Live data from Hacker News

'Shimmers' are the newest tool for stealing credit card info

cbc.ca

1–10 of 88 posts

Re: 'Shimmers' are the newest tool for stealing credit card info

#4
I'm having a surprising amount of trouble finding this information online: does the "chip" include some functionality (maybe called iCVV or dCVV) that allows it to individually "sign" transactions using internal secret keys, or does it not? This was my understanding of why the new system was supposed to be safer.

If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the signature is verified by the bank, I'm not sure how these "shimmers" would be useful, since the secret key would presumably not be compromised and so the shimmer may obtain some data identifying the card and transaction but not the ability to sign new transactions. If the answer is no, none of this is happening, then I'm not sure what the point of the switch was in the first place.

Maybe the answer is something in between? Banks suck, so they've implemented chip cards in a half-assed way with gaping security holes?

Re: 'Shimmers' are the newest tool for stealing credit card info

#5
post #4

I'm having a surprising amount of trouble finding this information online: does the "chip" include some functionality (maybe called iCVV or dCVV) that allows it to individually "sign" transactions using internal secret keys, or does it not? This was my understanding of why the new system was supposed to be safer. If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the sig…

Not all terminals in the States support chip functionality, so for the time being chip & pin cards here still have normal mag strips and can be run as older, regular cards - the mag strips can still be read/stolen & used.

Re: 'Shimmers' are the newest tool for stealing credit card info

#6

Krebs has a post on this as well: https://krebsonsecurity.com/2017/01/atm-shimmers-target-chip... “The only way for this attack to be successful is if a [bank card] issuer neglects to check the CVV when authorizing a transaction,”

I have not had the largest confidence in banks abilities to understand security. I've personally dealt with:

1) 'Two factor auth is on, you have to answer two security questions to access your account!' 2) 'Your password is limited to exactly 8 characters ... for security' 3) 'Oh, we now support SMS two factor auth' -- 4 months in, I've received 1 SMS challenge 4) 'You don't want a chip card, they are more hassle' 5) 'We allow systems like Mint to access your account when you have 2 factor auth on. No, you cannot opt out.'

Yeah, don't have the highest confidence that my bank(s) actually understand how to keep things safe.

Re: 'Shimmers' are the newest tool for stealing credit card info

#7
post #4

I'm having a surprising amount of trouble finding this information online: does the "chip" include some functionality (maybe called iCVV or dCVV) that allows it to individually "sign" transactions using internal secret keys, or does it not? This was my understanding of why the new system was supposed to be safer. If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the sig…

This sounds like the attack presented at DEFCON 19 (in 2011!): https://www.defcon.org/images/defcon-19/dc-19-presentations/.... Basically, the chip used to contain all the information present on the magstripe, which made it easy to create a copy of the magstripe via the chip interface.

Re: 'Shimmers' are the newest tool for stealing credit card info

#8
post #5
post #4

I'm having a surprising amount of trouble finding this information online: does the "chip" include some functionality (maybe called iCVV or dCVV) that allows it to individually "sign" transactions using internal secret keys, or does it not? This was my understanding of why the new system was supposed to be safer. If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the sig…

Not all terminals in the States support chip functionality, so for the time being chip & pin cards here still have normal mag strips and can be run as older, regular cards - the mag strips can still be read/stolen & used.

That's true, but the shimmers in question clearly have smart card pins. What you're describing is the traditional skimmer; a shimmer is not merely a thinner skimmer.

These devices read the data between the chip and the terminal. This would be fine, if payment processing consistently used iCVV/EMV, but it turns out they don't.

Re: 'Shimmers' are the newest tool for stealing credit card info

#10
post #4

I'm having a surprising amount of trouble finding this information online: does the "chip" include some functionality (maybe called iCVV or dCVV) that allows it to individually "sign" transactions using internal secret keys, or does it not? This was my understanding of why the new system was supposed to be safer. If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the sig…

> Maybe the answer is something in between? Banks suck, so they've implemented chip cards in a half-assed way with gaping security holes?

This is the problem. Some banks don't verify the signature/iCVV.

Post reply on HN