Credit card terminals have used same password since 1990s, claim researchers
csoonline.com
csoonline.com
This is a prime example of hyperbole. The password only allows you to change things like what is printed on the receipt (the banner), merchant ID and other such things. It basically allows you to enter into a menu to set a few settings. It's not as if you can get a dump of card swipes.
Just a few researchers spreading fear about what has been known for a long time.
Blissful in their ignorance of what was going on they then happily continued accepting transactions for the rest of the day. Oops.
I.E. some protocols I've worked with have had all sensitive data protected by ANSI X9.24 Appendix 1 (I think...) derived keys, or keys derived by various other standard means, such that being able to read the data stream is pretty irrelevant.
> Presumably ... there is some sort of encryption going on.
Color me skeptical. I would presume similarly, but I also would have presumed that they did not have the same password, either. A failure of that scope seems like it could be indicative of a systemic disregard for security.Well, all the security systems have to be audited and signed-off by third-party testing labs approved by the payment card industry body (PCI) so your cynicism should be unwarranted.
But then I've seen code that got through those labs that I would be thoroughly ashamed of, so who knows really...
My understanding is that since there are countless local banks in the US, adoption of technology changes is difficult and slow.
Places like Latin America aren't even thinking about changing cards (heck, we're still adopting the old magnetic cards in most stores!). What'll happen when I visit Canada with my card in one or two years? Will those still be accepted?
http://blogs.wsj.com/corporate-intelligence/2014/02/06/octob...
The US are still using magnet stripes?
We're taking our time, but we're finally moving there.
Edit: despite having chip cards, I've yet to be able to use the chip in the US. Many places now have chip-enabled terminals, but often not set up to use the chip part, and after a few failed attempts I just gave up on it.
How does this affect Square and similar peripheral readers for mobile devices? Will users of those now be liable for fraud?
Interestingly, it looks like this may be the end of the model where the reader is so cheap they can give it away for free, as they list it for $29.
Their original reader was pretty much a magnetic reader head hooked straight to the microphone port, decoded by Square's software on the phone. You could record your card's stripe using a voice recorder program (I tried it for fun) and you'd get this fun squeaking noise from it.
Square's competitors eventually tried to discredit them by pointing out that this data was unencrypted, and that meant that Nefarious People could Steal your Precious Card Data using a Square reader. Square eventually responded by changing over to a reader that encrypted the magstripe data before communicating it to the phone, meaning there must be some sort of digital communication happening over the audio port.
Thanks for the insight!
What about tourists and alike?
Legally (in countries I know about, Europe mostly), the liability is with the bank. They might ask if you gave your PIN to anyone else (you should not do this!) but there's no consumer liability.
The liability shift with Chip & PIN is from the bank to the merchant. If the merchant accepts an old-fashioned stripe transaction they accept the risk for themselves.
http://krebsonsecurity.com/2014/10/chip-pin-vs-chip-signatur...
I've been subject to fraud that could only have taken place because someone observed my PIN (or obtained it some other way). The actual fraud took place in another country where there is no EMV though.
I know the Cambridge research has turned up some interesting stuff - it's possible to use a man-in-the-middle between the card and the reader to convince the reader that a PIN has been entered and verified when no such thing has taken place - but I wasn't aware much of that had been seen in the wild.
--edit-- and it still involves a stolen card at that point doesn't it?
Not if they were using my PIN as that's never used online. Had to be a physical purchase to get that. As a workmate was subject to similar fraud at a similar time we figure it was probably a bar or restaurant we'd been to together, where our cards were skimmed and someone either watched or recorded us entering PIN details.
??
I frequently work in this area and have not heard these stories. Fraud is always covered on credit cards in the UK (for example), by law, and I'm pretty sure it is on debit as well.
To me, knowing how things usually work in the US - they'll claim it's an on your honor system, and then suddenly it will be "well we think you gave someone your pin so we aren't covering the charges". Conveniently a lawsuit will be more expensive for you, the consumer, than just paying off the fraudulent charges.
In the cases I've heard of it's something like a conman comes to the door, wants money "for a building job" or just "for charity", whatever. Says they'll get you the money from the bank, you give them the card and PIN, the bank then isn't obliged to cover the loss.
The measure in the Lending Code (a UK financial institution code of practice) is that provided you've taken "reasonable care" then they cover frauds; giving someone your PIN or writing it down with your card constitute not taking reasonable care.
That seems quite fair to me.
http://www.choose.net/money/guide/faqs/credit-card-fraud-vic... gives good detail. The Lending Code website doesn't but the full code is at http://www.theukcardsassociation.org.uk/individual/lending-c... with additional info, again the UKCA is an association of credit/debit card issuers in the UK.
But then my (chip) card was cloned to a mag-swipe card and someone attempted to use the clone in an ATM in Canada. I don't really know what happens if someone manages to get your original card and your PIN. AFAICT there's not a lot of fraud that happens this way.
See http://krebsonsecurity.com/all-about-skimmers/ for more on how that happens.
That's not giving it, it's having it taken. What constitutes giving your PIN is someone saying "give me your PIN" and you saying "it's XXXX"; similar provisions apply if you wrote the PIN on the card, or made the PIN available in an obvious place. Basically then you've subverted the potential protection of having a PIN.
In the UK being caught by a skimmer does _NOT_ mean you didn't take reasonable care, your maximum liability by law is £50. See eg http://news.bbc.co.uk/1/hi/business/3256799.stm.
The only time I've been subject to fraud in recent years, incidentally, was when my card was skimmed in London and then the clone used to attempt an ATM withdrawal in Canada. So clearly the skimmer had seen me enter a PIN, skimmed the magnetic stripe and then sold the details to someone who could use it in a country where those two things were enough.
Needless to say, I got the money back pretty quickly.
I was thinking of the courier fraud but that seems to be covered. The other version of that where they make the victim make a BACS transfer doesn't seem to be covered in the same way.
Given this I am wondering what kinds of settings are available in the Verifone secret menu. Is there anything like IP address, which could facilitate an MITM if an attacker walked up and changed it?
This password isn't the encryption key. Usually keys would be injected into the terminal either remotely through the POS terminal, POS controller or by shipping a special card w/a magstripe to the store where the manager or loss prevention person would swipe the card on each terminal that has the new key on it. PCI standards dictate that the retailer rotates the keys on a schedule with a documented procedure.
Changing the merchant ID probably would have little effect in most operations because the transactions aren't going directly to the MC/VISA/etc network, but are passing through a dedicated link to the merchant's acquiring bank. I've never tested this, but I would imagine that the acquiring bank would reject transactions that are for merchant IDs that do not belong to the customer that is leasing the connection. This situation actually happens quite often by merchants just mis-keying the merchant ID when setting up new stores.
I've also had Walmart refund partial purchases without my payment card being present. This shows me that it's possible that Walmart stored the payment card information.
You're right, not all POS talk directly to the bank. One of the products I worked on was a store-level switch, the POS would talk to that. However the store-level switch did not have the requisite keys to decrypt all of the data the POS would put out. In particular there are some pieces of data (PIN is one) that must, by card-scheme rules, be encrypted from the point of entry all the way to the bank. The keys used to achieve this are injected into the terminal during manufacture or during an update process that can only be activated using further keys held by the banks, not at the store level.
On your refund - Walmart may well be able to process a refund simply by specifying an amount and a transaction reference - they don't necessarily need to have had the card details to do that. Their bank can take that reference number and apply a refund against the transaction, looking up your account details in their database in order to inform your issuing bank about it. In some cases they may not even need to supply an account or card number to the issuing bank, just a transaction reference.