edit: "Chip and PIN" is taken directly from the sec filing that is linked.
the described deadline of october 2015 for the liability shift comes from banks[1] and not a US law or similar.
edit: "Chip and PIN" is taken directly from the sec filing that is linked.
the described deadline of october 2015 for the liability shift comes from banks[1] and not a US law or similar.
You can still get the magstripe data if you compromise the terminal, but the network will (eventually) reject magstripe transactions made by a chip-capable card in a chip-capable reader. You can get the transaction certificate for one transaction, but that TC is protected from replay attacks.
The interesting part to me was it sounded like the managers explained to them that it was all the bank's fault. Not that Home Depot was too cheap and lazy to update their software. And ya got to talk about something while the paint's shakin
edit: Also, keep in mind that some retailers are running POSReady 2009 / POSReady 7, which may look just like Windows XP at first glance.
Don't excuse laziness.
I'd love to be told I'm wrong, and that this can be made into a chip+pin card without physically swapping the card.
Edit: Chip cards provide a Cardholder Verification Method List (CVML) to the terminal. The terminal then decides what method it'd like to use. Options are PIN online, PIN offline plain text, PIN offline enciphered, Signature, or No Authentication.
I've received two new cards in the last month with a chip in them - both were chip and signature.