Thieves "bug" debit card PIN pads in 63 Barnes & Noble stores
news.yahoo.com
news.yahoo.com
These sort of exploits are significantly more difficult in other parts of the world that have switched over - the United States use of the outdated "magnetic stripe" for security is not only putting american consumers at risk (Yes, I know, you can always challenge a charge, IF you notice it sneak onto your card, AND if you got to the effort of getting it revoked. Go talk to someone who's been the victim of identity/credit card theft to see how much FUN that is) - it's also putting all the other countries that have to continue to support legacy card systems.
At the very least, the credit card agencies in the United States could start rolling out the Card Machines to NEW businesses, in preparation for the eventual upgrade of consumers.
My only guess is that they've done a RISK/REWARD assessment, and decided that the cost of upgrading all of these systems is more expensive than what they are losing to fraud.
[1] http://www.cl.cam.ac.uk/research/security/banking/nopin/oakl...
US (and Canada, UK) issued cards are verified against the billing address (AVS), in most cases. In other countries (e.g. Australia), this is not the case.
The card number and CVC are typically sufficient; you can put any other address you would like. My Amazon billing address is my work address, which is not the address my bank has (my home).
I wasn't even aware that the chipped cards _had_ PINs.
I think we can all agree that a chipped card + PIN is more secure than a magnetic strip card with no PIN. But, perhaps the reduction in fraud isn't worth the cost of replacing all the old gear.
Credit card fraud should not in any way be lumped in with identity theft, which is a vastly different act that's far more difficult to deal with. Credit card fraud is simply not worth worrying about as a consumer.
I think it is important to make the distinction because calling it fraud directs attention at a party that can actually do something about the overall problem.
He had to challenge each separate charge though - he couldn't just do them all in bulk. Needless to say - not a pleasant experience, and probably cost him 10s of hours.
When my number was stolen my CU directed me to an online form with which I could dispute all fraudulent charges in bulk, and they were reversed two days later.
A friend of mine has a system for that, at least at gas stations. Whenever he fills up, he tops it off such that the price ends in a 7. Then he scans his American Express statement for any gas station charges not ending in 7. Over the years, he's done several successful charge-backs.
http://www.barnesandnobleinc.com/press_releases/10_23_12_Imp...
Fascinating. I wonder how these "bugs" worked. More information here would be great.
However (as mentioned previously) it would be pretty straightforward to obtain an identical terminal, insert a logging circuit inside of it (connected directly to the keypad and card reader), and replace the one at the register with the hacked one.
Then all that's necessary is to recover the modified terminal at a later date and download the logged numbers.
http://krebsonsecurity.com/2010/02/atm-skimmers-part-ii/
I guess you can learn from these pictures how they work.
http://krebsonsecurity.com/all-about-skimmers/
Krebs has a story on POS skimmers w/ pics of pin pad overlay here:
http://krebsonsecurity.com/2011/05/point-of-sale-skimmers-ro...
It seems to me that this type of activity is on the uptick.
The only place I've used it was at the local Wells Fargo branch office with their pads to take out cash out of my checking account.
I bet they have a similar issue. Those pads are networked to their systems, all running Windows, it wouldn't take much to craft something together to pull those #s out.
I remember how reluctant people were during the "dot com boom" to use their credit cards online. Now I am reluctant to use public ATMs, even my own bank's ATM.
http://www.amazon.com/Kingpin-Billion-Dollar-Cybercrime-Unde...
That whole book is full of bizarre and amazing stories about hacking and credit card fraud. It's well written, too; the author was a hacker so the technical descriptions aren't painfully generalized as they too often are. Highly suggested.
A PIN is used to authenticate swiped (magstripe) transactions from a debit card. That said, swiped transactions from a credit card only require a signature -- though many terminals have been upgraded to also require the billing ZIP (postal) code. Most debit cards can also be run as credit cards, effectively bypassing the PIN check.
NFC-enabled terminals (and the cards to go with them) are slowly starting to appear, but even those don't require a PIN. Just a signature.
I was in New York state a while ago, and most places had PIN pads with chip readers. Not a single store person asked me to use it, and the few times I suggested I could, I got blank stares. I ended up signing for a bunch of stuff.
Long story short: just because no-one is using them doesn't mean there's no chip reader.