chip and pin danger revealed

Feb 12, 2010 10 Replies

Pin system which are being exploited by fraudsters to use stolen cards. Skip related content

criminals can insert a "wedge" between the stolen card and terminal, tricking it into believing the pin has been correctly verified, when in fact any pin can be used for the transaction to go through. The card meanwhile thinks it was authorised by signature.

most major UK banks. All have been found to be vulnerable."

Pin design and its security.

their banks as the receipt produced states "Verified by Pin".

cardholders have had stolen Chip and Pin cards used by criminals. The banks often tell customers that their pin

receipt will say the transaction was 'Verified by Pin' even though it wasn't."

regulation. The ombudsman supported the banks and the regulators have refused to do anything.

According to the BBC report on Newsnight, see

formatting link
"In November last year the law changed, placing the onus firmly on the banks to prove that a customer has been negligent in any dispute". So it is not true to say that the regulators have done nothing, but it seems to me that the banks can easily prove you *must have been* negligent, in some way or other, if the bank says a transaction was verified by pin.

Now we know how it could be done, that is one of the banks' 'excuses' exposed.

Paper here:

formatting link
It's a clever attack. The card believes that the transation was authenticated by signature while the terminal believes that the transaction was authenticated by pin. Neither side can tell that the other side believes something different. Only two messages between the terminal and the card have to be intercepted and changed.

So with a few hundred pounds of hardware a crook can get valid "Authenticated by PIN" transactions from a stolen card without ever having to know the PIN of the card.

Ironically, the attack is made easier against an honest merchant because we're now all trained NOT to give the card to the merchant. So the fact that the crook is about to plug in a fake card with wires running up his sleeve won't be easy to spot.

Tim.

formatting link
> "In November last year the law changed, placing the onus firmly on the > banks to prove that a customer has been negligent in any dispute". > > So it is not true to say that the regulators have done nothing, but it > seems to me that the banks can easily prove you *must have been* > negligent, in some way or other, if the bank says a transaction was > verified by pin. That is not proof. This is what the Banks used to say and the regulator told that that it is not enough. They have to have more than this.

tim

formatting link
>> "In November last year the law changed, placing the onus firmly on the >> banks to prove that a customer has been negligent in any dispute". >> >> So it is not true to say that the regulators have done nothing, but it >> seems to me that the banks can easily prove you *must have been* >> negligent, in some way or other, if the bank says a transaction was >> verified by pin. >

formatting link
>> "In November last year the law changed, placing the onus firmly on the >> banks to prove that a customer has been negligent in any dispute". >> >> So it is not true to say that the regulators have done nothing, but it >> seems to me that the banks can easily prove you *must have been* >> negligent, in some way or other, if the bank says a transaction was >> verified by pin. >

That's not proof of what?

formatting link
>>> "In November last year the law changed, placing the onus firmly on the >>> banks to prove that a customer has been negligent in any dispute". >>> >>> So it is not true to say that the regulators have done nothing, but it >>> seems to me that the banks can easily prove you *must have been* >>> negligent, in some way or other, if the bank says a transaction was >>> verified by pin. >>

Isn't it obvious from context? Proof that you must have been negligent if the bank says a transaction was verified by PIN.

In message , brightside S9 writes

And: "The card, meanwhile, thinks it was authorised by signature".

So much for signature authorisation, which is a 95% rubber-stamp exercise anyway.

In message , Tim Woodall writes

It will be rather amusing when the till operator takes the fake card out of the machine and tries to swipe it, as often happens. "Oops! Sorry Sir, have I torn your jacket"?

You do it at a terminal where you have to insert the card at the bottom, so that staff cannot easily access the card anyway and your hand would cover the wires. Or there are even better places where there is glass wall between the employee and the terminal.

The the consumer's point the important thing is that you have a chance of proving that a fake signature is not yours. There are probably individual characteristics in entering PINs (timing, pressure out on the buttons), but these are not recorded.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required