Live data from Hacker News

Is your chip card secure? Much depends on where you bank

krebsonsecurity.com

31–40 of 180 posts

Re: Is your chip card secure? Much depends on where you bank

#31
post #8

So this effectively lets you use chip data to recreate a magnetic stripe, which passes validation when the banks don't check against the right CVV. Yeah, not great. OTOH I worked on an early EMV implementation almost 20 years ago now, and it was obvious even then that mag stripe was a huge security problem. I'm amazed we're still talking about mag stripes and issuing cards with them in 2020. They should have been ret…

Maybe it would make sense to limit magstripe transactions to $40 or let people decide their own limit.

Won't work for gas stations which are the last holdouts.

Re: Is your chip card secure? Much depends on where you bank

#32
I will never understand why magstripe is still used in the US. Even after EMV became “mandatory” there are still magstripe transactions happening and when you are presented sith a chip reader it’s slow and awkward. Why is it such an inferior experience compared to Europe?

Re: Is your chip card secure? Much depends on where you bank

#33
post #27
post #4

Hi. I have worked for one of the acquirers (card acceptors) for couple of years, designing and implementing credit card terminals and security infrastructure. I was also security officer. Basically, credit cards can be very secure. But it also costs. Banks do simple cost/benefit decisions and may in many cases significantly lag behind in technology for various reasons. They get away with this because consumers have a…

But also banks take on all the liability for misuse. Customers aren’t liable for fraudulent charges, that’s why America has lagged behind Europe on rolling out chip cards, customers don’t demand it because they don’t pay the price for card fraud.

Right, and so the trade-off seems completely reasonable to me.

If the bank has calculated that extra fraud costs less than the price mitigating it with additional security measures, and it is the one bearing the cost either way, then power to them!

Re: Is your chip card secure? Much depends on where you bank

#34
post #2

What if you sidestepped all the chip cleverness and just put cameras to capture the name, CC number, expiration and 3 digits? You'd still need a billing address I guess, but you might be able to get that by looking up the name and disambiguating using the location of the terminal.

Another method would be a standardised QR code so that you can make a transaction from your app by scanning the qr code.

I don’t know about other countries, but this is basically the premise of QRIS Technology [0] used in Indonesia, basically to put an end on competing in QR-based payment method.

[0]: https://www.bi.go.id/QRIS/Contents/Default.aspx

Re: Is your chip card secure? Much depends on where you bank

#35

I will never understand why magstripe is still used in the US. Even after EMV became “mandatory” there are still magstripe transactions happening and when you are presented sith a chip reader it’s slow and awkward. Why is it such an inferior experience compared to Europe?

My understanding for part of it is that magstip readers were much more common in the US, and businesses (a) didn't want to pay to upgrade all their terminals and (b) don't want to turn away a purchase because a customer doesn't have a chip or the chip isn't working.

Re: Is your chip card secure? Much depends on where you bank

#36
post #27

Earlier quoted context omitted.

But also banks take on all the liability for misuse. Customers aren’t liable for fraudulent charges, that’s why America has lagged behind Europe on rolling out chip cards, customers don’t demand it because they don’t pay the price for card fraud.

Right, and so the trade-off seems completely reasonable to me. If the bank has calculated that extra fraud costs less than the price mitigating it with additional security measures, and it is the one bearing the cost either way, then power to them!

This completely ignores the amount of worry and frustration which an ordinary person has to go through to get back to the point that only the bank are out of pocket. It's not trivial by any means.

You could also make an argument that by continuing to allow this fraud to happen we're funding all kinds of nasty people. I'm not convinced the argument holds water since bad guys are often faster to move than the banks but it's worth noting.

Re: Is your chip card secure? Much depends on where you bank

#37

Earlier quoted context omitted.

Maybe it would make sense to limit magstripe transactions to $40 or let people decide their own limit.

Won't work for gas stations which are the last holdouts.

There's no reason why contactless EMV should not be required even at a gas station (not needing a limit).

Re: Is your chip card secure? Much depends on where you bank

#38
post #27

Earlier quoted context omitted.

But also banks take on all the liability for misuse. Customers aren’t liable for fraudulent charges, that’s why America has lagged behind Europe on rolling out chip cards, customers don’t demand it because they don’t pay the price for card fraud.

Right, and so the trade-off seems completely reasonable to me. If the bank has calculated that extra fraud costs less than the price mitigating it with additional security measures, and it is the one bearing the cost either way, then power to them!

I'm not sure I understand this. Fraud, and cleaning up after it, is not free of cost. If anything, fraud is more insidious because it costs the one thing I can't replace, which is time.

Even for me--someone who has multiple payment cards, primarily uses credit (instead of debit), a healthy savings account, and a flexible job--cleaning up from a stolen credit card number takes two or three hours at a minimum. For someone who does not have those things, particularly for people who primarily use debit cards[0], the impact is far worse.

If we swapped our cards to simply require a PIN that's validated by the chip on the card (so that in-person charges without the proper PIN cannot complete, even if the card is shimmed), that removes the bulk of in-person fraud attempts. But US banks are, largely, so fearful of customers switching away from them at even the slightest provocation, we don't get PINs. So I'm forced to ask what other "basic" measures (like 3D Secure for online transactions) we lack.

0 - I don't want to hear the rebuttal that "well, people should just use credit cards." There are a hundred different reasons why people don't use credit cards--don't qualify for one, have an objection to debt, past bad experience, and so on--and we cannot write off people who "only" use debit from security measures.

Re: Is your chip card secure? Much depends on where you bank

#39
post #8

So this effectively lets you use chip data to recreate a magnetic stripe, which passes validation when the banks don't check against the right CVV. Yeah, not great. OTOH I worked on an early EMV implementation almost 20 years ago now, and it was obvious even then that mag stripe was a huge security problem. I'm amazed we're still talking about mag stripes and issuing cards with them in 2020. They should have been ret…

Maybe it would make sense to limit magstripe transactions to $40 or let people decide their own limit.

If a transaction doesn't get made because it was over $40, that represents unacceptable missed profits, if some unfortunate consumer gets their identity stolen[1], well, they should have been more careful.

It would make sense to eliminate magstripes, to limit them to $40, to let people decide their own limit, or any number of other things - the trouble is that the incentives of the businesses, banks, and credit card companies are more to make every transaction a success and to blame the consumer when they're too successful.

[1]: Yes, I recognize this is bad framing, the fault isn't with the victim nor really with the perpetrator but the incompetent designer of the lock.

Re: Is your chip card secure? Much depends on where you bank

#40
post #35

I will never understand why magstripe is still used in the US. Even after EMV became “mandatory” there are still magstripe transactions happening and when you are presented sith a chip reader it’s slow and awkward. Why is it such an inferior experience compared to Europe?

My understanding for part of it is that magstip readers were much more common in the US, and businesses (a) didn't want to pay to upgrade all their terminals and (b) don't want to turn away a purchase because a customer doesn't have a chip or the chip isn't working.

That may have been the case, but pretty much everywhere I go stores have newer EMV capable terminals (e.g Ingenico etc). The only place I really use mag swipe now is a gas station pump (who have no excuse not to switch to contactless EMV).

You'd think with COVID-19, there'd be a rush to move to contactless payments.

Post reply on HN