Earlier quoted context omitted.
Is your counterpoint the below? Is it claiming that Target's practices don't or shouldn't work? "All individuals should know to use /r/shoplifting and are therefore impervious to Target's case-building trap."
No, my counterpoint is that Target’s strategy seems to have worked, and also that there exists the possibility that someone would opt to not shoplift at all due to the harsher penalties set by Target, and being unsure how widespread that practice is. To be clear, I think the actual problem with shoplifting is systemic suppressed wages coupled with inflation and arbitrary price hikes by corporations.
Target's EasySweep – Simplifying Skimmer Detection
141–150 of 151 posts
Re: Target's EasySweep – Simplifying Skimmer Detection
#142Earlier quoted context omitted.
This is plainly untrue. The US has an absurdly consumer friendly legal environment; you simply say you didn’t do the transaction and your money is immediately refunded; it is up to the payment infra to eat the losses. The reason mag stripe and associated technologies stuck around is precisely because US banks were good enough at real-time fraud detection that the cost of fraud was And identity theft is absolutely a t…
> The US has an absurdly consumer friendly legal environment; you simply say you didn’t do the transaction and your money is immediately refunded; US consumer laws don't hold a candle to European ones - it's not even close. Have you ever gone through this process yourself, or are you stating the idealized version of what should happen? I'd like to hear the bank you were dealing with, because mine tried to give me the…
The idea is that if someone steals your debit card and buys a bunch of stuff, they've stolen your money, but if someone steals your credit card and buys a bunch of stuff, they've stolen the bank's money, and the bank is on the hook for it - not you.
IIRC with debit card fraud you've got like 60 days and the bank can put some of the burden of proof on you, but for a credit card you can literally just say "I didn't buy that" 5 months later and the bank basically has to give you your money back. If you abuse this, the worst thing that can happen is the bank closes your card and cancels their relationship with you, but you won't be on the hook for the spending itself. Because of this additional liability, U.S. banks got really good at early detection of fraud and irregular spending, and Americans don't really give a huge shit about keeping their credit cards safe because there aren't really any major consequences.
Re: Target's EasySweep – Simplifying Skimmer Detection
#143Earlier quoted context omitted.
This is plainly untrue. The US has an absurdly consumer friendly legal environment; you simply say you didn’t do the transaction and your money is immediately refunded; it is up to the payment infra to eat the losses. The reason mag stripe and associated technologies stuck around is precisely because US banks were good enough at real-time fraud detection that the cost of fraud was And identity theft is absolutely a t…
> The US has an absurdly consumer friendly legal environment; you simply say you didn’t do the transaction and your money is immediately refunded; US consumer laws don't hold a candle to European ones - it's not even close. Have you ever gone through this process yourself, or are you stating the idealized version of what should happen? I'd like to hear the bank you were dealing with, because mine tried to give me the…
I am sorry you had such a terrible experience, but mine has been completely different.
US banking regs are actually more consumer friendly than Europe, and I have sources. Security Engineering 2nd ed, chap 10 section 10.4.3: https://www.cl.cam.ac.uk/~rja14/Papers/SEv2-c10.pdf
Re: Target's EasySweep – Simplifying Skimmer Detection
#144Earlier quoted context omitted.
Your quoted first paragraph: You make it sounds like this is something bad. What is wrong with Target's actions? I am confused.
Target has the opportunity to correct an individual whose punishment will be a misdemeanor but instead chooses to -escalate- the individual's behavior in order to punish them with a felony. Imagine that the misdemeanor — a fine and a few months in prison — would sufficiently deter an individual from ever stealing again, or at least from Target. Target's theft problem is resolved, and the individual goes on with a mor…
Re: Target's EasySweep – Simplifying Skimmer Detection
#145Earlier quoted context omitted.
> The US has an absurdly consumer friendly legal environment; you simply say you didn’t do the transaction and your money is immediately refunded; US consumer laws don't hold a candle to European ones - it's not even close. Have you ever gone through this process yourself, or are you stating the idealized version of what should happen? I'd like to hear the bank you were dealing with, because mine tried to give me the…
Most Americans use credit cards rather than debit cards for their regular spending, and the additional protections of a credit card is a big reason why. They're treated differently under American law. The idea is that if someone steals your debit card and buys a bunch of stuff, they've stolen your money, but if someone steals your credit card and buys a bunch of stuff, they've stolen the bank's money, and the bank is…
Which was my point exactly: European debit card users are more protected than American debit card users when their money is on the line
Re: Target's EasySweep – Simplifying Skimmer Detection
#146We wouldn't even need to worry about this dumb stuff if we had actual cryptographic PKI for payments. Honestly at some point fraud is 100% the card issuer's fault when the tech to prevent it is here and now. Why I still can't register a public key with my bank and say "do not under any circumstance honor a transaction unless it's signed with my private key" is beyond me.
Guys i appreciate the comment about EMV, I’m aware but it misses the point. They need to be _my_ keys, and ones _I_ can pick and verify. If you don’t generate the key, it’s not actually secure. At minimum, EMV would need to be verifiable. Ideally rotatable. Best case: chooseable.
- an on-card UI. Yubikey-style one-button-tap is not enough, you actually need to verify the transaction details.
- integration with backend systems to support rotation and recovery because otherwise folks will screw this up and lock themselves out
There's a reason webauthn passkey has obfuscated PKI to oblivion, because they simply can't figure out how to entrust end users with keys.
To be clear, I'm a PKI fan and want all of these things to exist, but we're very far from it. In the interim, a bank-managed PKI is a welcome improvement.
Re: Target's EasySweep – Simplifying Skimmer Detection
#147Earlier quoted context omitted.
Preferred gas station here did something to the UI--you can "pay" by waving your phone at it, but then it will prompt for your zip code. When you enter the zip code there's a couple of prompts about ensuring you know you're paying credit price--oops, entering the zip code also answers no to the first question.
That's real dumb and totally defeats the point. That sucks.
Re: Target's EasySweep – Simplifying Skimmer Detection
#148Earlier quoted context omitted.
Likely to avoid defeat attempts. The corporate email requirement acts as a first-line defense to at least try to stave-off would be skimmers / scammers grabbing the CAD file and working out the measurements needed to defeat it.
ah, nothing like security through obscurity!
Re: Target's EasySweep – Simplifying Skimmer Detection
#149Earlier quoted context omitted.
Target has the opportunity to correct an individual whose punishment will be a misdemeanor but instead chooses to -escalate- the individual's behavior in order to punish them with a felony. Imagine that the misdemeanor — a fine and a few months in prison — would sufficiently deter an individual from ever stealing again, or at least from Target. Target's theft problem is resolved, and the individual goes on with a mor…
Lots of jurisdictions decline to prosecute misdemeanor theft or apply light sentences for it.
Re: Target's EasySweep – Simplifying Skimmer Detection
#150Earlier quoted context omitted.
You don't have to have an agreement with Apple or Google to accept Apple Pay or Google Pay. If the customer holds a Visa then the phone presents a Visa to the reader. There is no special thing you have to do to accept those payments.
Unfortunately that's not how it works. There is a protocol at the payment processor for Apple Pay (at least) that has to be followed so that the device card number (not the card number on your card and not a "virtual card") is tied to the correct account. It's a whole thing. Most POS systems ship with support for it at this point. And you have to sign some sort of agreement so that you are compliant. https://www.forb…
I imagine it is possible to do something wrong at the processor to make this not work, due to the device card number shenanigans you mention. But, are there really still processors who still do it wrong? The device card number is associated at the issuing bank, not at the processor (unless I am missing something).