Secret Service Warns of Chip Card Scheme
krebsonsecurity.com
krebsonsecurity.com
Basically: the form of fraud it protects against is very rare in the US, and consumers find memorizing another number painful. Europe adopted chip+PIN not because anyone really wanted it but because it was mandated by law. It’s unclear that it has actually been effective.
At one point, I actually just had a single, combined debit and credit card. It worked for both, so I could use it at an ATM, as well as use it as a CC.
EDIT: IIRC, the Debt-to-Income ratio calculation (if you were to apply for a mortgage, for example), is based on your aggregate credit-card limits (used or not), on the assumption that you could be that exposed. I remember when I were a young lad, I had to kill a card (or two?) that I wasn't even using in order to get the mortgage rate I was looking for because of this effect.
There are certain types of payment which are also classed as a cash advance and sometimes catch people out, such as to gambling sites.
So it's generally a very bad idea to get a cash advance on your credit card, especially a credit card that you also use to charge other purchases.
Assuming you can stomach $50 in the case that you do drop the ball notifying the issuer upon realizing your physical card was physically lost, how do the rules differ appreciably?
Also, how does not having a debit card significantly alter the exposure of a given deposit account (eg through the ACH network), besides just having one fewer network address? It seems like the better option is to get a feed of transactions in a convenient manner, whether tablet notifications or an ofx feed.
(Not that I don't want to stick it to the banks as hard as possible for perpetuating this negligent payment network and tricking customers with terms like "identity theft", but just pragmatically speaking)
So once you assume whatever you use will get stolen, you determine what dealing with a stolen card number will be like. With debit cards it's your own cash locked up in a transaction dispute. With credit cards its the credit card companies credit balance and you have no money locked up.
You generally share your bank account number with a small number of trusted parties: employer, landlord, creditors, utilities, tax man, etc. Exposure is low. When you start swiping a debit card around town, you hand out the same level of access to every merchant you buy anything from, and whomever might be skimming their terminals or stealing their databases.
Credit card fraud adds to your balance, but you don't have to pay it while the investigation is ongoing. Typically they revoke your card number and mail you a new one. During that time, you live off of a different credit card your debit card. Critical payments go straight to your bank account and are unaffected. When the investigation is over, the charges disappear. At no point are you deprived of actual money, you merely have an inflated short-term debt.
Good point about a check bouncing though. I would think your bank should waive any charges (after all, you weren't defrauded nor did you write a bad check), but the recipient might complain about their bank's fee (for essentially a rejected ACH transaction, but I digress). Although speaking of checks, readily handing out a printed withdrawal key seems like a poor idea if your goal is avoiding surprises!
Every second website I buy stuff at has my IBAN.
Looks like it's a vety different situation here in Europe.
Sadly, too many US websites don't allow this, I ended up having to get a CC (and pay for it!) just to deal with US bullshit websites demanding a CC. That CC cost me more in fees than I've ever kost in debit transactions.
I only need it for american services though, all EU services I use accept SEPA pull or push, Sofort, giropay or Paypal with a bank account (strangely enough, some american services in the past declines to accept a paypal account without credit card, weird stuff)
Same goes for any SEPA DD based transactions. Everything else is secured via TAN, which depending on what generator method you choose (SMS, Optical, HBCI or Smartphone App) has varying levels of security (Optical and HBCI are highest atm, then App and SMS last, atleast according to my knowledge and understanding of the implementations).
The only bad part is when paypal fucks you over but that's a given risk when interacting with paypal anyway.
Having had ~US$20K sucked out of my debit card (which was ~$10K more than I had), I can verify that you have essentially no recourse. Why the stupid bank authorized someone to go over by such a yuuge amount still baffles me...
Also my bank issues me temporary debit cards for online purchases.
I can chose if the card is for one purchase or for multiple purchases with the same entity, over a period up to 12 months.
I can set a monthly or a total limit.
I can request as many cards as I wish and they are free. I use a new card for every online purchase.
This is particularly evident in East European countries, e.g. here in Poland credit cards are far less common than debit cards. And so people use them to pay in their grocery store as well as in ATMs.
I for example didn't had a credit card until recently, when I wanted to rent a car, it looks like credit card is (almost) mandatory and I use it only for that purpose.
So it just sits in my drawer until once a year I take it out when I go on vacation and rent a car there.
I recently got a new debit card which has the usual (European) chip and pin - but also annoyingly has contactless payment (aka "leech my money"). Sadly the only way to opt out might be to switch banks...
Apparently a lot of cards are dropping the requirement anyway. [1]
[1] - https://www.creditcards.com/credit-card-news/signatures-soon...
Moreover, if you think that retailers are making you sign a piece of paper because they want to hassle you and make you take your money elsewhere, you need to rethink the situation.
Just like sometimes you get a clerk who won't take a $2 bill. Nothing will ever trump human ignorance.
Not in my experience (Europe). Signature must match the one in the card, and cashiers check it most of the times.
At least in UK it was a sort of anti-consumer Trojan horse. Theft decreased by 80% or more, but now the responsibility of the remaining part lays on the user instead of the bank. I remember UK consumer groups quite upset about this ~12 years ago.
In both cases, you can dispute transactions with the banks, and in both cases, the banks are going to open their defence with "but how did the thief know your PIN?" but that does not make it clear-cut, nor does it mean the banks will always win their argument.
Chip+PIN (EMV) prevents this because the chip cannot be cloned, and so it completely eliminates this form of fraud. However, banks also used the introduction of Chip+PIN to move liability of any fraud to the customer, whereas before the banks would fully refund any fraud.
With chip and PIN, who is liable for card fraud?
Consumers remain fully protected from the cost of card fraud and are covered under The Lending Code. From 1 January 2005 there was a shift in liability for some types of card fraud from banks to retailers, but this will not affect cardholders in any way. If businesses have chip and PIN terminals in store, they are covered for the cost of card fraud whether customers enter their PIN or their signature, just so long as staff follow the on-screen prompts and carry out the routine checks to ensure cards have not already been reported lost or stolen. Banks will continue to be liable for the cost of card fraud committed on old-style non-chip and PIN cards, so by accepting them businesses are not putting themselves at risk in any way
So in what way has fraud liability shifted on to the customer?
"our systems are foolproof, and as you can only withdraw money with your PIN, you must have given your PIN out, so it's your problem"
this was mostly ineffective against people that knew the law
Juries are rarely told, and bank officials would hardly volunteer that big frauds often involve a bank insider, and sometimes even an insider the bank has since caught and fired. You won't get the money back from an insider who was taking 10% but you can make a victim of the individual account holder rather than eat the loss at your multi-billion dollar bank. And all you have to do is pretend systems you know are all too fallible are instead perfect.
Ross Anderson has written about some of this on Light Blue Touchpaper
As I've quoted from the website, there was no change to the consumer protection in the introduction of the chip. Your description applies equally well to court cases before and after the technology changed.
Er, no?
I guess it's possible you've actually forgotten what changed here.
It's 1995, I have stolen a VISA card issued to a nice old lady who lives across the street. I walk into a PC wholesaler which allows walk-in purchases, I hand over the card in the name "C. Smith" and walk out with two month's salary worth of Pentium CPUs that can be sold easily for almost their RRP. Did I know a PIN? Nope, just squiggled something that might be "C. Smith" on both the card and the receipt.
When her bank tells her she bought all those Pentiums, she's going to freak. And when she calms back down she'll say she never received that card. Has no idea where it is. Give her back her money.
The bank will of course insist that it's her card and surely she bought all those CPUs. But Ms Smith's lawyer doesn't need a Computer Science degree to understand what happened, and neither does the jury. Smart suit or not, "Her card was simply stolen from the post" is an easy argument to understand and she'll prevail.
Not so when the bank says her PIN was used. Who else could know her PIN? Those are secret. Aren't they?
Why didn't the store want a PIN back in 1995? Because they had no way to validate it, it would be useless to them. Only the _chip_ enables offline PIN verification, and in 1995 even some _ATMs_ were still doing offline transactions.
The transactions are not routinely On Line. Yes, I know, you had to wait 5 minutes the other day in an antique store because their card machine used a dial-up modem. Very annoying. And also quite possibly bogus, there's a good chance that wait was a charade. But why doesn't it have to be online, surely that's unavoidable?
Time for another brief lesson, this time not about history though, this all still true today:
Payment card transactions are really _two_ transactions, the banks make no real effort to correlate the two, and one is done entirely on the honour system.
1. Authorization: Does the card holder authorize this transaction? This is the one that has tightened up considerably due to fraud. But this doesn't move any money anywhere, and doesn't involve any real time interaction with a bank at all. Once upon a time this involved a machine that used carbon paper to take an "impression" of the 3D credit card, and collecting a signature. Today it's "Chip and PIN".
2. Settlement: Who should get paid, and how much, by who? This moves the actual money to the merchant. It's done entirely on the honour system, banks and merchants both routinely screw up, if your country's laws make them they'll eat the cost of fixing that, otherwise they'll probably blame you and make you suck it up. Hooray.
The first one has loads of serious technology thrown at it. Anti-replay for example. If I authorize one $14.99 payment, you can't just show that again to authorize another one.
And the second, which moves the money, undoes every benefit of the first, for example you needn't replay the authorization, just do settlement again for the extra $14.99 without any authorization at all. The bank will hand it over, the customer loses the money, unless they remember to explicitly complain about having $14.99 stolen you can just keep it. If they do complain, say it was a "mistake", you lose the $14.99 but so long as you don't do it too often you'll just get a slap on the wrist and can try ripping off other customers.
What on earth do you want banks to do? Make their systems less secure, so it’s easier for people to convince a court that their disputed transaction was fraudulent?
It’s natural and predictable that banks will argue that security improvements make it more difficult for thieves to make fraudulent transactions, but since these systems aren’t 100% secure, people will always be able to dispute these events and win their challenges.
To use an analogy, it would be like if you improve the reliability of a product you make, then start saying those who RMA your product must have damaged or mishandled it for it to be broken, and deny them their warranty.
This shifting of burden ultimately comes back to the consumer in higher costs and fees, and is just a cost of business for the merchants. The credit card company beneifts because they make money regardless of fraud, and they’ll make increased money from the detachment of the feedback loop from the consumer. Merchants don’t pursue fraud because they simply increase costs to cover it.
In this scenario merchants lose, consumers lose, credit card companies win from increased usage.
Who pays for fraud, in the end? Well, the customers pay, of course, since they are ultimately the only source of funds. Regardless of whether or not the merchant or bank eats the fraud, they are going to recoup the cost through their charges to customers.
It's also pro-consumer in that it lets you use your debit cards without much fear of fraud -- if I were liable for fraudulent charges, I would be _much_ more reluctant to use it anywhere (especially as the bank may not be as incentivised to provide as good a fraud protection), drastically reducing its utility.
I think a sensible solution is to split the liability between the merchant and consumer. Hiding it from the consumer hides it from the one party that would even care about prosecuting fraud.
I don't know a single person with more than one credit card. Why would you even need more than one credit card?
For everyday purchases I use one card for restaurants and gas, another card for groceries and yet another for everything else. Then two other of my cards have rotating bonus categories, so I may use one of those for gas one quarter and for restaurants next quarter.
And, at minimum, you should always have a backup, like a sibling comment points out. Especially when travelling, you don't want to be in the middle of nowhere trying to buy meal only to find out your card has fraudulent transactions and the new one has to be mailed to your house.
Wow. I'm taking it you don't have to pay an annual fee for having a credit card in the US.
Some cards waive the annual fee the first year and some don't. It's whatever the card issuer decides makes them the most money.
Personally, I pay two annual fees and have a third one waived for now. Some of the cards I have I've downgraded to the less benefits no annual fee version of the card after collecting the annual fee version benefits for a year.
Credit cards with an annual fee simply for the privilege of having a credit card, are mostly gone, chased out of the market much like the takeover of free checking.
1) Every day IRL use
2) Backup
3) Restaurants. This is the only use-case where my card is out of my possession, and I try to isolate that.
4) MOST on-line purchases (Except for #5 below)
5) Online subscriptions. These are things like DO or AWS or month-to-month Jetbrains or Safari. This makes it easier to visually scan the statement for things that should not be there, or are wrong. (Billing mistakes are not infrequent).
6) Business expenses. This makes either submitting expenses and/or taxes easier, because it's all in one place.
Chip+sig is so stupid. What is the sig supposed to be helpful for?
While people can always make up arguments for some edge case where it wouldn't work for them, that is anecdotal at best. Resisting change it only going to hurt (economically, technically, knowledge-wise) in the long run. I know that learning from history is not humanity's greatest skill, but actively working against what turned out to be a bad practise seems rather.. strange.
And at the same time, some commercial services jump in to fill the void, which is not something you probably want either due to the risk of monopoly, data sharing and other privacy concerns.
Most EMV countries have standardised on Chip + PIN, and before that on magstripe + PIN, and it is used equally across all of them.
Perhaps the problem is that people still think in terms of 'good guy' and 'bad guy' and nobody wants to be the 'bad guy' that made everyone upgrade their system to some sort of secure payment method. https://www.theatlantic.com/business/archive/2016/03/us-dete...
Basically -- again, as I understand it -- the losses due to credit card fraud is either on the merchant or the card-issuer -- generally the two groups most equipped to deal with the issue. If Visa thinks it's losing too much money due to fraud, they have the control to influence change on the system, put more resources into detecting or preventing it, etc. But they can generally view it as a cost-profit analysis, and handle it appropriately. Of course there's side effects, it costs all of us involving the courts or police, to some degree, but in the absence of a perfect solution in an ideal world, that's something that was going to happen anyway.
Which isn't to say the future couldn't change; money-ed lobbyists, such as Visa, can get the laws in the U.S. system modified to put the onus on the consumer, or on the business (which could drastically damage small businesses), but for the time being, the system does seem, to me, to be working well ... here.
One reason that can work in the US is because there is so much money slopping around in the system from high interchange/network fees. An issuing financial institution may bear most of the risk of fraudulent transactions, but the revenue of interchange fees is easily 10x that of fraud.
So, there are aligned incentives to keep the system secure which ends up being friendly to the individual consumer, but it comes at a cost because consumers bear this cost in the form of opaque fees in everything they buy.
One thing it does do is incentivize the banks to monitor transactions. They know my card # has been stolen before I have a clue, calling me nearly immediately.
I'm personally more attracted to fixing the problem instead of trying to keep dealing with the fallout.
I guess I'm a little confused as to how this works. In the case of my two card issuers "activating" the card means performing at least one fully online transaction at a chip-enabled merchant. (e.g: card present, chip used, pin entered.) If the card's chip were replaced in transit then I wouldn't be able to activate the new card. I'm guessing they are targeting card issuers that have a different activation scheme; but I'm a bit surprised that my extremely small midwestern bank is actually ahead of the curve on card security.
No idea what would happen for a company, but I wouldn't be surprised if some PA picked the answers and wrote them down. Which still makes it hard for a random crook to have them.
I'm more than a bit irritated with this since without the pin you can 'skim' chip cards just as easily as you can magnetic cards.
Would probably be better if at some point it was decided that using a signature is stupid and a deadline for using a PIN was set. But then again, the US hasn't been able to fix the date naming scheme, the measurement system or the temperature system (and it's just 4% of the world that is still using the old ones). I doubt this will ever be fixed.
https://cardconnect.com/company/blog/no-more-signing-for-pur...
That's exactly equivalent to proclaiming that the three dozen major languages still used in Europe should all be abolished, except for English. More than half of all Europeans share no common language. The most widely understood language in the EU, English, only has about 1/2 coverage.
Language is far more important than measurement, and it should be standardized just the same as measurement.
Now see what kind of response you get when you tell the Swedish, Germans, Greeks, Romanians, French, Hungarians, Italians, Dutch, etc. that they all have to abandon their languages for superior efficiency of communication.
Finnish, Lithuanian and Danish are a mere 1% of the EU language base. Estonian is less than 1%. Globally it's that much worse. Why are they persisted generation after generation? It's wildly inefficient and backwards to force them upon children. Where are the widespread calls for abolishing them in favor of English as the primary language, in the name of gaining efficiency?
But honestly the fact is that the various schemes mentioned aren't seen as problems by the vast percentage of Americans and transitioning to something else would be painful to various degrees. And where it's important/useful to have metric and Celsius measurement scales, they're mostly used.
Plus, langauge preserves a culture (literature, etc), which isn't really the same as measurement systems. I wish the UK (where I live) would hurry up and ditch it's remaining imperial units (e.g. miles). It would make life easier.
It's no more difficult to learn two measurement systems, as it is to learn two languages. I'd argue it's dramatically easier to learn two measurement systems.
To learn the metric system, how many concepts do you need to memorize? Not many, it's quite easy. Now try learning Estonian or Russian as a native English or Mandarin speaker. People spend years of effort just to become mediocre at speaking Mandardin as an example.
Now consider, you're born in Finland, and few other people globally or in the EU use Finnish. To communicate well with other foreigners (the other seven billion people), you need a common language (typically English in Finland). The effort involved in learning English at even a moderate proficiency, means you're going to practice and use English for perhaps six to ten years growing up to just become decent at it. Then it further requires that you use it on an on-going / never-ending basis to stay proficient at it. That's because language is radically more complex and difficult than eg the metric system. That need to adopt and maintain a popular common language in addition to the scarce first/primary language, comes at a great time cost when added up across a lifetime.
By contrast, you can teach someone the metric system (someone entirely unfamiliar with it) in a very small amount of time.
More people in the US as a percentage know the metric system than know Finnish or Estonian in the EU.
The cultural explanation for languages, which is common, is no more valid than claiming culture for the imperial system clinging-on that you see in the US. In fact, that's precisely why it hasn't gone away in the US (otherwise it'd have been trivial to abandon). You can explain cultural concepts just as well in English and you can make subtle adoptions into English for phrases or cultural concepts as necessary, without needing to learn an entire other language.
In the US a tall person may be six feet six inches. That's an example of cultural embedding.
In the US, a fast car might go 180 or 200 miles per hour. The speed limit might be 70 miles per hour. That's embedded into the culture.
The three point line in basketball might be at 22 feet. That's culture. The pitchers mound is 60 feet six inches, that's culture.
A first down is ten yards, not 9.1 meters. That's culture. There are dozens of other common, equally valid examples from across US life.
If someone claims those things are not part of US culture (whereas an obscure language phrase is culture), they're simply guilty of arbitrary - and rather comical - snobbery.
In every language you'll have phrases that relate to things from a long time ago, that doesn't mean they have a right to stay. The US has kept to the imperial system, which is your decision, but it's just few other people can understand your steadfastness.
In the UK we have phrases similar to what you mentioned regarding basketball rules, etc. They've stayed and quite rightly; also in russian and french we still have some of these words. But our general attitude to measurement systems has changed, for practical reasons, and quite rightly too.
I was in one of those fancy investment seminars and was seated next to a guy who either was or worked with the Chief Security Officer (CSO) of a big credit card issuer. I had asked how a credit card could justify charging 15 - 30% interest when the fed rate was below 2%. He explained that all of the fraud is covered by the fees and interest. They tune their systems to return the most money per dollar transacted and it is simpler to raise the interest rate across their base by 3% to cover any fraud obligations because they still make the money on the base transaction fee. While more complex security would cut their fraud losses it would also cut their earnings because it would reduce the overall transaction rate and the total number of dollars they process through a transaction.
Think about it this way, someone buys a $500 TV with a stolen or fraudulent CC. The CC company gets $10 from the company selling the TV (2% transaction charge) and covers the $500 "loss" out of interest payments above the cost of borrowing by other customers. End of the day they get their $10 and lose no money. What's not to like? Nobody will regulate them so that they cannot cover their "loss" of $500 by raising interest rates, and they still get their 2%.
It is a pretty classic case that their interests aren't really aligned with those of consumers.
Even if you leave finance charges out of it and are discussing debit cards - the interchange revenue is way more than enough to cover fraud liabilities. Throw in account fees, and you've got yourself a profitable product.
I was working at a small bank during ye old Target/Heartland breach years, and the only time I heard dissatisfaction expressed at the security status quo was when the breaches forced large-scale card reissuances. General fraud scaled proportionally with transaction volume, and was easy to deal with. Mass-reissuance didn't.
Huh. I assumed that the chip had a secret it used to pass a challenge-response type of thing. Can you skim a chip just by observing the data bits that go in and out of it?
The reason shimmers exist at all is that some banks have
apparently not correctly implemented the chip card
standard, known as EMV (short for Europay, Mastercard
and Visa).
Ok, so my assumption was right—in theory—but of course they screw up the implementation!Card fraud is embarrassingly easy in the USA if you're in the right position of employment, even in lower rungs of employment.
Uh... no? Not sure what you're saying. The PIN authenticates the human user, so without the PIN you can use steal a card. "Skimming" is a MitM attack, something expressely designed against in the chip design.
You could only use it on terminals that have EMV turned off or never supported it. Like gas pumps.
I don’t know EXACTLY what it is on the mag stripe that tells the terminal to use EMV mode, if anyone knows I’d love to hear it.
Its in the "service code" field: https://en.wikipedia.org/wiki/Magnetic_stripe_card#Financial...
I think if the first digit is a '2' instead of a '1', that tells the reader to force a chip-only transaction. Or in other words, if you can write the mag data to a blank card, you can set that byte to what ever you want and have a field day. Unless there is some more validation at the bank level? Haven't tried personally.
the second source of fraud is airline tickets and I have no idea how that works. crazy stuff.
I simply don't understand why, apart from too many retailers complaining.
Adding pins to checkout process adds friction and checkout time. It might be a minor amount per transaction. However if you add it up across all transactions, it's a significant amount.
BTW, if you want to see just how efficient chip-and-pin can be, go to a bar in a nordic country. In Helsinki I can pay with chip-and-pin as quickly as cash (assuming change). The bartenders won't even hold a tab open for you, they just charge you every time. I've experienced the same efficiency in Sweden.
ADDED: And you needed new devices but not mobile systems to bring to the table.
This process is probably the largest part of what happens when the terminal/ATM displays message like "Chip initialisation in progress".
Uuuuuh...
The rest of the world has been doing this for at least a decade without any problems at all. You got any kind of citation you can link us to demonstrating that the rest of the world is suffering from this decision in a way that the US is not?
If someone else is your spouse, kid, or personal assistant; you tell them the PIN or ask the issuer for an authorized user card.
I usually transfer them the money through the free, instant, secure and traceable inter-bank transfers that are universally provided by every financial institution in my country to every other financial institution in my country, so that they can use their own card.
Quite frankly, as a consumer I don't need increased security over what we had 20 years ago (mag strip and signature), someone else took the liability for any fraud. Chip+pin is trying to push the cost of fraud on me, and I don't like it. The value of cards over cash or checks is largely because I pay less price for fraud.
Signatures do absolutely nothing in that case so why bother?
It wasn't a valid signature. Even when you attempt to make a legitimate signature on a screen it comes out incredibly poorly. The only legitimaticy is that "someone signed some form of letters/made a drawing of a penis". I can't see why that would ever prevent chargebacks
When you have a documented history of legit signatures on file, signature difference is one of the factors that get considered in the event you file a dispute.
PIN does not mean you are automatically liable for fraud losses. Federal law caps credit card liability at $50. Most issuers eat that too with $0 liability to remain competitive.
I thought that was for debit cards? Or does it apply to both?
There are also state laws that may go further in consumer protection. The card network may also have additional protections. Finally as I've mentioned the issuer often waives all fraud loss liability.
I imagine if banks were required to shoulder the cost of point-of-sale fraud, suddenly they'd be very interested in issuing PINs.
Yeah, there can be a limit on the number of transactions, but my bank and several others just don't care, there's only a limit on a single transaction, currently £30. Genius, just genius.
That's for personal cards, though. Always use a prepaid card when paying for anything, anywhere.
Not sure if they do that in the US or if they'd do it for corporate cards as well, but I guess it wouldn't be a problem to intercept the second envelope for whoever intercepts the cards. In that case the PIN wouldn't add any value.
Now regarding card destruction, I wonder how hard would it be for them to just print fake cards with fake chips that just have the same numbers.
Probably a better solution would be forcing to activate the card in an atm, so that the chip would be validated.. cumbersome but safer.
The idea that employees of delivery companies might be conspiring to do these large scale scams is terrifying.
I remember when a ton of Sony stuff disappeared from the repair depot I worked at. Boy that was a fun day. 300 laptops, freshly repaired that week, gone from the warehouse. Never even made it to the shipping lanes on the other side of the warehouse. And no camera footage despite every angle being covered from the repair store cage to the shipping lanes.
1) Remove scratch off tape
2) Tamper with card
3) Replace scratch off tape
You can get scratch off tape from here: https://www.amazon.com/Security-Evident-Scratch-Stickers-Scr...
People tamper with giftcards this way too.
A simple way to solve this issue is ask for a pin only for first use (provided at the time of activation). That way users will have to use pin only once, after which it can be used like a regular chip card.
Ideally, pin should be asked for each transaction. But I’m the land of the free, PIN is an outcast.
> It could well involve U.S. Postal Service employees (or another delivery service)
I find older generations put a lot of faith in the post office. For instance, one of my investment banks, "in order to securely reset your online password", literally snail-mailed me a new pin number.
Some day, I'd like to be able to able to register public keys with my bank's blockchain and have them only authorize purchases if the itemized invoice is signed by an active private key. One can dream.
Solution: Put chips in humans instead.
Solution: ???