'Shimmers' are the newest tool for stealing credit card info
cbc.ca
cbc.ca
If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the signature is verified by the bank, I'm not sure how these "shimmers" would be useful, since the secret key would presumably not be compromised and so the shimmer may obtain some data identifying the card and transaction but not the ability to sign new transactions. If the answer is no, none of this is happening, then I'm not sure what the point of the switch was in the first place.
Maybe the answer is something in between? Banks suck, so they've implemented chip cards in a half-assed way with gaping security holes?
Also, more frequently than I would wish banks or payment processors ask payment terminal operators for a "simpler", meaning less secure, transaction protocol. Most often it's for compatibility with some legacy system from the 80's somewhere in their payment validation backend.
From my experience in the industry, this happened very rarely in Europe but considerably more often in the Americas and Middle East.
I'm guessing the added cost of the fraud liability for swiped cards is turning out to be lower than the cost to convert to chip readers.
In the USA, however, a lot of retailers were still using signatures up until a year or two. It seems to be only in the last year that retailers are starting to move to chip+pin. I think it is simply the large number of credit card terminals, and the cost of upgrading them all.
Now, the internet being a bigger share of retail every year, chip and pin is not an improvement: what we need is 2FA across the board. You have my CC number? Great. Without my 2FA secret, you won't be able to charge me anyway.
This 2FA beats a pin, and would make payment fraud so much smaller, it'd become a minor thing, but good luck finding a bank in the US offering such feature for all charges.
No, that's not quite true. They are moving to chip+pin, but some card issuers are not currently issuing PINs. However the machines themselves fully support chip+pin (and I can confirm this, as most places in the USA now require me to enter a PIN for my card).
http://www.creditcards.com/credit-card-news/emv-faq-chip-car...
Mine only does it when the transaction is large, or unusual. I get a call asking me to confirm the transaction. Maybe they ask some other information, I can't remember.
I haven't been to the USA for a while, and most other countries have a working (not new) Chip+PIN system, but I assume magstripe transactions would be considered higher risk too.
The only exception currently is for gas pumps, for which the liability shift has been extended until 2020.
If the incoming transaction lists that the terminal is chip&pin capable, so you'd simply automatically reject a magstripe transaction with a code that should result in POS showing "please insert card in the chip reader";
If the incoming transaction lists that the terminal is not chip&pin capable, the merchant has chosen to be liable for all fraud cases themselves, so it can't cause a loss for you and your customers. It is an inconvenience, but as all the fraud in the country concentrates on the (fewer and fewer) merchants accepting these transactions, it causes an increasing financial pressure on them to switch.
Not all of it - the chip has a dynamic CVV that differs from the one on the magstripe. This only works if the bank isn't checking CVVs.
Source please? Because if you're right, my bank lied to me when they said they couldn't see whether I paid by chip or by magstripe.
Source: 25 years of EFT development on Bank transaction systems.
It kinda seems like the magnetic stripe system should be completely separate from the chip system. Make it so that the card ID (or whatever) reported by the chip can never be used for swipe transactions, and vice-versa. Combining them just seems to cross-product-ify the attack surface, which is dumb.
Only for countries like USA which have not completed the move from magnetic readers.
An old school version of this would be installing a camera in top of your ATM and recording your card data with the stripe, which as you say would be the stripe's fault, but here they get the information and the pin simply from the shimmer, which looking at the picture shows only a chip connector.
Then a fraudster can duplicate the card exactly, and use the duplicate with the same pin at a random ATM across the world. I think this is why banks can block your card if you didn't warn them about going abroad, as they're unable to tell if this is your card or a replica of your card used by a fraudster.
Furthermore, they can't get the card private keys in this manner, so they can't duplicate the card chip, only its magstripe; and they are definitely able to tell if a replica of your card is suddenly used in a magstripe-only mode. This means that it's a problem, as the parent post said, "only for countries like USA which have not completed the move from magnetic readers" because otherwise you can simply reject any transactions that might use a cloned magstripe.
That being said, this doesn't allow to duplicate a card (it relays the fraudulent transaction in real time to the real card while it's stuck into compromised hardware), the PIN is captured from video or the "la-cara"device, and you do need to have the "extracting" device mounted to a real ATM for prolonged periods until you can empty it (you can do it only as fast as the real transactions come in, and they do so at unpredictable intervals), which gives a nice opportunity to capture the involved people. It's a very powerful proof of concept, but harder to scale than the current "cashout crews"/mules - the logistic problems are somewhat comparable to the classic approach of setting up a completely fake ATM.
PINs really only just deter someone from physically stealing your card and then using it, so until card theft becomes a problem, I don't think we're going to be moving to chip-and-PIN any time soon.
(On the bright side, Android/Apple Pay are generally good enough to function as chip-and-pin: it's as secure as a chip card, and don't allow thieves to use your cards unless they're either sophisticated enough to get past the fingerprint sensor, or they know your passcode. It's just a bit awkward to set up.)
(though mostly because they don't want credit card payments to be easier than debit or cash).
Funny as it may be my debit card for some reason has a $500 (unmodifiable) limit on chip&pin purchases, but it has no such limit for swipe purchases. When I asked them how is that more secure, I got a verbal shoulder shrug.
Banks are in the business of underwriting. I believe at least on the corporate level they probably don't like the idea of fully secure, verifiable payments, because that would mean you don't need them anymore.
These devices read the data between the chip and the terminal. This would be fine, if payment processing consistently used iCVV/EMV, but it turns out they don't.
This is the problem. Some banks don't verify the signature/iCVV.
https://krebsonsecurity.com/2017/01/atm-shimmers-target-chip...
“The only way for this attack to be successful is if a [bank card] issuer neglects to check the CVV when authorizing a transaction,”
1) 'Two factor auth is on, you have to answer two security questions to access your account!' 2) 'Your password is limited to exactly 8 characters ... for security' 3) 'Oh, we now support SMS two factor auth' -- 4 months in, I've received 1 SMS challenge 4) 'You don't want a chip card, they are more hassle' 5) 'We allow systems like Mint to access your account when you have 2 factor auth on. No, you cannot opt out.'
Yeah, don't have the highest confidence that my bank(s) actually understand how to keep things safe.
I got exactly that line fairly recently. To be fair, it probably is much more of a hassle from what I've heard, so they're not wrong, exactly. It seems like the chip+pin rollout has been bungled pretty terribly.
That's awful! By using the two-factor wording it's deliberately misleading people who don't know much about it.
As a consumer, I am indemnified by my bank, per Regulation E, against fraud from swipes. I get no benefit from the slower chip + sig system.
Why would they do this? The assumption is that the thieves plan to use the chip data to create fake magstripe card or make online purchases somewhere that the CVV is not checked. Not checking the CVV is a complete failure, and apparently for once it's not a US failure (unless the thieves are targeting tourists??).
So one possibility is that they're stealing magstripe data off the chips for cloning and use in the US banking system.
Disagree. Consumers and businesses (ultimately) pay the interchange fees, and this class of problem is the domain of payment infrastructure providers. I'm not interested in keeping vigilant against the latest exploit, and unless the responsibility for dealing with the problem lies with credit card networks and processing gateways they'll have no reason to stop rolling out crappy easily-owned payment tech.
I'm talking about Visa PayWave/Mastercard PayPass - both work through NFC and won't surrender any data to a normal reader, you need an authorized terminal that can give an authorization key valid for a given time. There were some attacks against it, but you can't just swipe a card through a wallet, it's extremely time sensitive and requires access to a valid terminal.
Your personal experience is not a valid scientific reasoning. If it was: "I have not used more than maestro cards and my 4-digit pin in 4 years. I did not have a single fraudulent transcation for 4 years now. [...] Maybe we should just use this everywhere!"
So shouldn't it be called a sLimmer?
The card decides if the PIN is correct, but it might be possible to record all the PINs that were tried.