Chip Credit Cards Give Retailers Another Grievance Against Banks
mobile.nytimes.com
mobile.nytimes.com
I'm paying with my phone via Commbank Tap & Pay [1] and the one part of going overseas I'm not looking forward to is going backwards in banking systems & technology.
Initially, chipped cards were (are?) slower because the approval was transmitted via dial-up (!) or GPRS. The newer terminals (that also support NFC) are using 3G and are fine speed wise. Some retailers even do batched approvals - the terminal does some kind of check and displays "offline approve".
1: https://www.commbank.com.au/personal/online-banking/commbank...
The latter is incredibly rare. The former is your own fault. That's why generally if a PIN was provided the liability is on the card holder.
One thing I'm trying to change is get my partner to stop using a clone credit card they have of mine. It makes it hard for me to do my monthly scan of spending an know what what should/shouldn't be there.
Going forward I hope they get an e-ink screen on the card showing the last spend amount. I dislike when businesses swipe small transactions and you cant see the terminal amount. I generally ask for the receipt in these cases but having the most recent spend on the card would make things that little bit easier.
The idea that PIN doesn't bring fraud down to almost zero is ridiculous and it really is about fees. That's why debit card transactions with PIN have such low interchange, because the PIN brings the fraud down to essentially zero as well.
When chip cards were introduced here, the cards and the readers weren't very reliable, so the rule was "if the reader can't talk to the chip, you swipe the card instead". This would happen if the card wasn't fully inserted, if the contacts were dirty or corroded, etc.
That lasted maybe two years before the fraud increased and the reliability improved to the point that the fallback wasn't worthwhile. Now if a chip doesn't read the answer is "try it again" followed by "do you have a different card?"
The rest is whining by merchants. And look their fraud levels are going down, so they have a reason to like it
Chip-and-pin existed elsewhere a long time ago, if anyone got a non-chip-and-pin reader on the last 5 years they should have known better
Oh I forgot in the US nobody knows the rest of the world exists
Merchants are furious about the required upgrade to a chip-and-signature system which requires them to pay for expensive upgrades to all their POS machines and is much slower to validate than swiped cards, but leaves high interchange fees and doesn’t appreciably bring down their fraud liability.
Well, I agree, but first of all, getting payed in money is not free as well, and second, they should pass that fee on to the consumer then.
This seems backwards. Here in Australia we just pay a rental fee to the bank, for the pin pad human interface device. Everything else is business specific and shouldnt need upgrading...
Banks (including PEDS used by the bank) are audited by VISA to make sure they follow required stanadrds/processes (i.e. see https://www.visa-asia.com/ap/center/merchants/riskmgmt/inclu... although this looks out of date)
In my three year history of taking credit card payments online there has never been a time when I was not made to bare the entire cost of the chargeback plus Stripe's chargeback fees. So I am wondering When, if ever, does the bank or the processor bare the costs of a fraudulent purchase?
EMV reduces fraud a whole lot for card-present payments. It does absolutely zero for online transactions, due to some unfortunate history around (not) integrating chip readers into laptops and desktop computers.
Austria is chip&pin only (except for american cards which are allowed to do magstripe) and interchange fees are < 1%. Sure, part of that has been the EU forcing the networks down to that level, but this could not have been done if Chip&PIN was not in place.
Apple Pay is the best solution. It is quick and since Apple sends a token and not the CC number there is perfect security from hackers as long as the bank ensures that the correct CC is entered in the iPhone. In other words, Apple Pay does not depend on merchants updating their software.
Target and later Lowes (and perhaps Neiman-Marcus) were hacked because they were running their POS terminals on Windows XP embedded which had been last updated in 2006 (the embedded version). Microsoft told the retailers such as Target and Lowes to update their POS terminal software to Windows 7 embedded which is still supported yet they ignored this manufacturer recommendation.
At any rate, the quickest, most efficient approach is to use Apple Pay when you can and all retailers should support it for its efficiency of use and its security.
Chips are great, but in-store fraud transactions (from unauthorized purchases) have scaled downward, until...
Google Wallet, and Apple Pay.
In fact, it's now easier to perform in-store credit card fraud, thanks to such technologies.
This is important because stores are becoming more and more complacent with chip tech, when what they should really be doing is not allowing transactions via Google Wallet, Apple Pay, or any similar technologies.
We'll hear on the news that chips are a big deal — and don't get me wrong, they are — but with new technologies comes new opportunities, and it's now 100x easier to perform a fraudulent in-store transaction, it really makes me laugh how much of an afterthought we're giving these technologies when all you have to say is "chip" and everyone's like "oh okay that's safe."
> In fact, it's now easier to perform in-store credit
> card fraud, thanks to such technologies.
How is it easier for someone to perform fraud using Apple Pay? You'd need to both have and then unlock either my phone or watch to make a payment using them, which is still two-factor authentication...An industry consultant, Cherian Abraham, put the fraud rate at 6 percent, compared with a traditional credit card fraud rate that is relatively minuscule, 10 cents for every $100 spent. Mr. Abraham wrote in a blog post, one of the first to spotlight the issue, that the Apple Pay fraud “is growing like a weed, and the bank is unable to tell friend from foe. No one is bold enough to call the emperor naked.”
The vulnerability in Apple Pay is in the way that it — and card issuers — “onboard” new credit cards into the system. Because Apple wanted its system to have the simplicity for which it has become famous and wanted to make the sign-up process “frictionless,” the company required little beyond basic credit card information about a user. Nor did it provide much information to the banks, like full phone numbers and addresses, that might help them detect fraud early.
When I got an iPhone supporting Apple Pay, I added two cards to it. One just set up with nothing more than entering the information. The other one triggered a phone call to the issuing bank where I had to jump through multiple verification hoops to convince them I was the cardholder.
Apple can't fix the first bank's security problem, and I don't really expect them to.
Both took a few minutes, not really an issue.
You could theoretically call into the victim's bank, and with their SSN + address + etc. add the card to Apple Pay. This would allow you to use the card in-store. Contrast this with previous use, where you the potential damage might range from taking over the account and performing online transactions.
Being able to go from online transactions to in-store transactions is huge. But it's not so simple as just "type in the cc #, zip, and cvv". You need their entire details and to be very methodical. The issue is... people are easily convinced to part with all their identity information.
Really? This strikes me as a nice bit of hyperbole. Most convenience stores I've ever come across have, at most, two or three PoS terminals. Even the most expensive card readers with EMV support—the ones with the fancy colour screens, NFC, and so on—don't cost more than $800 or so.[1] Even with paying someone to set it up, I just can't see the average convenience store spending more than a few thousand dollars.
EDIT: They look like this: http://kytx.images.worldnow.com/images/24359909_BG1.jpg if you aren't familiar with what US gas pumps look like.
There is a small chance retailers and banks will pass on fraud savings via lower prices, but it will be hard to notice a 2-3% price decrease.
It is very easy to notice waiting 5 more minutes for youe morning coffee since each transaction takes 30s instead of the old 3-5s, though.
A reduction in fraud will make running a successful retail business easier, creating more jobs, offering more choice, and leading to more retail entrepreneurs doing what they want to be doing. The knock on effect is that people get to live in a better society with less crime. I think that's quite a significant impact.
Meanwhile, in April one of my cards reissued and now does chip-and-PIN. I've been to Europe twice since then and enjoyed, for the first time, being able to use the automated ticket kiosks in train stations.
POS // Retailers are having fraud and liability shifts forced on them from the payment networks and banks. If a POS // Retailer accepts a fraudulent swipe, they eat the bill now, fraudulent chip purchase (much harder), bank pays.
> does anyone have any insights on why they are doing
> this, and now
Because it cuts shop fraud down to essentially zero, and the rest of the developed world have been using it for long enough to be embarassing that the Americans aren't?FWIW, South Africa started moving to C&P 6 years ago - http://www.bizcommunity.com/Article/196/182/34015.html - as did Nigeria - http://www.atmmarketplace.com/news/postilion-drives-africas-... . And Kenya is further along on the migration than the US - http://www.foxnews.com/tech/2014/02/10/chip-and-pin-future-c... .
You can't enter your card until about 10 seconds have passed after all your items have been scanned, or it blows up.
You must leave your card in for ~20sec, or it blows up, while the machine does seemingly nothing.
The quickest you can complete a transaction is ~30+ seconds; after all the items have been scanned.
Compare this to ~5 seconds with the swipe method.
Now, take 25 seconds / registers * people. That is the lower bound on how much additional time we must wait in line because of these BS machines.
Trader Joe's is now a wasteland of wasted time standing in line.
TJ's put in the new machines and those machines have the constraints I described above.
Europe, its ilk, and their terminals are completely irrelevant.
Not really. It's a valid comparison to figure out what the cause of the problem actually is.
More likely it is just poor specifications and poor execution.
That's the US we're talking about, I'm quite sure their banks built everything from scratch without taking into account what a few decades of use have taught European banks.
It was also slower than is it today when introduced, at least in France (though mostly because connection was over dialup or GPRS).
And now with wireless PIN transactions less than €25 are instantaneous. And above again take the time to enter the PIN.
What pos terminal did you use? Besides you can just use NFC in Europe these days which is even faster.
Also, yes, the banks suck.
The tap terminals have existed in the US for years. Usability was pretty much the same as the swipe method: fast and easy.
Amazing. It's as if they should have just caught up with the rest of the world on Chip and PIN instead of going half the way there.