1. An NFC-enabled EMV card will happily reveal its entire account number and expiration date over NFC with no authentication whatsoever. I don’t know whether the CVV comes along, but I wouldn’t be surprised if it did.
2. (As mentioned in the article) issuers accept transactions from EMV (chip)-capable readers that nominally originate from EMV-capable cards without requiring the chip to be used. So what’s the point of the chip? (Note that this allows a card to be cloned without even touching the card - see #1.)
3. The information leaked in #1 is enough to buy things online (as long as the CVV2 can be found or guessed). Wtf?
4. For some reason I can’t fathom (presumably just laziness), if your card number is stolen, the chip stops working until a replacement shows up.
5. Fancy merchants can arrange a subscription that survives a lost card or even a fraud report against that merchant. But these subscriptions can’t be seen or cancelled on the cardholder website or even by customer service.
But somehow all this comes with fairly stringent PCI requirements, which supposedly represent best practices, despite the entire system design being a case study on worst practices.