(1) If the foreign use is "online" to the UK issuer, they could reject the transaction as "chip required", couldn't they? (2) If the foreign use is "offline" to the UK issuer, wouldn't liability lie with the foreign acceptor of the card?
Didn't find your answer? Ask the community — no account required.
A
Alex Heney
Based on my experience, most pin entry devices in shops are harder to overlook than most ATM pin entry pads.
And VERY much harder to install a camera overlooking them without it being an "inside job".
What makes you say that?
I don't know how far away it *is*, but I would have expected months rather than years.
Not round here.
They were not working one day last week in my local Tesco, but that was the first time I have come across any installed but not working.
Just requiring verification from the issuer whenever a supposedly non-chip card is presented would deal with that problem pretty quickly.
T
Tumbleweed
Oh really? This court case would say differently.
formatting link
J
Jim Ley
Not in mine.
which it's naive to pretend it never is, indeed one of the many cases is of a till assistant watching the pin then simply not returning the card.
The fact that even now a long time after their introduction, Tesco can't manage to keep the system up, Waitrose haven't even installed it, let alone all the other businesses. Also of course my C&P&Magstripe cards all have years of validity on them.
So phone the issuer every time? That's crazy.
Jim.
T
Tumbleweed
Magstripe cards are here for a *very* long time for compatibility internationally and that gives a let out to UK retailers. How long before all ATMs are C&P enabled? Also, I dont believe the US has any plans to introduce it either.
J
john boyle
In message , Tumbleweed writes
Thank you. You may stand down form the box. :-)
J
john boyle
In message , Jim Ley writes
Eh? No, C&P dramatically reduces the chance of cloning. That is the whole point!
That would be crazy!
Yes, but it is the chip bit that does the work. It wont matter if you clone the strip bit becuase you cant clone the chip & pin bit.
J
john boyle
In message , Tumbleweed writes
There seems to be some confusion entering into this thread.
The situation regarding ATMs is exactly the same pre C&P as it is post C&P (for the time being) and any misuse at an ATM would not be C&P fraud.
A
Alex Heney
In what way?
That wasn't what decided the outcome of that case at all.
In fact AFAICS, it wasn't even an argument advanced. Otherwise, the bank (not in the UK, BTW) would not have requested a court order banning publication of the vulnerabilities in their system.
You can hardly apply for a an injunction preventing publication of the details of something you claim doesn't exist.
A
Alex Heney
But is what is done *as standard* by most machines in most shops.
All that is needed is to add the check for whether the account actually has a stripe only card.
M
Mr X
In article , Alex Heney writes
It's years away because the US refuses to adopt C&P so all machines world-wide must support the stripe
A
Alex Heney
True.
But I don't expect the UK magstripe only cards to be usable for all that much longer.
J
john boyle
In message , Tim writes
The IFA arranged the original investment at which point he performed the first part of the fraud. Many many months later her performed the second part in which he got the investors dosh without the investor knowing.. I hope you dont mind if I dont go into details, suffice to say false documents were uttered by the IFA.
I would regard the false documents to be equivalent to a cloned card. In the scenario you describe there must be some link from the thief to the customer because the customers card must have been available to some third party at some time in order to perform the clone. The cloned card may pass through other hands before reaching the thief.
Yes and he had to sell his house to repay the investors despite trying to pass title to a third party prior to the court hearing! The judge was clever. After pleading guilty the criminal stated he had paid all the dosh back, and had no more dosh and would go bankrupt if he had to repay it all and nobody would get any more. The judge knew this was untrue becuase of the house transaction. So, after asking for the usual reports he bailed the guy for two weeks and said 'In two weeks you will come back here in front of and give me all the money that you stole that you havent repaid and when I see what the shortfall is, if any, I will then decide how long to send you to prison, because you WILL be going to prison". This gave him an incentive to repay as much as poss so as to, in effect, buy his way out of jail. So he had to unravel the transaction with the house and paid it all back, hence the relatively short sentence. (The third party was his daughter who was (wait for it) a defence barrister!)
J
john boyle
In message , Tim writes
None.
A
Alex Heney
Yes. I was careless in what I assumed there.
I assumed he was talking about UK cards only. It will not take much work to reject any UK magstripe only card once there are no more in circulation, even if they don't set it up to always check with the issuer when a stripe only card is presented.
M
Mike Scott
IIRC I don't think anyone actually requested a court order or injuinction. As a matter of course, the experts were expected to observe secrecy about commercial "secrets" to which they had access. The Cambridge people weren't too happy, as it was going to cause them problems with publication of future papers on bank security issues, even material dealing with public domain knowledge. And the UK courts were involved in some way; I believe part of the hearing was in this country.
No? If properly worded, you can gag someone quite effectively: "You are prohibited from disclosing or discussing details of XYZ's systems". A perfect gag, admitting nothing.
M
Mike Scott
True, but the card authorities pretend you can't make a stripe card from a chip card, and thus pretend you have "chip security" at an atm when you haven't. Meanwhile, the PIN is potentially exposed in many, many more places than it used to be.
True, but unlikely for the near future.
M
Mike Scott
Which is scant comfort to those at risk in the meantime.
T
Tim
"john boyle" wrote
In that case, I don't think it's equivalent.
"john boyle" wrote
No problem. You've said enough to answer my question!
"john boyle" wrote
That's where we disagree. I wouldn't expect the insurance docs to be passed to many, many different retailers etc "in the normal course of business". Yet the original bank card *is* passed to many, many different people, all in "the normal course of business". Any of those retailers could have a "bad apple" working for them, who intercepts the details...
"john boyle" wrote
But that use is "as it was intended" - the bank *wants* the customer to pass the card to retailers "in the normal course of business". That's the whole point of the card!
"john boyle" wrote
Great story! Good on that judge.
T
Tim
"john boyle" wrote
;-)
Join the Discussion
Have something to add? Share your thoughts — no account required.
Didn't find your answer?
Ask the community — no account required
Report Content
You are reporting this content to the moderators. They will look at it
ASAP.