https://krebsonsecurity.com/2017/01/atm-shimmers-target-chip...
“The only way for this attack to be successful is if a [bank card] issuer neglects to check the CVV when authorizing a transaction,”
https://krebsonsecurity.com/2017/01/atm-shimmers-target-chip...
“The only way for this attack to be successful is if a [bank card] issuer neglects to check the CVV when authorizing a transaction,”
1) 'Two factor auth is on, you have to answer two security questions to access your account!' 2) 'Your password is limited to exactly 8 characters ... for security' 3) 'Oh, we now support SMS two factor auth' -- 4 months in, I've received 1 SMS challenge 4) 'You don't want a chip card, they are more hassle' 5) 'We allow systems like Mint to access your account when you have 2 factor auth on. No, you cannot opt out.'
Yeah, don't have the highest confidence that my bank(s) actually understand how to keep things safe.
That's awful! By using the two-factor wording it's deliberately misleading people who don't know much about it.
I got exactly that line fairly recently. To be fair, it probably is much more of a hassle from what I've heard, so they're not wrong, exactly. It seems like the chip+pin rollout has been bungled pretty terribly.
As a consumer, I am indemnified by my bank, per Regulation E, against fraud from swipes. I get no benefit from the slower chip + sig system.