Cheers,
Ross-c
Cheers,
Ross-c
At 20:31:42 on 18/06/2006, snipped-for-privacy@wmin.ac.uk delighted uk.finance by announcing:
But the point is, would *you* be identifiable from the picture?
At 20:33:21 on 18/06/2006, snipped-for-privacy@wmin.ac.uk delighted uk.finance by announcing:
How secure do you think storing the PIN on the magnetic stripe would be?
It wouldn't store the PIN on the stripe.
You know, I was going to mention that. I seem to recall, a few years ago, someone telling me just that - people with some implausible story trying to get passers by to give them cash to pay for a train ticket they'd just bought with `their` credit card. I guess if you're brazen enough and there isn't a camera around, and the tickets were £10 a shot, you could make some money out of it.
It isn't necessary to store the PIN on the magstripe in order to be able to perform PIN verification. Cash machines have managed this for ages before chipped cards were even planned.
Nothing like as traceable as a car reg plate.
You probably won't see it unless you go over it, in which case a member of staff would have to verify the transaction.
How is this the point? I'm not concerned if I use my card. I'm concerned if someone steals, or clones my card, then uses it to buy stuff charging it to my account. I won't wear a fake beard and glasses because I'm not doing anything dishonest. A criminal using my card or a clone of it is likely to disguise themself as they know that they are breaking the law.
Cheers,
Ross-c
Wait a second, I may have just realised what you are saying. You are saying that if I complained that the card had been used illegally, then it could be shown that it wasn't me because a person other than me would be seen using the card on the video/photo. Is that what you mean?
If that's the case we come back to whether the credit card co. would reverse the charge with no quibbles. Not sure I agree with the optimism of others that it woudl definitely be that easy.
Cheers,
Ross-c
I should have been clearer here. I would prefer that the PIN be asked for, but that this be done by using a chip reader, not the mag-stripe.
The whole setup seems insecure.
Cheers,
Ross-c
True, but I would have thought that someone who steals/clones credit cards would also be prepared to steal/clone car reg plates.
Gareth
At 00:02:13 on 19/06/2006, snipped-for-privacy@wmin.ac.uk delighted uk.finance by announcing:
Exactly. Was it you who performed the transaction? If not, and you were not complicit, what makes you think you're liable?
At 00:04:48 on 19/06/2006, snipped-for-privacy@wmin.ac.uk delighted uk.finance by announcing:
From experience, it is. They're not bothered at the end of the day. If it wasn't an EMV transaction they just reverse the charge and leave it up to the retailer to pursue the payment by other means.
At 23:13:45 on 18/06/2006, Jonathan Bryce delighted uk.finance by announcing:
So what? My primary concern, as the cardholder, is to ensure I'm not out of pocket. Tracing the offender is a secondary matter, of little concern to me, but of more concern to the retailer/bank.
At 22:27:57 on 18/06/2006, Tom Anderson delighted uk.finance by announcing:
Well done.
At 22:54:11 on 18/06/2006, Ronald Raygun delighted uk.finance by announcing:
Cash machines work purely online.
At 00:06:26 on 19/06/2006, snipped-for-privacy@wmin.ac.uk delighted uk.finance by announcing:
But it's Tesco who carry any fraud hit so I shouldn't worry about it.
The point is that your bank is concerned you might be fraudulently disputing transactions which in fact *were* carried out by yourself.
Even though that might be the case now, it hasn't always been. Nor does it mean the PIN is checked online, though it might be.
The point is that magstripe technology allows PIN checking to be done locally, by reference to the card, *without* the PIN in fact being stored on the card.
The way I understand it works (or worked) is that the PIN entered by the user, together with other information on the card stripe, such as account name and number, sort code, etc, is put through a one way encrypting function, the result of which is compared with a "should-be" result stored on the card. This allows match-checking without allowing the PIN to be re-computed.
Moreover, if you changed your PIN, it would store on the card the difference between the new and original PIN, thus making it possible to support PIN-alteration without changing the aforementioned should-be result. All you needed do was subtract the stored difference from the PIN in fact keyed in, to generate the putative original PIN, before plugging this value into the encrypting function.
Have something to add? Share your thoughts — no account required.
Ask the community — no account required