers' are the newest tool for stealing credit card info

#82

I haven't actually physically inserted my card into a machine for at least 2 years now. It's contactless everywhere. If the transaction is more than ~$50 it just asks for my pin and that's it. Maybe we should just introduce this everywhere and then see how criminals can possibly break it?

Contactless is even less secure than chip and pin. You can literally read card details out of someone's wallet without them having any way to tell. Even if someone uses a wallet that guards against this sort of attack, they're still vulnerable at the point of use. http://youtu.be/x3S_6EJCjn0 http://youtu.be/vmajlKJlT3U

Usually, you would limit the contactless transactions and ask for a PIN for higher amounts. E.g. you could ride the subway trying to scan people's cards, but if you have the skills to do that, you'd probably be better off doing something else.

Re: 'Shimmers' are the newest tool for stealing credit card info

#83
post #62

Earlier quoted context omitted.

They are not moving to chip and pin, but chip and signature: very different. Now, the internet being a bigger share of retail every year, chip and pin is not an improvement: what we need is 2FA across the board. You have my CC number? Great. Without my 2FA secret, you won't be able to charge me anyway. This 2FA beats a pin, and would make payment fraud so much smaller, it'd become a minor thing, but good luck finding…

Some European banks implement that second factor, although most commonly using an SMS or phone call. Mine only does it when the transaction is large, or unusual. I get a call asking me to confirm the transaction. Maybe they ask some other information, I can't remember.

That sounds awful, how would I use my card when I'm traveling abroad if it's trying to send SMS's to my home SIM card?

Re: 'Shimmers' are the newest tool for stealing credit card info

#84

So at some level there is an issue with the "inside" aspect of card readers. If you had four guide posts and you just pressed your card against the pogo pins would it make it harder to interpose?

Agreed, this type of device could be easy to detect with some simple upgrades to the card readers. However, the cost of upgrading card reader hardware at all vulnerable banks and retailers is unlikely to be small.

Many businesses in the USA have recently upgraded or will be soon... It would be a shame of they installed new terminals that were flawed from the start.

Re: 'Shimmers' are the newest tool for stealing credit card info

#85
post #83

Earlier quoted context omitted.

Some European banks implement that second factor, although most commonly using an SMS or phone call. Mine only does it when the transaction is large, or unusual. I get a call asking me to confirm the transaction. Maybe they ask some other information, I can't remember.

That sounds awful, how would I use my card when I'm traveling abroad if it's trying to send SMS's to my home SIM card?

It's been easy for me - I call my bank ahead of time and tell them where I'll be going,the duration of my stay and my number while I'm there. They usually ask for a backup number just in case I'm not reachable.

Re: 'Shimmers' are the newest tool for stealing credit card info

#86
post #83

Earlier quoted context omitted.

That sounds awful, how would I use my card when I'm traveling abroad if it's trying to send SMS's to my home SIM card?

It's been easy for me - I call my bank ahead of time and tell them where I'll be going,the duration of my stay and my number while I'm there. They usually ask for a backup number just in case I'm not reachable.

How do you know your number while you're there before you get there and buy a local SIM?

Re: 'Shimmers' are the newest tool for stealing credit card info

#87
post #83

Earlier quoted context omitted.

Some European banks implement that second factor, although most commonly using an SMS or phone call. Mine only does it when the transaction is large, or unusual. I get a call asking me to confirm the transaction. Maybe they ask some other information, I can't remember.

That sounds awful, how would I use my card when I'm traveling abroad if it's trying to send SMS's to my home SIM card?

I've only had it happen for over-the-phone purchases, and when using a debit card to transfer about £5000 via TransferWise.

I haven't been to the USA for a while, and most other countries have a working (not new) Chip+PIN system, but I assume magstripe transactions would be considered higher risk too.

Re: 'Shimmers' are the newest tool for stealing credit card info

#88
post #32

Earlier quoted context omitted.

The answer is yes, most chip cards can do public key cryptography to sign a transaction without compromising the secret key burned in. Also, more frequently than I would wish banks or payment processors ask payment terminal operators for a "simpler", meaning less secure, transaction protocol. Most often it's for compatibility with some legacy system from the 80's somewhere in their payment validation backend. From my…

A good number of the supermarkets and other retailers around me are still just swiping cards. Gas pumps of course as well. I'm guessing the added cost of the fraud liability for swiped cards is turning out to be lower than the cost to convert to chip readers.

Actually the major card companies set deadlines and have all now shifted the liability for swiped transactions onto the retailers. So it's up to them to get their systems updated if they want protection.

The only exception currently is for gas pumps, for which the liability shift has been extended until 2020.

Post reply on HN