Live data from Hacker News

'Shimmers' are the newest tool for stealing credit card info

cbc.ca

11–20 of 88 posts

Re: 'Shimmers' are the newest tool for stealing credit card info

#11
post #4

I'm having a surprising amount of trouble finding this information online: does the "chip" include some functionality (maybe called iCVV or dCVV) that allows it to individually "sign" transactions using internal secret keys, or does it not? This was my understanding of why the new system was supposed to be safer. If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the sig…

This sounds like the attack presented at DEFCON 19 (in 2011!): https://www.defcon.org/images/defcon-19/dc-19-presentations/... . Basically, the chip used to contain all the information present on the magstripe, which made it easy to create a copy of the magstripe via the chip interface.

With that information i make the conclusion that it should not be a problem in countries that have moved 100% to "chip & pin".

Only for countries like USA which have not completed the move from magnetic readers.

Re: 'Shimmers' are the newest tool for stealing credit card info

#12
post #5
post #4

I'm having a surprising amount of trouble finding this information online: does the "chip" include some functionality (maybe called iCVV or dCVV) that allows it to individually "sign" transactions using internal secret keys, or does it not? This was my understanding of why the new system was supposed to be safer. If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the sig…

Not all terminals in the States support chip functionality, so for the time being chip & pin cards here still have normal mag strips and can be run as older, regular cards - the mag strips can still be read/stolen & used.

And it's unlikely that this will change anytime soon due to the lack on incentives on all sides.

Funny as it may be my debit card for some reason has a $500 (unmodifiable) limit on chip&pin purchases, but it has no such limit for swipe purchases. When I asked them how is that more secure, I got a verbal shoulder shrug.

Banks are in the business of underwriting. I believe at least on the corporate level they probably don't like the idea of fully secure, verifiable payments, because that would mean you don't need them anymore.

Re: 'Shimmers' are the newest tool for stealing credit card info

#13
post #4

I'm having a surprising amount of trouble finding this information online: does the "chip" include some functionality (maybe called iCVV or dCVV) that allows it to individually "sign" transactions using internal secret keys, or does it not? This was my understanding of why the new system was supposed to be safer. If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the sig…

Magstrip only terminals are still widely used in the US.

Re: 'Shimmers' are the newest tool for stealing credit card info

#14
Lots of comments here about magstripes and the failure of the US banks to get rid of them. Funny thing about that is this is a Canadian article about this happening in Canada, and shimmers actually steal data off chips - not magstripes.

Why would they do this? The assumption is that the thieves plan to use the chip data to create fake magstripe card or make online purchases somewhere that the CVV is not checked. Not checking the CVV is a complete failure, and apparently for once it's not a US failure (unless the thieves are targeting tourists??).

Re: 'Shimmers' are the newest tool for stealing credit card info

#15
post #4

I'm having a surprising amount of trouble finding this information online: does the "chip" include some functionality (maybe called iCVV or dCVV) that allows it to individually "sign" transactions using internal secret keys, or does it not? This was my understanding of why the new system was supposed to be safer. If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the sig…

This sounds like the attack presented at DEFCON 19 (in 2011!): https://www.defcon.org/images/defcon-19/dc-19-presentations/... . Basically, the chip used to contain all the information present on the magstripe, which made it easy to create a copy of the magstripe via the chip interface.

> the chip used to contain all the information present on the magstripe

Not all of it - the chip has a dynamic CVV that differs from the one on the magstripe. This only works if the bank isn't checking CVVs.

Re: 'Shimmers' are the newest tool for stealing credit card info

#16
post #4

I'm having a surprising amount of trouble finding this information online: does the "chip" include some functionality (maybe called iCVV or dCVV) that allows it to individually "sign" transactions using internal secret keys, or does it not? This was my understanding of why the new system was supposed to be safer. If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the sig…

This sounds like the attack presented at DEFCON 19 (in 2011!): https://www.defcon.org/images/defcon-19/dc-19-presentations/... . Basically, the chip used to contain all the information present on the magstripe, which made it easy to create a copy of the magstripe via the chip interface.

From the issuer side, the solution to remove this risk is simple (and I believe I was told it in an EMV implementation seminar 10 years ago):

If the incoming transaction lists that the terminal is chip&pin capable, so you'd simply automatically reject a magstripe transaction with a code that should result in POS showing "please insert card in the chip reader";

If the incoming transaction lists that the terminal is not chip&pin capable, the merchant has chosen to be liable for all fraud cases themselves, so it can't cause a loss for you and your customers. It is an inconvenience, but as all the fraud in the country concentrates on the (fewer and fewer) merchants accepting these transactions, it causes an increasing financial pressure on them to switch.

Re: 'Shimmers' are the newest tool for stealing credit card info

#18
This happened to me recently when my card data was stolen in a very respectable place where I've been a long time patron. It was totally unpleasant surprise. Right the next day the fraudulent transactions on my card started to popup all over the world - Beijing, North Carloina, etc. My bank promptly blocked the card - but I had to deal with the pain of calling in, going over my transactions list, verifying my identity and then waiting 2 weeks for a new card in the mail.

Re: 'Shimmers' are the newest tool for stealing credit card info

#19

Lots of comments here about magstripes and the failure of the US banks to get rid of them. Funny thing about that is this is a Canadian article about this happening in Canada, and shimmers actually steal data off chips - not magstripes. Why would they do this? The assumption is that the thieves plan to use the chip data to create fake magstripe card or make online purchases somewhere that the CVV is not checked. Not…

The article is lite on specifics, but my Canadian chip card will normally reject stripe transactions in Canada (or it did the last time I saw a stripe machine, several years ago), but happily perform them when I cross into the US.

So one possibility is that they're stealing magstripe data off the chips for cloning and use in the US banking system.

Post reply on HN