Live data from Hacker News

Is your chip card secure? Much depends on where you bank

krebsonsecurity.com

131–140 of 180 posts

Re: Is your chip card secure? Much depends on where you bank

#131

Earlier quoted context omitted.

Another method would be a standardised QR code so that you can make a transaction from your app by scanning the qr code. I don’t know about other countries, but this is basically the premise of QRIS Technology [0] used in Indonesia, basically to put an end on competing in QR-based payment method. [0]: https://www.bi.go.id/QRIS/Contents/Default.aspx

Wouldn't work in a lot of places where there's no LTE reception, though that will probably change with things like 5G and Starlink. I also wouldn't want my ability to pay to be tied to my phone. Not only do I want to be able to pay for things even when my phone is dead, but it just seems like it would add yet another vector of attack to steal my money.

> > Another method would be a standardised QR code so that you can make a transaction from your app by scanning the qr code.

> Wouldn't work in a lot of places where there's no LTE reception,

I happened to read about this recently (https://www.emvco.com/emv-technologies/qrcodes/), since it's going to be the base of Brazil's new instant payment system to be released later this year (PIX - https://www.bcb.gov.br/estabilidadefinanceira/forumpagamento...).

From what I understood, it does have a way to do offline transactions. There are two kinds of QR codes: one which is scanned by the app and used for both online and offline transactions, and a second kind used when offline which is presented by the app and scanned by the POS. This second QR code contains data similar to what a chip card would return to the reader during an offline transaction, so the transaction flow after that point is similar.

Re: Is your chip card secure? Much depends on where you bank

#132

Earlier quoted context omitted.

Gas pump readers are very expensive. The solution for the wise customer is to go inside and use the POS terminal at the counter if possible. Old school gas station attack: many gas stations queue and forward transactions for reconciliation in batches, waiting to do so when they don't have connectivity. People have taken advantage of this fact by climbing up on the roof of stations with satellite connections for their…

> The solution for the wise customer is to go inside and use the POS terminal at the counter if possible. That's irrelevant to this attack. Bad guys aren't obliged to use that terminal, and they're the ones relying on access to a mag-stripe reader. However for that "old school" attack EMV could help if it was deployed. Because EMV cards have state, they can have arbitrary rules about how often they're willing to perf…

I should have been more clear: the first sentence was meant for defeating skimmers and the like. Nothing to do with helping the retailer, just the end consumer.

You're entirely correct with EMV. Additionally, more gas stations are moving away from the old satellite connections, and an m2m cellular card in a POS terminal is a lot harder to shut down (at least without the cashier noticing).

Re: Is your chip card secure? Much depends on where you bank

#133
post #106

On this topic, if anyone can point me toward a US-based issuer where I can open an account and get a card that supports credit pin (not pin for cash advance on a credit card), I'll happily venmo you a pizza or something. The issuers I have spoken to[1] all tell me it is impossible to get such a card in the US, which seems ridiculous. [1]: https://wallethub.com/credit-cards/chip-and-pin/ I discussed each of the cards…

First Tech Federal Credit Union offers Chip and Pin Mastercard. https://www.firsttechfed.com/ https://www.firsttechfed.com/help/support/frequently-asked-q... What is the difference between Chip and PIN versus Chip and Signature? Chip and PIN is the most secure type of credit card technology. Instead of a signature being used for identity verification, it requires you to enter a four-digit Personal Identification Numb…

I joined First Tech just to get that Chip and PIN card. It worked great everywhere I went in Europe.

Re: Is your chip card secure? Much depends on where you bank

#134
post #113

Earlier quoted context omitted.

>Second is, is there a way to gain the safety of the chip and pin with online purchases. In the UK we have had "Verified by Visa" and "Mastercard 3D Secure" for many/most online transactions for a long time (12 years?) It's effectively a form of 2FA, the transaction flow diverts to a bank portal where you authorise the transaction with a password, or a selection of digits from a passcode. This never goes near retaile…

How do those work over there? We have both in the US as well, but I've always refused to use them because signing up for either seems to transfer a significant chunk of the liability for fraudulent transactions away from the bank and on to the consumer.

They're kind of half-arsed. So far as it's possible to tell, nobody who knew anything about UX or digital security was anywhere close to these projects.

So, your bank opts in to the Verified by Visa scheme (they can't opt individual account holders out, or at least my otherwise very co-operative "good" bank said they can't when I asked years ago)

If an online retailer performs Authorisation the API they talk to will examine your card number and conclude it needs this extra check, so it tells them to forward your browser to an HTTPS site you've never heard of, in the arcot.com domain. I guess if you're a huge bank you've heard of Arcot, but consumers haven't. The site claims to be from your famous bank brand, but the domain name clearly isn't, anybody who has learned anything about phishing ought to run screaming.

The arcot.com HTTPS site looks at the transaction and if you've never done this before it (presumably always? but maybe if there's a fraud flag this doesn't happen?) registers you for the "Verified by Visa" service. You can pick "No, I'm busy right now, just let me buy stuff" and it will give you a few passes, but I believe eventually it's mandatory.

Signing up requires giving them some details about the card, and also effectively creating yet another secret password. (Because we all know secret passwords are great right?). There might be an option to pick a picture or text greeting so you'll "know it's them" although of course a sophisticated attacker could duplicate that part...

On subsequent visits you may be asked for that secret if you've created it. Or, it might give up asking and just say everything is fine before returning you to the original payment flow. My transactions are reassuringly boring so I am never asked for anything these days.

The whole thing looks like it was built by people who were impressed by IE6 and are planning to buy a 17" display soon. The cryptography would be impressive for the IE6 era and not so much today, it's TLS 1.2, it has some basic precautions, but it's scarcely Fort Knox, your GMail is better protected.

Re: Is your chip card secure? Much depends on where you bank

#135
post #130
post #78

Earlier quoted context omitted.

Until EVs are more mainstream I guess, but that won't probably be for another 5-10 years.

Haha. A bit unrelated, not sure how it works in the rest of the world, but inNorway EV charging stations doesn’t even have a card reader, you have to sign up with an app and register your card there. And each charging company has their own app. Absolutely bonkers. You can get a chip for your key chain and tie it to all your apps so you can read that at the charging station, but still.

I own a Tesla, and there are not card readers at superchargers.

Re: Is your chip card secure? Much depends on where you bank

#137
post #113

Earlier quoted context omitted.

First I would love to find a way to find which banks or processors are vulnerable. Second is, is there a way to gain the safety of the chip and pin with online purchases. Currently I obscure my CC info by using PayPal where available and when in the real world I live by Apple pay. If I could disable access to my card by stripe for real world where Apple pay is not usable I would.

>Second is, is there a way to gain the safety of the chip and pin with online purchases. In the UK we have had "Verified by Visa" and "Mastercard 3D Secure" for many/most online transactions for a long time (12 years?) It's effectively a form of 2FA, the transaction flow diverts to a bank portal where you authorise the transaction with a password, or a selection of digits from a passcode. This never goes near retaile…

Yeah, whenever I hit one of those, I immediately back out of the transaction. I'm like, "Wait, I'm supposed to be paying business X, why am I at a different web site? Something's fishy here. Fuck this."

Re: Is your chip card secure? Much depends on where you bank

#138

Earlier quoted context omitted.

> The solution for the wise customer is to go inside and use the POS terminal at the counter if possible. That's irrelevant to this attack. Bad guys aren't obliged to use that terminal, and they're the ones relying on access to a mag-stripe reader. However for that "old school" attack EMV could help if it was deployed. Because EMV cards have state, they can have arbitrary rules about how often they're willing to perf…

I should have been more clear: the first sentence was meant for defeating skimmers and the like. Nothing to do with helping the retailer, just the end consumer. You're entirely correct with EMV. Additionally, more gas stations are moving away from the old satellite connections, and an m2m cellular card in a POS terminal is a lot harder to shut down (at least without the cashier noticing).

The whole point of the scheme this HN post is about is that it doesn't need to skim the mag-stripe.

Here's how this goes (everything in this story actually happened in England years ago, but that's before a change this story says wasn't entirely effective in eradicating the fraud)

Sarah lives in England where they are getting EMV terminals everywhere. Her cousin Terry lives somewhere which doesn't yet have terminals everywhere. Let's say it's Belgium, although in fact it was not.

Sarah owns a dozen petrol stations (that's what they call gas stations in England) and there are shiny EMV terminals arriving. Terry sends over instructions and electronic kits. The terminals are hollow and the instructions explain how to open one without the "anti-tamper" mechanism noticing and add more electronics in the convenient space.

Sarah teaches all her staff how to use the new terminals. She of course doesn't mention they've been tampered with.

You go to a petrol station, fill up your car, and hand your card to the clerk. "We got new machines" says the clerk and hands the card back. You put your card in the machine, and enter your PIN. I guess this is more secure?

In Belgium, Terry receives the magnetic stripe details of your card, retrieved from the chip using a convenient "Hey what is your mag-stripe?" API and sent over by a mobile chip in that circuit Sarah fitted. Terry has a mag-stripe writer and turns a cheap plastic card into a good-enough clone of your bank card. He sells this card to street level criminals in Belgium for €100, Sarah will get £10 per card as her cut.

Those street-level Belgian crooks need mag-stripe terminals because their cards have no chip, but you not swiping made no difference.

Edited to add:

While we're here. This is a recurring security problem. Old insecure systems can ruin it for new secure systems.

Imagine you have a brand new, up-to-the-minute TLS 1.3 only website. You use a cert for www.example.com with a nice shiny Elliptic curve public key & the corresponding Elliptic curve private key is in an HSM at a protected site, no problems. What can go wrong? Unknown to you, some numb-nuts who was angry about the company choosing Slack set up an "experimental" IRC server doing SSLv3 on port 6667 of their laptop using a *.example.com wildcard RSA cert that's still valid until next month. Bad guys who get even fairly limited access to your network can attack that IRC server, which is running on a high port on some idiot's laptop computer in corporate, not the secure datacentre where the web server is, and use it to flawlessly impersonate www.example.com if they can get on-path. They know this trick can work as soon as they find the IRC server, no special insight is needed.

Re: Is your chip card secure? Much depends on where you bank

#139
post #40

Earlier quoted context omitted.

That may have been the case, but pretty much everywhere I go stores have newer EMV capable terminals (e.g Ingenico etc). The only place I really use mag swipe now is a gas station pump (who have no excuse not to switch to contactless EMV). You'd think with COVID-19, there'd be a rush to move to contactless payments.

Lots of gas stations do use the chip, but it's the same process of inserting the card.

In New England, I've never seen anything other than a magstripe insert-remove type reader in a gas pump (although I think some do contactless EMV).

FWIW, At least in MA, it's rare to see a gas pump older than 10 years -- I think due to both Federal and MA State UST laws that require fairly recent (e.g. 2019) minimum standards such as double walled, properly cathodized, leak detecting tanks along with subsidies for tank replacement that have resulted in pretty much every gas station around here being totally renovated in the past 5 years or so.

https://www.mass.gov/guides/massdep-underground-storage-tank...

Re: Is your chip card secure? Much depends on where you bank

#140
post #27
post #4

Hi. I have worked for one of the acquirers (card acceptors) for couple of years, designing and implementing credit card terminals and security infrastructure. I was also security officer. Basically, credit cards can be very secure. But it also costs. Banks do simple cost/benefit decisions and may in many cases significantly lag behind in technology for various reasons. They get away with this because consumers have a…

But also banks take on all the liability for misuse. Customers aren’t liable for fraudulent charges, that’s why America has lagged behind Europe on rolling out chip cards, customers don’t demand it because they don’t pay the price for card fraud.

The banks may take on the liability but I assume they offload the risk elsewhere with insurance or pricing it in.

We pay for fraud with increased transaction fees.

Post reply on HN