Credit Card Signatures Are About to Become Extinct in the U.S
nytimes.com
nytimes.com
...except card fraud lossed are recharged to the merchant so perhaps they don't care?
Out of interest there is a special exception for disabled people who cannot use a pin pad btw...
I also found this Visa page explaining that PIN isn't used in the US because it's too expensive:
https://usa.visa.com/visa-everywhere/security/the-cost-of-pi...
I never got one though, I ended up getting married soon after and got a UK bank account.
"The last fraud"? Are frauds so rare that it's meaningful to talk about the last one?!
Normally, I pay for everything with American Express. Would you recommend I get a different card for London? I wonder if there's a US card that support chip and pin?
Amex isn't as widely accepted outside the US. If you have a Visa or Mastercard, bring that.
Almost all credit cards issued in the US now support EMV chips. They almost never support PINs, but that doesn't actually matter because all merchants are required to be able to accept all three.
I've traveled all over the world, and never once has this been an issue. Nobody's even batted an eyelid when I give them a US-issued card. Except, of course, for places which only accept cash, but that's a separate question.
But it is easier to use plastic in the Tube, as others have said.
Of course you still have the problem that not eveywhere takes Amex, so getting a Visa is recommended too.
For a long time after EMV chips were introduced, the liability was actually shifted back to the customer. EMV chips were initially a huge step backwards for customer protection, and it took some years before this was fixed in law across Europe.
Nowadays, if you see a merchant who can't accept EMV chips, it's likely their POS vendor who's liable. The merchant is liable in theory, but some vendors still don't provide EMV-capable terminals, so they've agreed to assume the risk until they do.
Whose responsibility is it to make those cards more common, if not Mastercard's?
In Sweden, cards have only been issued with chips since the early 2000s, and consequently merchants only very rarely use signature purchases. Why they didn't push this sooner in the US is a riddle wrappen in a mystery...
The only place I've seen signatures used recently around here have been in busy bars/nightclubs, where stressed-out bartenders don't want to wait for online validation. I guess they get few enough fraud attempts at cocktails that they don't care too much about validation.
The issuers. Of course, Mastercard has some influence over them... But they certainly can't unilaterally dictate conditions to them beyond whatever contract they signed.
There's also the fact that, even if issuers handed them out, the machines and merchant processors also have to support them. Which was something that still hasn't completely happened in the US, even with the networks pushing as hard as they could. (Moving fraud liability to the merchants is about the biggest move they could make.)
I was involved with Australia's chip-and-pin switch in 2006. At the time, we were amazed how slow USA was getting rid of magstripe cards and signatures. And that was 12 years ago...
I have often wondered why the US has historically lagged behind for everyday banking. (e.g. email money transfers, chip enabled cards, pin number verification, tap to pay)
It's a bit of a prisoners-dilemma thing: new technology can only be adopted with sufficient coordination, but each individual party is only interested in cooperating if they think they will "win" from it more than their competitors.
The US seems to be a very bad place for consumer advocacy in general. Perhaps it's seen as "anticapitalist". I don't know if the patchwork regulatory environment of the states helps or hinders this?
In the US it's almost exclusively about beating the other guy.
I mean, in tech, look at the HTTP "referer" header, which is spelled wrong. Imagine what a hassle it would be to fix that.
If there was a Leviathan that could force every vendor and user to eliminate the old spelling or else, it could get done a lot faster.
Everyone uses NFC credit cards now (and if the amount is over ~$40 or a daily limit has been reached, with pin).
For us, chip and pin is basically deprecated, and no one has used magnetic strips in a decade.
–"The system says 'signature needed', was that intentional?"
It _is_ practical though, if you forget your pin code and need to pay something.
It used to be very common in bars/clubs too, at least before contact-free cards, to speed up the payments.
There are a handful of places in the UK that don't have PIN terminals at all and do classic swipe-and-sign transactions, though. The one I encounter most commonly is the onboard cafe car on Great Western Railway trains.
It benefits only consumers, while costing the banks and payment providers. It's the same excuses for still having critical banking infrastructure written in COBOL.
Hogwash. Yes I know all bankers live in extinct volcanoes but one thing they know a lot about is money. It is ridiculously expensive to support the US's conservatism when it comes to finance. The lack of chip and pin pales into insignificance compared to their addiction to paper checks, for example.
It would be completely in the banks' interests if everyone moved to internet banking, NFC cards etc because the running costs and fraud costs are vastly less. The problem is all those pesky, inertia-laden customers.
With a small number of banks and a stronger central government which can exert pressure you can see why the UK and EU are ahead.
When I go to the U.S. I usually have to produce ID when using my credit card. Is this because I am from out of country or do they do this with everyone paying by credit card?
I'm in my late 30s and have never once been asked to produce proof of ID in relation to a standard credit card purchase. Whether at a grocery store, restaurant, etc. I've never seen anyone else have to show ID either, maybe once in the 1980s.
Anyone with some insight as to why want to chip in?
There's also a separate, arguably more deserved stigma about entitled people causing trouble by using unnecessary technology.
These together, along with a reluctance to cause trouble for low-wage clerks, make people reluctant to risk holding up the line by using Apple Pay.
That means fewer people even try Apple Pay, so fewer other businesses see the need to make it available.
In my experience Apple Pay is faster than other payment methods.
In what way do you see it as slower?
However 'Tap and go' is so widely adopted that I haven't carried cash in months and I know people that legitimately don't know their own PIN
Unintentional pun. The US public seems to have a huge reluctance to use the chips in the cards too. It's swipe and sign.
(I'm also from Australia and signing for a credit card purchase went away decades ago. PayWave is really popular, my 89 yo mother loves it.)
Just what does the CC system offer over debit?
https://due.com/blog/addressing-rising-payment-fraud-rates-u...
The only things that are checked are the digits of the amount, and the account number.
The rest of the check can be complete garbage, and the check will go through and the bank will pay it. Then the banks will blame you, the account holder.
I learned this the hard way.
Well, the payee is also usually verified to match the destination account, and a few other elements are technically required for it to be a legal financial instrument (even if banks don't spend the time to check them every time). Legally, a check could be written on the back of a napkin and still be valid - as long as it has a few required details.
The thing I've come to learn about checks is that their security features are not necessarily intended to prevent fraud, but rather to legally prove fraud after it has occurred. So no, banks often will not check those things, but anyone with access to the ACH network can reach into anyone's account and move funds around if fraud is suspected (it's basically a shared database with surprisingly little security). It inherently relies on the legal system to sort things out after the fact, which is a completely different approach from what we see in modern information security (where preventing unauthorized access/behavior upfront is the primary concern).
This is why it’s critical to have transaction alerts for all activity for your financial accounts. Otherwise you could have an ACH slip through that drains your account. You wouldn’t notice till the next time you logged in or, more likely, when you try to use your debit card and realize it’s cleaned out.
Ha! Not even that. In the cheque clearing process, about the only thing that ever gets checked (even by automated processes) is the MICR line (account/transit and institution number).
Everything else (EVERYTHING ELSE) is just assumed to match whatever the person entered at the ATM/image capture app/teller window. The bank considers it your problem, as the cheque writer, to catch any issues on your next statement, and then they'll review the image of the cheque (in many jurisdictions now, the physical cheque is destroyed pretty early in the process). You should really never ever give a cheque to someone you don't trust. It's pretty silly, but that's the reality.
Although, fun fact, it's the cursive amount that is the 'official' one if there's a mismatch between that and the digits, since it's much more difficult to subtly adjust that.
Source: work for an institution that processes literally millions of cheques (I'm not in that area, but yeah).
Also worth noting, it doesn't need to be in cursive. I spent all my life struggling with writing in cursive on checks (because it's pretty much the only place I ever do it). One day, someone told me I could print it (it just never occurred to me that this was acceptable) and I've been much happier ever since (during the, you know, 10 times a year I actually write checks).
In the old days, they would print a computer-readable version of the amount on the bottom of the check, right-justified with the account number. Once that was there, most banks just processed that, and ignored the rest of the check.
The other info on the check isn’t meaningless. It will (should) be examined when there’s some kind of fraud or dispute about a check payment - but it effectively does nothing to prevent fraud or theft.
As you say, none of this will prevent basically any amount of money from being withdrawn from your account however. But you do absolutely have routes available to you to get your money back. If your bank blamed you instead and didn't let you know what options you had then you had a shitty bank that rolled you, you should get a new bank (or a credit union).
Surely this must not be a unique case; what’s supposed to happen in this sort of situation?
In the past, I'd wave around the cancelled check and resolve it quickly. With ebanking, it's hours and hours on the phone and sitting in the bank manager's office refusing to leave until they deal with it.
With that particular one, I eventually made the bank issue a "clawback" on the funds they transmitted. Wonder of wonders, this caused the vendor to find the money they'd received :-)
Maybe this is how life is like in the Valley, but even so I doubt it’s the experience or thought process of the non-tech worker.
I just used a check this month to pay for my earnest money deposit for a house I’m buying. Before that, I’ve had to use either money order or personal check for the deposit and application fee of every apartment I’ve ever rented. Several landlords only accepted checks for the regular rent as well.
They weren’t slumlords (as some of the other commenters here assume), those who took only checks for rent were individuals who rented out a house or apartment building and took good care of it.
I’ve paid my gas bills with checks back when I lived with college roommates.
Checks aren’t as ubiquitous as they once were, but I remember in my life time, growing up, when they were ubiquitous.
Here in Australia, I can just give out my bank account number freely -- the worst you can do to me with that information is send me money.
The only check I routinely write now is to the gas company. They use Western Union as their payment processing vendor and WU charges $2.95. It's petty, but it's easy enough to write a check.
But my last two apartments required cashier's checks for both... so honestly, I don't expect to write another check my whole life.
My renter's for 1.5 years wrote me cheques with payee of wrong first name, and typo in last name.
No issues depositing any
YMMV. Simple won't let me deposit a check made out to "Me and Wife" in my personal account - I can only deposit it in our joint. They'll permit me to deposit "Me OR Wife".
Suffice to say, I went back to my neighborhood bank.
To Simple's credit: Their customer support was beyond fantastic -- they were at the mercy of their controlling bank...who was receiving the garnishment request.
When Simple switched banks last year, I received a check in the mail for $3 and change for the amount that I had left in my account after moving my direct deposits and such over. Just...a massive headache.
Checks have many safeguards against fraud. "Catch me if you can" exploits have protection.
It also depends on the teller, how much of a hardass they are going to be about cashing it. I guess I don't know what the protocol is for for mobile deposit, they may or may not have manual review.
even in cases of fraud?
Unfortunately most US cards don't use a pin code at all. There are a few issuers that provide you with a pin code, but even in those cases there's typically a signature preference and the pin code is only used as fallback if the terminal doesn't support signatures. So if you're using a US card in Europe pretty much the only places where you can use the pin code are automated terminals (e.g., at train stations). At most other places you're going to have to use a signature.
There are a few US issuers that issue Chip & PIN cards with PIN preference - for example UNFCU and First Tech Credit Union. Those cards work great in Europe, but are sometimes a pain to use in the US. E.g., if you're paying at a restaurant and you have to go with the waiter to the terminal in some backroom, because the terminal asks for the pin. That's not an issue in Europe, as waiters usually carry mobile terminals with them.
Huh? I have a European card (chip & PIN, PIN preference), and at restaurants in the US I've always signed and never had to go to the terminal in some backroom.
I had that a few times in Asia (think Vietnam). I quite appreciate the times it happened. Instead of taking my credit card then hoping for the best I specifically have to authorize the transaction. In Europe they usually just bring you a portable device.
I have one credit card that I mostly don't use anymore, and keep the account open only because it does chip + PIN so I can use it at train-station kiosks in Europe.
Don't feel so bad - remember that we invented the credit card.
Also the phone.
And the Internet.
For your example of "the Internet" that's true only if you squint and choose TCP/IP as "the Internet". But if you take a step back the Network is a more or less an inevitability, I would insist on dating _that_ to at least the Treaty of Bern (1874) and perhaps earlier. Of course Bern moves actual paper letters, rather than just bits, but the central idea is there - the network effect, we must communicate with absolutely everybody, if we let national sovereignty get in the way of that we lose out.
Your argument looks a lot like a fallacy, to me.
Buying and selling houses is excruciating thanks to the number of signatures required.
I went to a closing on behalf of my then-wife who didn’t want to deal with it; because it was her house we were selling, I had to sign all the paperwork on her behalf, which involved a signature plus some additional verbiage. My hand was in pain by the time we were finished.
I don’t give two shits what you put down as a signature, I just want a record that you consciously were present and signed something, so I don’t get accused of trying to pass off something quietly that you never agreed to.
If I have some scribble you made at a time and place, the onus is on you to prove it wasn’t you who did that.
Here's one way to think about it. If it was the way you suggest then all an identity theif would have to do is to draw something on the dotted line and all of a sudden you're in a position where you have to prove your innocence.
One of the problems I came across was the number of things I had to send through the postal system. Apparently scanned documents (signed) weren't good, and using a fax machine wasn't an option either.
So I had to print forms, sign them, and then mail them - always with tight deadlines. Luckily only one piece of mail was lost en route, and it was skipped in the end.
(I also had to mail back the physical bundle of title-deeds, something I was told previously was all electronic these days. Fascinating documents though, I remember when we paid off the property we received them and there are copies of each sale contract/price details since the place was built in around 1890. First sale was for £400, then the next for £1200, and every 1, 5, 20 years it would sell for more. Went for £162,500 when I sold it. That's a huge jump from the starting price!)
Yeah, I know :'(
> thanks to the number of signatures required.
What!? You found that the hardest part?
May tips disappear next.
The rest of the world does not tip (Europe & Asia). Only in North America is this awkward tipping practice still a thing.
This doesn't make sense in a society (like the US) where many (most?) people pay for dining out with a credit card.
Tipping is a very in the face sign of inequality and really needs to die (as soon as the inequality is gone of course).
Whilst there's no way I'd ever subscribe to current mentality of tipping 10% when unhappy and 15-20% when happy I'm not sure I'd want to remove tipping entirely. It should be exceptional times when one tips, i.e. really got above and beyond - not just doing their job.
https://en.wikipedia.org/wiki/Tipped_wage_in_the_United_Stat...
So now I find I can get impatient when someone is painfully trying to recreate their exact signature using a digital signature pad that could never possibly have the resolution to do it justice.
The receipt needs to go the way of signatures and hopefully soon.
Not sure if you are a UX person, but the receipt in 2018 is bad UX for the customer and the business! Just like signatures have been for years..pointless, frustrating and annoying!
I wish I could use Apple Pay everywhere!!!
The reason business here have to offer a receipt (but the customer can reject it) is because the customer is supposed to be certain that the transaction is taxed. Typical small businesses with easily hidden turnover (such as restaurants) some times register only e.g. 1/2 purchases, thereby dodging a lot of the taxes. Having to offer a receipt on every purchase makes that harder.
Electronic documents can already carry the same force as paper legal documents. What’s the holdup?
The receipt needs and will go the way of the dodo bird, credit card signatures and etc...
Well, this story/hoax/experiment from the late 90s was at the time the funniest thing I had ever read online:
https://web.archive.org/web/20130120184305/http://www.zug.co...
When I noticed I hadn't signed my card he said he couldn't accept my purchase, so I had to sign the card first, then he could compare the signature...
I rarely remember to sign my cards and this tripped me up one time last year when trying to return something to a store which I'd bought online with my credit card.
I had to leave the store, buy a pen, sign the card and re-enter the store.
That's exactly what I did too. And yes, this was when visiting the UK. I had no idea the strip on the back of the card was for comparison, never seen it used elsewhere. Would be interesting to hear the person who thought that the signature-comparison thing was a good idea explain how they were thinking.
(Backwards, I know, but them's the breaks...)
I recently got a new credit card and nowhere does it say to sign the back.
I always wonder what the point of the signature is in this scenario.
Fraud cause from in-person transactions is very low and hence our merchant fees are also very low. 10-20¢ for debit transactions and approx. 1.2% for credit transactions.
After all, Australian banks are some of the most profitable per customer in the world.
Are lost and stolen cards not a common problem? I suppose if the card holder reports it to the credit card company fast enough, it would prevent fraudulent charges from going through, but it would be nice if the person who found/stole the card(s) wasn't able to just use it without having to enter a PIN to do so.
In the USA, we have to sign at most places for any transaction over $50, but not under.
NZ, Aus, UK, are pretty much on the same level banking tech-wise (with UK bank-to-bank transfers being much quicker). Credit cards are common enough, but most people only have one or two, with lower credit limits than in the US.
I was somewhat amazed to see it was still I thing when I visited the US recently.
Strictly speaking it's still a thing in Australia, but there are always better options -- chip, pin.
I wondered, which kind of graphology training do Tesco cashiers go through in order to be able to identify a fake signature?
> Unsigned Cards
> While checking card security features, you should also make sure that the card is signed. An unsigned card is considered invalid and should not be accepted. If a customer gives you an unsigned card, the following steps must be taken:
> • Check the cardholder’s ID.
> Ask the cardholder for some form of official government identification, such as a driver’s license or passport. Where permissible by law, the ID serial number and expiration date should be written on the sales receipt before you complete the transaction.
> • Ask the customer to sign the card.
> The card should be signed within your full view, and the signature checked against the customer’s signature on the ID. A refusal to sign means the card is still invalid and cannot be accepted.
> • Ask the customer for a different signed Visa card
> “See ID”
> Some customers write “See ID” or “Ask for ID” in the signature panel, thinking that this is a deterrent against fraud or forgery; that is, if their signature is not on the card, a fraudster will not be able to forge it. In reality, criminals often don’t take the time to practice signatures. They use cards as quickly as possible after a theft and prior to the accounts being blocked. They are actually counting on you not to look at the back of the card and compare signatures; they may even have access to counterfeit identification with a signature in their own handwriting.
> In this situation, follow recommended steps listed above under Unsigned Cards.
https://usa.visa.com/dam/VCOM/download/merchants/card-accept...
I'm still waiting.
In the US I have my real signature at the back of the card but I just draw a straight line when signing the receipt. No one ever complained about that.
In Europe I sign with my real signature (because I know that cashiers there are more strict) and even then sometimes hear complaints that the signature on the receipt doesn't exactly match the one on the card.
It's quite the contract with the Netherlands, but then again about 10 or so years ago I wasn't able to identically copy my signature and was unable to get a new bank card... luckily I didn't have this issue online filling out a form.
Most stores have an automatic system where they require pin if a payment has bounced before and in random intervals. But using the direct debit system instead of PIN is so much cheaper that even higher fraud rates don't matter much.
But in general you can't actually sign anymore, you have to either use PayWave or chip and pin.
When you sign a receipt, you’re not just providing a sample of your signature for comparison against the one on the card. You are signing a document, usually saying that ‘I agree to comply with the terms of the cardholder agreement’
If this is no longer necessary, the card issuers must have determined that they have other legal agreements which cover purchases, and that the signature on each transaction is not necessary.
Also missing is a discussion of why PINs are not seen by the banks as an obvious next step.
This sounds like the old myth that "if you don't sign the back of your card, you can't be held liable for the debts you incur if you contest it later."
This is of course not true.
This is in fact the only reason for a signature, it does fuck all to identify somebody, even if merchants were to check it, which they never do.
But with the amount of CCTV nowadays, that's probably more reliable than a signature.
Also ironic that anybody would describe PINs as the next step, I can't remember a time before PINs were used. Even EMV contactless payments are pretty common now, and provide benefits to the banks (liability shift/less chance of PIN compromise) and customers (quicker).
It's not a tech problem, it's a cultural one. You don't realise how much less friction, less hassle it can be until you've lived it. From my time in the US, it seems like it isn't exposed to outside ideas that much, maybe due to it's size.
The EMV standard includes a purchase total verification step where the customer is shown the number and must press OK to confirm. But again speed has been considered more important. That OK? prompt is going away and Quick Chip will first authorize a dummy amount and send the real amount after the transaction is totaled up. It's not like USA market was using PINs for two factor authentication anyway. Restaurants are allowed to adjust purchase totals for tips and closing out tabs.
I'm glad we can finally stop wasting time (and resources, for physical signatures).
This is especially fun with e-signatures in California: “Electronic signature” means an electronic sound, symbol, or process attached to or logically associated with an electronic record and executed or adopted by a person with the intent to sign the electronic record.
https://leginfo.legislature.ca.gov/faces/codes_displaySectio...
The thought process is that my UK drivers license has my picture, full name, and signature. The merchant looks at the ID and sees my photo next to my name, checks it with the name on the card to see if they match, then checks the signature against that on the ID. Unless a thief has the same name as me, they can't use the card as either the photo or the name won't match. The signature doesn't matter as it will be caught in fraud alerting / rejected by the bank.
That signatures are somwtimes compared is secondary, akin to comparing paper types or forensic prints. Contracts are not like a signed bat. They do not become worthless because you forget to cross your T.
CC networks currently use previous purchasing patterns, location, time of day, etc.
It's the same reasons why biometrics is not a magic security solution. Authentication must be based of something that's hard to fake, cheap to verify, random, and easy to change. What threshold would you set to balance false negatives and false positives? In comparison the private key in your chip card meets all of the criteria.
Not so sure about that. If I use a different mouse then my "signature" using those metrics will fail, as I'm basically a completely different (inept) person using other mice. Just an example, but I don't think that e-signatures can be trusted by using machine learning techniques, at least not any that I know of today.
I'm not really suggesting it as "trust" thing, but a better "pin" code that could be combined with the current shopping history/etc metrics being used to detect fraud.
Also, since developing a disability in my hands, that _can't_ be the case -- there _will_ be variations in stroke speed due to level of pain/stiffness at the time.
Imagine being able to pick up your receipt and leave. What I see being the stalwart of signatures are probably restaurants. They require that extra step with the tip.
Your right, can we also remove that stupid bag tax in SF. It easily takes 20 - 30 seconds per transaction.
"Do you want a bag?"
"Ugh, yeah I do"
"Alright that's 50 cents"
"wait, could I get three bags, not two - I don't want my bag to rip"
"Sure, we can do that, 75 cents"
Every. single. time.
The grating, low-grade, annoying, time-wasting inconvenience is supposed to continue to irritate the purchaser until they decide to bring their own bags.
Makes a lot more sense. :)
I have also seen stores that put a barcode on the bag and the bag gets scanned just like any other item. That, IMHO, is the best way to go.
The process will naturally become faster as adoption increases and more people get familiar with it.
The USPS sadly still forces credit card users to have signatures on the back. They don't check signatures against the PIN pad / signed receipts, but the clerk will either yell at you or refuse the transaction if you have "Ask For Drivers License" on the back of the card. This has happened to me on more than one occasion.
This is a business decision they've made not to be in compliance.
Cases are routinely deemed uncollectible in court when challenged and they are required to remove the items from your credit report.
I spoke to a lawfirm in PA who has literally won 100% of the time against Capital One in hundreds of debt cases because they can't provide the proper documentation required by law when asked to collect on their debts.
They primarily rely on people being afraid or ignorant of the laws.
This was mind blowing to me when I first realized it and then researched it and saw actual cases in real time be ruled for the defense.
> “We’ll play it a little bit by ear,” said Michael DeSimone, ShopKeep’s chief executive. “Right now, I don’t think there’s a high level of awareness about this. Let’s get the changes in place and see how they work operationally, and then we’ll adapt.”
I can't imagine the hell of a place that must be to work when extending a feature which works at $25 to any sum — or no sum at all — is that hard. I can think of some really good reasons for it to be that difficult, but all of them sound like a terrible working environment.
That is when the signature pad actually works.
Never once stopped me using them. I'm glad for it because my signature isn't exactly consistent.
In fact, I don't think the swipe and signature method is generally allowed in the UK.
Always gets a smile out of the people accepting it.
Since Square is still requiring signatures though, we can add this to the endless list of things that Jack Dorsey is fucking up.
During election years, I always tell myself I'm going to sign as the presidential candidates, but I never get around to it.
Regards,
A man who currently has a broken wrist.
EMV (Euro/Master/Visa) defines the standard for a chip card. [1]
The cards can be configured as chip+signature, chip+pin or both. The priority ordering can be pin only, sig only, pin then sig or sig then pin (and a bunch of other esoteric rules).
Paywave (VISA) and Paypass (Mastercard) are contactless standards for EMV transactions.
The rules for chip+pin transfer the liability to the merchant (and the merchant bank) for fraudulent use. The liability moves from the card issuing bank. It's a "stick" to make the merchants upgrade. That's why merchants are going to at least chip+signature (ie EMV chip reduces fraud). Moving to chip+PIN reduces fraud even further.
The card issuing banks tend to introduce rules about how safe your PIN is and apply rules to your PIN to stop things like repetitive numbers (eg all 1s), sequences, birthdate matches etc.
Chip + PIN was introduced in the EU and other more advanced than the US banking environments (ie, everywhere) a number of years ago. The "liability shift" for Mastercard happened ~2006, Visa was ~2010, later in some places (eg AU was 2015).
It is only just happening in the US (according to Wikipedia it will be completed by 2020-10-01).
Paywave/Paypass implement new rules on when a PIN is required. In AU it is $100. If the amount is below that, then the liability is accepted by the merchant bank (ie the merchant will get paid). If it is >$100, then a PIN is required for the merchant bank to accept the transaction.
In Australia, if you report your card lost/stolen, then you are not responsible for Paywave/pass transactions. If you don't ("an unreasonably long time"), then you are, unless the card issuer (your bank) can chargeback the merchant (ie <120 days).
This applies to the Credit Card networks (Amex/MC/VISA/Discover/JCB/Union etc). MC and Visa also have "debit" cards that use the same network and are treated basically the same for the merchant.
There are other payment networks (eg in AU there is EFTPOS) which is an AU bank owned network that basically does direct debit from cardholder to merchant online. So if you actually insert your card in the reader, you'll get the choice of "CR" (ie the MC/VISA network, SAV (EFTPOS) or CHQ (EFTPOS)).
So an "ANZ Bank Mastercard" can have 3 different accounts attached, the Mastercard CC account, and two different savings accounts. No one really has a "cheque" account anymore. The banks also issue Mastercard/VISA debit cards (that also offer CC/SAV/CHQ, but CC actually means SAV) and their own debit cards (EFTPOS only).
EFTPOS has much lower fees for both merchants and the banks. That's why Apple Pay hasn't been accepted yet by 3 of the 4 major AU banks, because they don't want to lose their sweet EFTPOS network or pay more to MC and VISA. They also don't want to pay Apple (or Google) more fees in the interchange.
For a while, supermarkets were making people with MC/VISA debit cards insert their cards and only allow them to use the SAV/CHQ options so that they didn't have to pay CC transaction fees for EFTPOS debit transactions.
Anyway, the summary of all this is that moving the US away from signatures is painful because of the disjointed and irrational US banking and payment systems as well as the baked in insistence by users on signatures and paper checks (not cheques, 'cos nowhere that spells it correctly still uses them much :) ).
I believe the latter is the generic notification sound and vendors who customized their solutions post-chip swapped it. I just can't remember which is which right now.