Live data from Hacker News

Is your chip card secure? Much depends on where you bank

krebsonsecurity.com

91–100 of 180 posts

Re: Is your chip card secure? Much depends on where you bank

#91

I will never understand why magstripe is still used in the US. Even after EMV became “mandatory” there are still magstripe transactions happening and when you are presented sith a chip reader it’s slow and awkward. Why is it such an inferior experience compared to Europe?

What is crazier still, is I wasn't even sent a chip & pin from my bank until just last year. At least they did everything all at once, chip and contactless. But I'm still waiting for Capital One to send me a contactless card (its my preferred card to use internationally where contactless seems to be the standard).

If you have a (modern, smart) phone you can teach the phone this Capital One card and it'll "be" that card contactlessly when you travel, one less thing to carry.

I deliberately own (special ordered from my bank) a card that has no contactless, and it's also the card my phone "is" so all contactless transactions with that card are through the phone, the bank never issued a contactless card so it's literally impossible that the card itself was used for a contactless transaction.

Using the phone this way allows me to walk around the supermarket, scanning product codes with the phone, then walk to the checkout, scan the "I'm done" code and hold the phone near the contactless checkout as payment. No human interaction, very little touching stuff, only need the phone which I'd carry anyway, no cards or cash.

Re: Is your chip card secure? Much depends on where you bank

#92

Earlier quoted context omitted.

If a transaction doesn't get made because it was over $40, that represents unacceptable missed profits, if some unfortunate consumer gets their identity stolen[1], well, they should have been more careful. It would make sense to eliminate magstripes, to limit them to $40, to let people decide their own limit, or any number of other things - the trouble is that the incentives of the businesses, banks, and credit card…

> If a transaction doesn't get made because it was over $40, that represents unacceptable missed profit Contactless already has transaction limits so clearly payment method-specific transaction limits do not create "unacceptable missed profit".

> Contactless already has transaction limits so clearly payment method-specific transaction limits do not create "unacceptable missed profit".

This isn't true with US payment cards, in my experience. I've charged over $1000 on a credit card multiple times while using contactless methods (both RFID and Apple Pay, specifically). I was also able to do the same with my (American) cards while in Europe.

Re: Is your chip card secure? Much depends on where you bank

#93

Earlier quoted context omitted.

I have inquired about this also and found no solution. If I use my US based credit cards abroad where chip and pin is the norm, I end up getting asked to sign a printed receipt. I imagine the card networks just don’t want to spend money to change the infrastructure to support chip and pin because the merchant pays for most the losses in the US?

The liability shift in the US that affected most retailers occurred in October 2015 -- basically, merchants are and have been liable for fraud that occurs on swiped transactions. I'd be curious to find out how the example presented by the parent article could change this -- a valid-looking card that only has swipe would definitely be taken by a merchant for fraud, and if the card doesn't claim to be EMV-capable, it s…

Previous commenter and I were talking about chip and pin, not just chip (aka EMV).

With EMV, someone can still use your card after they steal it. With chip and pin, that is far more difficult. I don’t know if merchant off the hook even with just chip, I presume the card networks kept some weasel language in order to allow them to blame the merchant.

Re: Is your chip card secure? Much depends on where you bank

#94
post #8

So this effectively lets you use chip data to recreate a magnetic stripe, which passes validation when the banks don't check against the right CVV. Yeah, not great. OTOH I worked on an early EMV implementation almost 20 years ago now, and it was obvious even then that mag stripe was a huge security problem. I'm amazed we're still talking about mag stripes and issuing cards with them in 2020. They should have been ret…

Mag stripes via fingerprinting of the actual stripe, can make make them more secure than EMV or contactless.

Both the standard card data and the underlying magnetic fingerprint of the card is read, all in a single swipe. [1]

[1] https://www.magtek.com/product/magnesafe-intellihead

Re: Is your chip card secure? Much depends on where you bank

#95
post #37

Earlier quoted context omitted.

There's no reason why contactless EMV should not be required even at a gas station (not needing a limit).

Gas pump readers are very expensive. The solution for the wise customer is to go inside and use the POS terminal at the counter if possible. Old school gas station attack: many gas stations queue and forward transactions for reconciliation in batches, waiting to do so when they don't have connectivity. People have taken advantage of this fact by climbing up on the roof of stations with satellite connections for their…

> The solution for the wise customer is to go inside and use the POS terminal at the counter if possible.

That's irrelevant to this attack. Bad guys aren't obliged to use that terminal, and they're the ones relying on access to a mag-stripe reader.

However for that "old school" attack EMV could help if it was deployed. Because EMV cards have state, they can have arbitrary rules about how often they're willing to perform offline transactions and how much value for. So e.g. a card can decide it won't do more than five offline transactions or more than $100 of transactions without going online.

Re: Is your chip card secure? Much depends on where you bank

#96

Earlier quoted context omitted.

What is crazier still, is I wasn't even sent a chip & pin from my bank until just last year. At least they did everything all at once, chip and contactless. But I'm still waiting for Capital One to send me a contactless card (its my preferred card to use internationally where contactless seems to be the standard).

If you have a (modern, smart) phone you can teach the phone this Capital One card and it'll "be" that card contactlessly when you travel, one less thing to carry. I deliberately own (special ordered from my bank) a card that has no contactless, and it's also the card my phone "is" so all contactless transactions with that card are through the phone, the bank never issued a contactless card so it's literally impossibl…

I actually had trouble the a year ago when traveling in the UK (I miss travelling), I was using my capital one through apple pay, but it would get declined constantly and shut off because the UK doesn't pass the CVV into the transaction. I never found a clear pattern for when fraud detection would occur, but one app that caused it constantly was Deliveroo.

Re: Is your chip card secure? Much depends on where you bank

#97
post #2

What if you sidestepped all the chip cleverness and just put cameras to capture the name, CC number, expiration and 3 digits? You'd still need a billing address I guess, but you might be able to get that by looking up the name and disambiguating using the location of the terminal.

Another method would be a standardised QR code so that you can make a transaction from your app by scanning the qr code. I don’t know about other countries, but this is basically the premise of QRIS Technology [0] used in Indonesia, basically to put an end on competing in QR-based payment method. [0]: https://www.bi.go.id/QRIS/Contents/Default.aspx

Wouldn't work in a lot of places where there's no LTE reception, though that will probably change with things like 5G and Starlink.

I also wouldn't want my ability to pay to be tied to my phone. Not only do I want to be able to pay for things even when my phone is dead, but it just seems like it would add yet another vector of attack to steal my money.

Re: Is your chip card secure? Much depends on where you bank

#98
post #87

OK, so if I grasp this, the problem is that an EMV skimmer gets the card number and an iCVV. The bad guys make a stripe card with that number and the iCVV. That should not work because banks are supposed to look for the iCVV only on dipped transactions, and look for the CVV on swiped transactions (and the CSC for online/telephone transactions). Some banks apparently left out the logic of matching the type of code to…

I would hope that a card would be flagged as suspicious before a hundred tries. They’d still could get some transactions through, but that would cut the success rate by a couple of orders of magnitude compared to just hoping that the bank won’t check.

What really needs to be done is letting go of the magnetic stripe.

Re: Is your chip card secure? Much depends on where you bank

#99
post #27

Earlier quoted context omitted.

But also banks take on all the liability for misuse. Customers aren’t liable for fraudulent charges, that’s why America has lagged behind Europe on rolling out chip cards, customers don’t demand it because they don’t pay the price for card fraud.

European customers aren't liable for fraudulent charges either, I don't really understand your logic here. Everyone pays the price of fraud and it's probably one major reason that explains high interchange fees in the US.

No, US interchange fees pay for "reward" cards. You charge everybody 5% extra, you give Karen 5% cashback, she thinks you're "rewarding" her and everybody else get screwed, the payment network keeps the difference.

The EU caps the interchange fee, does that mean the networks exit the business because they can't make money? No. Does it mean they've eliminated fraud? No. But it does mean they can't pay Karen 5% "reward" so they don't. There aren't any cards like that in Europe. For everybody else it makes the system cheaper.

Re: Is your chip card secure? Much depends on where you bank

#100
post #4

Hi. I have worked for one of the acquirers (card acceptors) for couple of years, designing and implementing credit card terminals and security infrastructure. I was also security officer. Basically, credit cards can be very secure. But it also costs. Banks do simple cost/benefit decisions and may in many cases significantly lag behind in technology for various reasons. They get away with this because consumers have a…

My experience has been that all the banks that gave me cards were diligent in verifying suspicious transactions, often erring on the side of caution and asking for confirmation. Also, they don’t tend to argue much before refunding an illegal transaction.

So, from my point of view, it could certainly be improved (along the lines of what Apple Pay is doing with tokenisation: confidentiality is an issue), but there is no real reason to complain.

As long as fraudulent transactions are rare enough that the banks don’t drag their feet, it’s fine.

Post reply on HN