http://www.lowcards.com/emv-transactions-slow-37884
Compared to Apple/Android Pay it's painfully slow, but it's also noticeably slower than swiping.
The process can be slower if the retailer uses an older system that hasn't got a permanent network connection. With some ancient terminals, you could hear a modem dialing up and talking to the bank. That was slow, but luckily those kind of terminals are now rare.
Edit: Swiping used to take 1-2 seconds to process, EMV seems to take about 10.
Worse yet, not all the chip enabled readers have the chip part enabled. So you can stick your card in, wait, and then realize you have to swipe. Otherwise, you swipe, get the suprisingly aggressive BZZZRT sound, and then use the chip reader and wait at least 5 seconds while it authenticates.
I'll time it at the local Target. It's slow.
In terms of speed from fastest to slowest: Apple/Adroid, swipe, swipe and sign, swipe and PIN, dip and sign.
When using a chip, my process is: insert card, wait for transaction to complete, remove card, put everything away, go.
You'll notice that putting stuff away happens in parallel with the transaction in the first case, but they're in series in the second case.
It may be reasonably quick, but it's still noticeably slower than swiping. It's not a big deal, but it's just one of those little annoyances.
If we had chip+pin it would be a different story, but because we have to sign, the EMV+sign process is slower than swipe+sign.
Is this seriously a security measure? Even if it did matter, it's on the back of the card anyways, for someone to copy!
Why not just get rid of it?
The US is way behind on this, it's ridiculous.
So is chip + signature, but that's a different argument.
Afaik you can't do that in Europe. At least I've never heard of it being possible.
Conceptually, I don't grasp how possibly exposing my PIN number at a point of sale is MORE secure. I just can't get past the idea that I'm now using the number I use to withdraw funds at an ATM at MORE places than just at my bank.
I doubt it will take much for you to get past it.
And the machine itself checks the PIN against the chip. No sending anywhere, no checking by the clerk.
You only have to trust the machine itself. If you don't, you're fucked anyway because who says a hacked machine will only charge as much as it says it will?
Card+signature is security by "something you have", Card+PIN is "something you have and something you know". That's much more secure.
A signature isn't "something you know" because it's written on the card anyway. If it's not written on the card, then using the signature doesn't do anything in the first place. And nobody checks those signatures anyway. This is why for large purchases they ask to see your ID.
If a machine charged you too much, either it would say so on the receipt and you could protest immediately, or the receipt wouldn't match the charge so you could protest later. Sure, the first few customers might get fucked, but soon the bad machine would be caught. OTOH if the machine processed the current transaction correctly while sending all your codes to the bad guys, it could do so until the store noticed its bad firmware, which could take years.
There's no way around trusting the machine itself.
Banks already correlate fraud reports to where customers have used their cards to track down offending stores that skim cards. They don't have to find the bad firmware, they just have to see "well 10 customers had their cards skimmed, and the only store they had in common was that one"
If someone hacked the terminal I use for an Apple Pay transaction what exactly would happen? It's a one time token that gets passed to the terminal and I immediately get a push update about the transaction.
Most american banks are issuing EMV & Sign cards, which means no PIN. You can set a PIN, but it's not a default flow and you have to call in to get it set.
And we're Chip+PIN here in general. But all merchants provide the Chip+Signature option.