In message , Tim writes
No. How on earth can a retailer 'know;' if somebody is 'disabled'.
It doesnt work like that. The terminal will tell the retailer if it requires a Pin or a Sig.
In message , Tim writes
No. How on earth can a retailer 'know;' if somebody is 'disabled'.
It doesnt work like that. The terminal will tell the retailer if it requires a Pin or a Sig.
In message , Mike Scott writes
It would only get this far if you hadnt realised your card had been nicked by the time the card had been used.
In message , James writes
Source?
I dont think it was chip and pin (as we know it)
"Alex" wrote
I know. That's why I wrote "3 guesses" !
Do you think that invalidates my point?
"mogga" wrote
Is there an "Ability Discrimmination Act"? (as opposed to the Disability Discrimination Act)
"Mike Scott" wrote
A short while ago you said :-
------------------------
"Mike Scott" wrote
------------------------
Make your mind up!
I did mention this to the bank's support line. They actually told me they could set the PIN to something easy for me to remember!! Did someone mention "security" just now????
I thought I had :-)
What I was getting at was that in civil cases you only need to show P>50% that you're right, and you win; in criminal case, you have to show P = 100% within some ill-defined approximation. So if the bank says there's only a 1/3000 chance or whatever of guessing a PIN, it follows that they win - unless the user can prove a higher chance that someone 'stole' the PIN.
I think. But IANAL as ever.
I'm reminded of British Rail's wrong kind of leaves. You're using the wrong kind of probability. You can't compare the 0.3% with the 50%. What they'd have to do is to prove with P>50% that a thief using the right PIN is practically impossible. Simply blinding with statistics doesn't cut it.
Sure, it's pretty unlikely that a thief could guess your PIN, but:
(a) given 10,000 stolen cards, the chances of one or more of them matching one of the thief's three lucky numbers are pretty high, and it ought to be straightforward to persuade any court of this.
And more importantly:
(b) guessing isn't the only way of obtaining the number. That that isn't blindingly obvious to everyone I find very hard to understand.
True. But for *any given card* the probability is low. I, the customer, claim my PIN has been fraudently used. The bank argues (a) its system is secure - 0% failure rate [accept for argument's sake] and (b) the chance of a successful guess is near enough 1/3333 [true] and (c) the only other way would be via my own knowledge of the PIN. We know [for argument's sake] the transaction took place. Therefore the chance I must be complicit is is 3332/3333.
But then, I never did like stats :-)
You have more faith than I!
I'm not convinced that courts show either required background knowledge or, frequently, any sensible degree of common sense: wasn't it a long time before so-called "phantom withdrawals" were accepted as a real problem, rather than customer-related? It's an unfortunate fact that in court a lot aparently depends on how much you can afford for a lawyer: and banks have a *lot* of money potentially riding on all this!
I have a distinct wish not to be in the forefront of any forthcoming legal battles :-)
"Mike Scott" wrote
Why - do you think that would be any less secure?
"Mike Scott" wrote
The other 9,999 cases in 10,000 wouldn't go to court. Hence, bearing in mind that the case we are talking about *is* going to court, then the chances of that *particular* card having been victim to a guessed PIN will be higher...
"Mike Scott" wrote
Are you counting shoulder-surfing & thieves obtaining PINs by installing dodgy PIN terminals at sales points as "via the customers knowledge"?
"Mike Scott" wrote
Even ones where you have to prove that you are disabled? :-(
Without a hint of irony, "Matti Lamprhey" astounded uk.finance on 10 Nov 2004 by announcing:
Only in that the PIN is virtually useless without the card.
Without a hint of irony, "Aztech" astounded uk.finance on 10 Nov 2004 by announcing:
That's incorrect. They will be liable if they are not capable of processing EMV transactions. EMV CVMs include online PIN (ATMs in UK), offline PIN (regular transactions in UK), signature and 'none'.
The fact that you use a C&S card does *NOT* make the merchant liable as long as it's processed as an EMV transaction.
Yes, if that's not obvious. "Easy" numbers include plenty like 1111, or significant-date-related. If a number isn't random, it's not as secure. And that's ignoring the issue of bank staff knowing the PIN.
A disputed transaction would be a civil matter decided on the balance of probabilites, the presumption of innocence does not come into it. It would be you on one side claiming that you were not negligent, and the bank on the other claiming that its systems are secure and you must have been negligent, and the judge would decide in favour of the party which has the stronger argument.
Doesn't have to be any less secure, I can remember for example the last 4 digits of the local tax office phone number is 1453 which I used to have to call regularly, that is a number burnt into my mind which I find easy to remember as I used it regularly, it isn't something you are obviously going to guess at is it the local tax office. (and no that isn't a PIN I use BTW)
The only time I have changed a banking PIN over the phone like that they operator explained of what to do and then I was transferred to a automated voice prompt which asked me to enter the number so I wasn't actually telling the operator. To be honest with chip and pin it thought the pin was encoded on the chip so I can't see other than issuing a new card how they could change the pin for you.
"Mike Scott" wrote
Well, obviously, you should choose numbers which don't have the same digit many times (1111), run in order (1234) or are "easy" dates to guess - birthday, anniversary.
But surely you could choose a number which you'd remember, but other people (even close friends) shouldn't be able to guess?
"Mike Scott" wrote
They shouldn't know your PIN (old or new) - you change it yourself at an ATM.
But how do you know the operator (or someone else) wasn't listening in?
The chip isn't read-only. You can take the card to an ATM and go through a PIN-changing procedure there. This will in effect write a new PIN into the card's chip.
"Steve" wrote
Everyone can see that the C&P terminals are not * 100% * secure ....
Have something to add? Share your thoughts — no account required.
Ask the community — no account required