Earlier quoted context omitted.
In the 90s through political turmoil in the Balkans (former Yugoslavia, so perhaps Hungary which borders it to the North was similar), it was impossible for young adults to acquire a payment instrument that worked online (even my dad had a tough job getting a Visa card: you had to deposit something like 500 Deutsche Marks for a limit of 200 DMs, which was like 50x monthly salary, and only one or two banks issued them…
Serif . Publishing it was a great way for me to lose a lot of money I didn’t have.
Offline card payments should be possible no later than 1 July 2026
571–580 of 581 posts
Re: Offline card payments should be possible no later than 1 July 2026
#572Earlier quoted context omitted.
> You won't be able to ride the Tube in London or Subway in NYC with a card that does not support it, for example. Those systems all perform online auths at the gate, they don’t rely on offline transactions at all. Asymmetric encryption is used to prove the identity of the card itself, I.e. prove it’s a real card owned by a real issuer. But it’s not used to sign the transaction itself. Transaction cryptograms, the cr…
> Those systems all perform online auths at the gate, they don’t rely on offline transactions at all. No, there's not enough time for online authorizations at transit turnstiles. They do the online auth as fast as possible, and if it does not go through they put the card on a denylist [1]. But since it would be possible to just make up random valid card numbers on the spot, they do enforce successful offline authenti…
Yes you’re correct. Although as it happens there is a very easy way to get hold of randomly generated valid card numbers. Which is Apple Pay, and is a huge problem for TfL.
But again the asymmetric crypto here is just to validate the identity of the card, and to secure the communication between card and terminal. It doesn’t actually secure the transaction itself in any meaningful way.
> That's true, but doesn't change the fact that offline authentication is an integral part of EMV. Also, the "then thrown away" part could relatively straightforwardly be changed by the networks if ever necessary. The CDA output provides actual non-repudiation.
You ever been part of a network rule change of that magnitude before? I can tell you with some confidence there is nothing easy about. I’ve seen much smaller changes take decades to implement. Making rules change is easy, getting all the participants to implement the change, that’s an entirely different kettle of fish.
> I do suspect that this could change, with EMV becoming more and more accessible for very small merchants using cheap mobile terminals or even regular contactless-capable smartphones. But as I've mentioned, it's not too hard to address these issues using policy.
Nah I doubt it’ll change. There’s already policy level protections to protect against these cases. The standard chargeback process and the removal of merchants with high chargeback rates already prevents this behaviour. Malicious merchants already exist, but they defraud people mostly through social engineering, putting people in positions where they approve transactions they don’t want to, and make it extremely embarrassing for them the victims to report the crime. From the issuers perspective the only type of fraud where are our hands are completely tied, is the variety where customers refuse to admit they’ve been defrauded. Which does happen.
Re: Offline card payments should be possible no later than 1 July 2026
#573Earlier quoted context omitted.
> Huh? If you have worked on this stuff, surely DDA and CDA ring a bell? They're both based on asymmetric cryptography, and they absolutely allow the terminal to dynamically verify whether a given card is authentic or cloned, without having to go online. Yes I was a little wrong here. My most recent experience in this area is dealing with messages on the issuer side. It’s been a while since I’ve done anything serious…
Ah, so you're talking about the edge case where the terminal claims to have, but did not actually, perform ODA? Yes, that's somewhat of a gap in the EMV protocol. As I've mentioned in my other comment, I could see CDA eventually becoming mandatory, as well as keeping the entire CDA output terminal-side. That trace does provide non-repudiation. There are other ways too to stop "sloppy terminal processing", but as far…
No, not even that. Remember that transaction settlement is based only on what’s actually sent over the network. All kinds of stuff can happen between the terminal and card, but if that info isn’t actually sent over the network, it may as well not exist (from a settlement perspective).
So we have no reason to believe that CDA wasn’t performed. Instead we had a network participant effectively mutating presentment messages so they no longer matched the cryptogram produced by the card. We already knew the presentment were mutated because they indicated our card were approving transactions offline that they were configure not to approve. But during the dispute process, we had the acquirer claim that they had valid cryptograms, so we had no right to chargeback. In turn we actually had to go and start decryption cryptograms, and as we expected, the decrypted cryptograms didn’t match the transactions they had been sent with. The transaction amounts didn’t match up.
The sloppy processing was a little more complicated, and was a bit more complex than just badly configured terminals. The types of transactions in question where fairly complex multi-step transactions, that to process correctly required properly supporting some of the slightly more niche network features by both issuers and acquirers. Due to a lack of proper support by many issuer (although we had proper support), the acquirer took some shortcuts to reduce customer complaints, but drastically increasing their own risk exposure. Unfortunately for them an OCG had figured out they could exploit this nuance.
I doubt the OCG had any understanding of the underlying transaction mechanisms. They had just figured out if they followed a specific set of steps, they got free money (or something trivially easy to covert into money).
But to deal with the losses the acquirer was seeing. Some bright spark over there decided they would start forging network messages to try and cover their losses, and shift them onto us. Unfortunately for them, we were more technically competent than most issuers, and more importantly, really couldn’t afford to take the losses.
> I suspect that all of that is a big reason why the networks don't love offline processing if it can be avoided.
Nah the networks don’t care. They get paid regardless, and they’re never on the hook for any losses that might appear. But certainly offline transactions carry a lot of additional risks for issuers (notably it’s impossible to ensure funds will exist to cover any offline payments that might have happened), which are easily mitigated by simply configuring your cards to always go online, and thus shifting the liability on to the merchant if stuff goes wrong.
> And I couldn't agree more to your last paragraph – the industry does have an unfortunate history of propping up questionable security engineering with legal threats. But I'm slightly more optimistic on EMV, at least some implementations: Decades later, we can actually have some nice things :)
Eh, ultimately everything in this world boils down to who has the larger capacity for violence, regardless of what may be correct. Thankfully in most countries we’ve replaced violence with government, police and courts. So now it’s more a question of who has the larger capacity to hire lawyers.
Even if the technical layer supported non-repudiation, I doubt it would make much difference in a court of law. It’s extra evidence for sure, but ultimately most of these things are resolved via settlement based on what makes the most financial sense for the parties involved, which includes many more factors than just the state of the transactions are the heart of such a dispute.
Re: Offline card payments should be possible no later than 1 July 2026
#574Earlier quoted context omitted.
Serif . Publishing it was a great way for me to lose a lot of money I didn’t have.
Thanks! It seems nothing but the homepage works on http://www.serifmagazine.com/ — I assume this is it?
In the backlog of my things to do is a best-of compilation of articles from the published (and one planned but unpublished) issues.
Re: Offline card payments should be possible no later than 1 July 2026
#575Earlier quoted context omitted.
>"people under 60 that uses cash are considered, if not criminal, at least suspicious, like they have something to hide. Or simply wackos." I have barely used cash in 25 years. This doesn't mean anything at all. You're probably putting this solely in the context of using cash for significantly large purchases, e.g. higher 4 digit sum or above, or as in your example a craftsman who want to exempt it from his or her ac…
no we use cards for everything, even for just buying an icecream or something. most older people use cards too actually, but sometimes you can see one struggling with their coins and notes when buying groceries yes.
Re: Offline card payments should be possible no later than 1 July 2026
#576Earlier quoted context omitted.
... information theoretically... you can't it's okay there's already some fraud, waste, loss, inefficiencies, accidents (packages lost, chargebacks by mistake, package arrives weeks later) .... that said the chips have some physical protection, it's not trivial to clone them and the chip has a variable where it stores how much more you can use without online confirmation of course, these are cheap protective measures…
What's the information theory connection in your view? > these are cheap protective measures, They're holding up extremely well. I'm not aware of any cryptographic or physical key extraction compromise in EMV, for example. All known bugs are protocol design oopsies, as far as I'm aware.
Re: Offline card payments should be possible no later than 1 July 2026
#577Earlier quoted context omitted.
I've never handled a £50 note. (I am young enough that if you gave me £1 for every year I've never handled one, I wouldn't be able to afford one. But I am old enough that I could dip into my lifetime of savings to make up the difference.) A friend's dad showed me one when I was at school - that's it. He seemed amused I hadn't seen one before, then after making a minor show of it, as if it was some precious, rare item…
I saw them every day when I worked in central London. The shop staff were no more discerning than with smaller notes. But when the bill is £45, there's no problem anyway.
(Maybe they're a bit easier to get hold of now, especially with recent inflation? But I don't use cash as much as I did when I was younger.)
Re: Offline card payments should be possible no later than 1 July 2026
#578Earlier quoted context omitted.
complicated. star/plus/cirrus etc - pure debit-only networks - aren't accepted on a plane debit cards that are on one of the credit card rails (visa, mastercard, etc) are very common. those work because they're just a normal visa transaction
> those work because they're just a normal visa transaction I wouldn’t be so sure about that. In some payment situations you’re asked whether you’d like to have the transaction go through as debit or as credit—so those two must be different somewhere. And probably in more than just a bit in a packet, as, for example, paying with debit Visas or MasterCards (normal ones, not Electron resp. Maestro) in the Netherlands (…
> I wouldn’t be so sure about that.
I would be very sure about that.
> In some payment situations you’re asked whether you’d like to have the transaction go through as debit or as credit—so those two must be different somewhere
Yes, that is correct.
Re: Offline card payments should be possible no later than 1 July 2026
#579Earlier quoted context omitted.
Credit card fraud is not nearly as common in Europe as it is in the US. Additionally, and specifically in Sweden, the fees that banks charge businesses for handling cash (picking it up and depositing it at the end of each business day) have increased significantly in the last decade or two. This has been a significant factor in driving businesses away from cash - it's just expensive for them to deal with.
Are you sure Europe has less credit card fraud? When is your data from? The US has a much less secure system specifically because there was much less credit card fraud in the US than in Europe. Chip and PIN was an attempt to combat the rampant fraud in Europe. It may be true at this point, I haven’t been tracking recently, but it wasn’t in the past.
Re: Offline card payments should be possible no later than 1 July 2026
#580Earlier quoted context omitted.
There are a few differences for sure. All entirely technical in how the money moves or clears. The most obvious point here is debit card moves your money from your account, credit moves the issuers money from their account. But to your wider point; from a transaction fee point of view you are dead right. Of course a credit card has other attractions; for example it's credit :D but also things like section 75 protecti…
> There are a few differences for sure. All entirely technical in how the money moves or clears. The most obvious point here is debit card moves your money from your account, credit moves the issuers money from their account. From the perspective of the card network and the merchant, there is no difference here. The card network has a contract with the issuer, so all transactions, in all scenarios, are always first p…
But there is a lot more complexity than, I think, you are glossing over. For example, you also likely have at least one technical services partner in the flows, probably two.
Additionally, money often doesn't move in real time, especially when credit cards are involved. The process is, intentionally, split.
Your point on that is fair, but remember, many credit providers are also not banks, and the money is in a bank account owned by a third party. So, as a trivial example, I can't just assume money coming to me from Bank A is related to transactions from Bank A's cards.
A lot of people don't realise that the main way all of this works is through very large batch files with lists of transactions in moving back and forth between various parties behind the scenes.
(We are on semantic points, though, but I just wanted to clarify the complexity behind the scenes that most people don't see or understand)