Visa warns that hackers are scraping card details from gas pumps
engadget.com
engadget.com
This is classic gas station operator whining. Back in 1984, US gas stations were required by the EPA to install double-walled tanks and leak detection. One in four of the old tanks was leaking. Gas stations got 15 years to do it. At the end of 1998, many were hoping for a further extension. They didn't get it. No more fuel deliveries, and they had to go out of business.[2] That's also why, for some years, you saw recovery systems at former gas station sites, trying to suck the gasoline out of the soil.
[1] https://www.gilbarco.com/us/emv-migration-guide [2] https://www.latimes.com/archives/la-xpm-1998-oct-25-me-35989...
This is essentially the same exploit as ATMs with often lower risk since gas station pumps aren’t inspected for skimmers.
The only way to prevent track2 skimming is to remove the magnetic strip however there are also many skimmers today that don’t read the track 2 data but rather scan both sides of the card giving you the CC number, exp date, CVV/CVV2, issuer code (if present) and the card holder details then you can usually perform a card not present transaction fairly easily at best you’ll only have to match the card holder with a post code or a billing address however most issuers will let you pass security with any address that was tied to the card for the past 5 years so your google search results on the name doesn’t even have to be super up to date.
Basically anything but a bulletproof wireless E2EE system will allow skimming. And I’ve seen PoCs for near IR photographic skimmers that try to photograph the card from within the wallet or sleeve with moderate success.
Is the world ready to remove the magnetic stripe and numbers on the card? Only expose them through your online bank and keep them separate from the card. Then only some online payments will be vulnerable - like hotel bookings.
For example Revolut cards still have the stripe, but the card details are hard to read, almost invisible for the eye unless under proper light
This feature won't be too useful in a few years when every payment terminal has NFC, but until then it is nice to have backwards compatibility.
I was in NYC for a week and had to swipe my card at least 6 times during that period. I imagine the rest of the country isn't leaps and bounds ahead.
Really? I have worked in NYC for over three years, and the only card I have ever had to swipe in that time is my FSA/transit card that, inexplicably, does not have a chip yet. There were a few smaller merchants in suburban New Jersey that lagged behind, but even they were on chip by 2017.
“The major difference between a thing that might go wrong and a thing that cannot possibly go wrong is that when a thing that cannot possibly go wrong goes wrong it usually turns out to be impossible to get at or repair.”
They set APRs, fees, etc. to absorb it. The cost is, ultimately, borne by all of us, in either scenario.
I'm not advocating that individuals be held responsible for credit card fraud. I think the current setup is probably the best - the folks with the most ability to smooth out the losses (the banks) have most of the liability.
I'm simply objecting to the "The general populace has no reason to care" statement up-thread. That we're not directly liable for the fraud doesn't mean we're not getting screwed financially by it.
It's no different as an abstract concept than Boeing purportedly sacrificing hundreds of people to try to produce a 0.1% higher ROI. In general, you optimize a number that describes a large system, and you have to consider that there may be tradeoffs - things may get...lumpy.
It's not so much evil as that people have jobs that involve optimizing certain numbers and certain related consequences are outside their purview.
A quantitative improvement could mean implicitly taking away insurance that was gratis.
I have to go inside and pre-auth. This process sometimes only requires a swipe, sometimes chip and pin - but never a zip code.
Could they just fix that?
In my experience the zip code is built into the gas pump machines for 2 reasons: a) provide a least a modicum of security at the pumps the card user is an authorized user; and b) more importantly there is a good chance the manual input of the confirmed zip code provides a slight discount to the gas station with respect to their merchant services contract (which is probably pretty important on low margin purchases of gas).
They could fix it, but I'd be surprised if anyone decided it was worth allocating any resources towards.
One of my British cards (Capital One?) has me use all zeroes.
Check out this video: https://www.youtube.com/watch?v=5b1axnNK-wI
Two attackers. One distracts the clerk, a second slips a skimmer over the in-store point-of-sale terminal in three seconds.
This feels like a business opportunity. Surely there must be a way to build an adaptor?
Call me old-fashioned, but I still like being able to open a bar tab.
I've taken to using my revolut card for places that look a little shady. But ACME petrol station probably wouldn't register as shady for most.
For American Express, at least on Android, I get notifications through the Google Pay app for all purchases made (even if those purchases weren't made using Google Pay).
Unfortunately it seems like support for this does greatly depend on the issuing bank.