'Shimmers' are the newest tool for stealing credit card info
1–10 of 88 posts
Re: 'Shimmers' are the newest tool for stealing credit card info
#2https://krebsonsecurity.com/2017/01/atm-shimmers-target-chip...
“The only way for this attack to be successful is if a [bank card] issuer neglects to check the CVV when authorizing a transaction,”
Re: 'Shimmers' are the newest tool for stealing credit card info
#3So shouldn't it be called a sLimmer?
Re: 'Shimmers' are the newest tool for stealing credit card info
#4If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the signature is verified by the bank, I'm not sure how these "shimmers" would be useful, since the secret key would presumably not be compromised and so the shimmer may obtain some data identifying the card and transaction but not the ability to sign new transactions. If the answer is no, none of this is happening, then I'm not sure what the point of the switch was in the first place.
Maybe the answer is something in between? Banks suck, so they've implemented chip cards in a half-assed way with gaping security holes?
Re: 'Shimmers' are the newest tool for stealing credit card info
#5I'm having a surprising amount of trouble finding this information online: does the "chip" include some functionality (maybe called iCVV or dCVV) that allows it to individually "sign" transactions using internal secret keys, or does it not? This was my understanding of why the new system was supposed to be safer. If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the sig…
Re: 'Shimmers' are the newest tool for stealing credit card info
#6Krebs has a post on this as well: https://krebsonsecurity.com/2017/01/atm-shimmers-target-chip... “The only way for this attack to be successful is if a [bank card] issuer neglects to check the CVV when authorizing a transaction,”
1) 'Two factor auth is on, you have to answer two security questions to access your account!' 2) 'Your password is limited to exactly 8 characters ... for security' 3) 'Oh, we now support SMS two factor auth' -- 4 months in, I've received 1 SMS challenge 4) 'You don't want a chip card, they are more hassle' 5) 'We allow systems like Mint to access your account when you have 2 factor auth on. No, you cannot opt out.'
Yeah, don't have the highest confidence that my bank(s) actually understand how to keep things safe.
Re: 'Shimmers' are the newest tool for stealing credit card info
#7I'm having a surprising amount of trouble finding this information online: does the "chip" include some functionality (maybe called iCVV or dCVV) that allows it to individually "sign" transactions using internal secret keys, or does it not? This was my understanding of why the new system was supposed to be safer. If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the sig…
Re: 'Shimmers' are the newest tool for stealing credit card info
#8I'm having a surprising amount of trouble finding this information online: does the "chip" include some functionality (maybe called iCVV or dCVV) that allows it to individually "sign" transactions using internal secret keys, or does it not? This was my understanding of why the new system was supposed to be safer. If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the sig…
Not all terminals in the States support chip functionality, so for the time being chip & pin cards here still have normal mag strips and can be run as older, regular cards - the mag strips can still be read/stolen & used.
These devices read the data between the chip and the terminal. This would be fine, if payment processing consistently used iCVV/EMV, but it turns out they don't.
Re: 'Shimmers' are the newest tool for stealing credit card info
#9Re: 'Shimmers' are the newest tool for stealing credit card info
#10I'm having a surprising amount of trouble finding this information online: does the "chip" include some functionality (maybe called iCVV or dCVV) that allows it to individually "sign" transactions using internal secret keys, or does it not? This was my understanding of why the new system was supposed to be safer. If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the sig…
This is the problem. Some banks don't verify the signature/iCVV.