Even today, two years after the supposedly "drop dead date" for switching to chip cards, 40% of my transactions are by swiping.
0 - There are other reasons, like some ATMs reading the magstripe to ascertain whether a card has a chip and then prompting the user to leave the card in place. I've only encountered older ATMs that do this but it is another reason. But the most common one is that outside-the-U.S. issuers want their cards to work inside the U.S. if a customer of theirs travels there.
So let them have it, why should I care and endure security risk? I've never been to USA nor I'm planning to (at least not unless they fix that gestapo-like border control), but still my every card has a magstripe waiting to get skimmed. If I ever need to go to USA, I'll get a suitable card.
It would be good to raise the bar, but it won't be an end-all solution.
At the end f the day, it's going to take quite some effort to move the entire payment industry to something more secure.
The current state of affaires is good enough in terms of cost for the banks vs loss from fraud.
Even if they see my PIN, they can't clone a chip, so what they are going to do with it?
Trying to use a non-US card in the USA is a pain: most online shops or machines (e.g. NYC Metrocard) require a 5 digit ZIP. Cards from elsewhere don't have a 5 digit ZIP to enter. So usually I can't use those websites, at least if it's a machine I can pay cash.
• information required by the bank,
• information that the bank will check if you supply it,
• information that is not checked by the bank.
The first category, required information, is just the card number for most banks (and the amount to charge, of course).
The second category, checked by the bank if supplied, is everything except for the card number and the expiration date and the amount. This information is used for fraud control. If a merchant supplies it, the bank tells the merchant if it was correct. With many banks the credit card fees are slightly lower if this information is supplied. Even if the merchant supplies this and the bank says it does not match the merchant can go ahead with the transaction, although such transactions have a higher risk of fraud (and therefore chargebacks).
The third category, information not checked by the bank, is the expiration date. The expiration date check is at the payment processor, and that check is simply:
if expiration_date < current_date()
reject_transaction()
The expiration date on a card is just when that physical card is no longer supposed to be used. It is not an expiration date on the underlying account.This is one reason why many people have gotten a surprise when they have had some kind of subscription they no longer wanted, and instead of actually cancelling it they just let their card expire and think the re-billing will then fail. There are three problems with that approach.
1. If the merchant marks a transaction as a recurring transaction some payment processors skip the expiration date check.
2. Some merchants include something like this in their re-billing code:
if expiration_date < current_date()
expiration_date = date_add(expiration_date, interval(3, 'years'))
3. Visa, Mastercard, and Discover (not sure about Amex) have updater services. Merchants can send a credit card number and expiration date to the updater service, and the service will tell them the current expiration date and the current card number for the underlying account. This one can be especially surprising to people because it can update both the expiration date and the card number.It's also possible that there is more checking for transactions that are not flagged as recurring payments.
Payment should require some kind of private information, either from the chip, or from the head of the owner (like a PIN), but preferably both.
> Get rid of the magstripe and bad
> actors will steal your card info
> using cameras
They probably won't though, they'll probably just skim people who don't do that.EMV chip transactions and 3DSecure really ought to eliminate the vast majority of "card number stolen" fraud. Too bad it's all so poorly implemented.
Because banks the world over are notoriously slow about doing anything that might nudge even a fraction of a percentage of customers over to a competitor. If they removed magnetic stripes (which, in the short run, would cost a bank money because that's a specialty card) and said "just contact us if you're going to the States and we'll overnight you a States-compatible card, no questions asked," nothing would stop a competitor from running adverts that say "why wait 24 hours and worry about not getting your card? We issue cards that work in the United States from day one!" Now the person who made the decision to delete the magstripe from cards issued by the first bank is out of a job and so now you see why his or her interests didn't line up with yours.
It's the same reason why chip-and-PIN isn't primary in the United States; chip-and-sign is. Over here, customers have been trained that entering a PIN means the money comes out of a checking (draft/demand/deposit) account while signing means it goes "on the card." Trying to get that mindset changed is more costly than just eating the potential stolen-card-being-used-before-being-shut-down fraud for most issuers.
(Some credit unions, primarily catering to people who travel overseas, and smaller banks that want to differentiate themselves are issuing PIN-primary cards but they are definitely in the minority. I happen to have cards from three of them--First Tech, Spokane Teacher's, and Target--for reasons of security and international use but I am also in the minority. Amusingly, it's large merchants who want PIN-based cards because it puts the onus on the cardholder, not the merchant.)
I've written in my other comment that I did ask. The answer was "it is not possible".
I live in San Diego, 8/10 places where I shop still have chip slot taped closed with a handwritten message "Does not work".
Once it was demonstrated to me, I went back and found out the cards I've had since 2013 (pre-chip).
In so many ways going from Canada to the USA feels like going back in time, and swiping a credit card is always one of them.
Well, we're relatively slow.
That is to say, after inventing credit cards we now have a lull in innovation and feature adoption.
I catch myself falling into that trap.
But since most internet commenters never go anywhere, they buy into the "US is old and backwards and dumb" cliche that makes them feel superior to everyone else.
Because I am the OP of this comment chain, I feel that is directed at me.
For reference, this is me - http://theroadchoseme.com
I like to think I have been a few places, lived a few lives.
I'd blame the 5 companies that control 50% of global credit card terminals that decided to keep things low cost in the US. Much of the blame probably also rests on the 5 banks that issue the majority of the credit & debit cards in the US.
In fact I believe the current chip rules are there just to hobble new entrants in the space. Probably 10-20 startups like Square built readers that they provided for free or nearly free and gave millions of units away. Many of these are garbage as a result, and all of the mag readers will be eventually.
The chip (with conspicuously missing PIN) legislation was a pretty expensive attack on all of those companies, intentional or not.
Considering that Canada's GDP is a rounding error compared to the United States, it's going to take a while to any payment method change to spread nationwide.
That said, I've run into far more "cash only" situations in Canada than in the U.S.
In Australia you pay for fuel after filling up, and one fuel station owner is dealing with an average of a driver or two a day who is unable to pay for fuel.
They don't carry cash, the chip/EMV is failing and they don't have the mag stripe linked to a facility since they're often debit cards.
Apparently the failure rate on phone based payments is also high(er).
It's one of those issues I wouldn't have considered before speaking to retailers.
The problem with a cashless society really is that you assume the tech is reliable. Unfortunately, that's often not the case.
I know you're speaking of NFC chips in cards, but you might know — Does the phone version (Apple Pay/Android Pay/Samsung Pay) still work when my phone's battery is dead?
Though theoretically your phone could have a RF-powered NFC chip in it that took over when the phone is off...
I look forward to having banks issue cards without any mag stripe on them.
Again, that's US-centric thing. Here in Europe, there's >99% cellular coverage (the remaining 1% is usually deep woods and mountains), so it's not a problem. What I don't get is why the rest of the world must still have magstrip and be open to the related risks, when virtually nobody uses it. I've never seen anyone using magstripe over here or see a place accepting it, but I hear about skimmed/cloned cards and emptied banks accounts regularly.
If you are really concerned about having your card skimmed, you can take any simple magnet and erase/scramble the data by waving it over the mag tape.
You can check that things worked by swiping before and after at some place where they'll let you swipe (or by making/buying a reader).
Because, like it or not, it doesn't make economic sense for the issuers to remove them.
The US is still a place where a lot of transactions are done, and despite the last 10-15 years of immigration bullshit, a ton of people still visit the US from abroad. A non-US card issuer isn't going to spend money to get a custom card without a mag stripe in the first place, and also then be at risk of losing customers who do travel to the US. Offering a special mag-stripe-free version of the card for an extra fee likely isn't worth it to them either, especially when they're fine eating the cost of fraud, and don't care that canceling your card is an inconvenience to you.
Magstripe is historically for fallback mechanism when the chip on the card or the reader in the terminal might be damaged.
There is also a class of terminals that may not have the chip reader altogether, for example airlines didn't bother with chip at all for very long time.
That's nicely solved with contactless. You get immediate confirmation that the card was accepted but the terminal still confirms online. The feedback comes 3-5 seconds later. That still allows the retailer to stop you if the card was declined but you can already use the time and don't have to wait until you can remove the card.