Credit Cards/Chip and Pin/ATM withdrawls

Dec 14, 2005 714 Replies

If a large individual with a large knife follows you out of a shop on a dark evening, where you have used your chip and PIN, and asks you to accompany him to the nearest ATM and, once there, to hand over your card and your PIN, might not *someone* get to know your correct PIN? They would mine..

Will the increased security of chip and PIN, which makes the card worthless without the PIN, encourage a few thieves to go in for this method of generating income, as stealing cards from open shopping bags, or picking pockets for them has become rather pointless (unless they ahve shoulder-srufed the PIN, earlier)?

Me, I would rather have my cards stolen covertly, than overtly..

However, at the moment, so many people seem entirely unconcerned about shielding the pad when entering their PIN that the pickpockets still have a good living to make..

Wrong, because if fraud is being comitted by people inside the system, they may not need a card at all.Same goes for a bug that attributes a withdrawal to someone else, or just invents one.

My God, for the first time ever on usenet, a thread has gone off topic!

other than a crim in the bank, a relative, someone who watches you enter it, someone who uses a card skimming device on an ATM, someone that uses a terminal that records the PIN, a phone system that records the PIN, etc.......

however the cost of contesting the argument is too high for anyone who's time is worth anything.

The "to start with" is pretty relevant, when it's easy enough, with no increased risk to yourself, to simply avoid all of it by having chip+signature.

Jim.

Wrong

They are just as likely to say it was you to start with when they get a forged signature.

So peopel keep asserting, however you're missing other peoples points.

chip+sig gives no less protection to an individual from fraud than chip+pin.

chip+sig is the same as everyone has always used, the risks and methods to minimise those risks are known, nothing new to learn.

The methods to contest fraudalent transactions are well known, indeed a whole range of fraudalent _and erroneous_ transactions become impossible - those involving a PIN.

There's no advantage to an individual in using a PIN, yet there is a cost, rather than continually re-asserting that there's no difference start explaining why individuals should bear the cost.

If the benefits from fraud reduction are so immense, and rely on _everyone_ using chip+pin, give chip+pin users a discount! However until then you need to explain a lot more why individuals should bear the cost without direct benefit to themselves.

As I have said before the majority of fraud costs are not directly felt by an individual, and c+p reduction methods don't need 100% coverage to work.

Jim.

If Chip+PIN is better and safer, why has my local supermarket disabled the PIN terminals and gone back to the old procedure of signing the slip printed by the till?

IT problems. For example,

formatting link

"GSV Three Minds in a Can" wrote

There's nothing perfect about the audit trail of a sig on a bit of paper. And fraudsters using PINs do leave audit trails too.

"GSV Three Minds in a Can" wrote

I find it varies with factors such as type of pen used, whether the paper is slightly "waxy", the height of the till counter (writing with arm horizontal or pointing downwards affects the reporduction) etc etc.

"GSV Three Minds in a Can" wrote

This seems to be a reasonable objection, which could easily be resolved by either two PINs or disabling the ATM function.

It makes the fraud more likely, although I agree that the final effect of any fraud *should* be the same. (i./e. the bank refunding any monies taken by fraud).

Ditto Chip+PIN for the VAST majority of people. Almost everyone who has a debit card has had a PIN for it for as long as they have had the card(s), for use in ATMs.

But a whole range of fraudulent transactions become impossible with a PIN - namely those involving forged signatures.

And those are the more common types of card fraud, which is why Chip+PIN cuts down overall fraud levels.

There is no cost.

What is this "cost" you think exists?

Who ever said they did?

I'm not sure what you point is here.

Presumably because they have had some sort of problem with the system.

It will most certainly not be due to any reduction in safety.

Of course there is, you're obviously very able to learn new skills and have a good memory, not everyone is as blessed as you, they struggle to learn new skills and routines. That is a cost, it may not be a cost to you, but understanding how to enter a pin onto a pad they cannot see as they shield it with their other hand is not trivial for lots of people.

No-one, but I assumed you felt it because of your so vigourous defence that everyone should have one, if you agree that it doesn't need it, then why not understand everyone is not the same as you and they do have reasons to want chip and sig?

Jim.

Palindrome wrote

If you allow her to do that, you're not very street-wise, are you? :-)

I shield the pad, and tap the numbers in so fast I often get them wrong, and try again. This confuses that large woman stood behind me with the knife.

Alex wrote: ...

Nothing; but I don't see why you ask that.

A year ago I had C&S cards that an ATM rejected as 'no PIN'. Today I have C&S cards that the same ATM requests a PIN for. Same transaction type, supposedly the same card type, different result.

Can a C&S card be reprogrammed by EPOS equipment to be C&P? Or is it safe to assume the newer supposed C&S cards were always PIN cards?

"Can't" is a /very/ strong assertion. I'm sure the banks would like their security to be utterly impenetrable, and would even more like us to believe it so. If the banks actually believe it, they are fools; /no/ security system is completely bombproof - all you can do is put the cost of busting it so high it's not worth while bothering. Once organized crime works out that the old methods won't work, they'll turn their attention to the new in a serious way.

...

?????????

Correctly? You mean guaranteed not overlooked by any person or hidden camera; not recorded by a tampered-with terminal? You're /quite/ sure that on /every/ use your number isn't being recorded somehow? If so, please tell us how you are 100% certain!

Tim wrote: ...

Heartily disagree. Example conversation:

customer: "I was with the Prime Minister in London at the time of the transaction; he'll vouch for me. The transaction took place in Edinburgh, so can't have been me."

bank: "Ah, of course we believe the PM; so you must have given someone else your PIN to use. Our systems are foolproof; can you prove you didn't divulge your PIN, accidently or otherwise, at some time?".

Customer: "it wasn't me!" Bank: "Our system security is foolproof, so it must have been you".

Can I point out that in the event of a problem: (a) the bank already has the money; the customer would need to extract a refund from them somehow. (b) banks can afford better lawyers than most people (c) banks have a vested interest in maintaining the aura of security round the C&P system (d) as others have pointed out, it's not a zero-loss game for the customer when complaining. If you complain there's a non-zero chance of a high penalty after being accused of fraud. (This is, of course, not reciprocal for the banks)

Quite. Prove that "C&P is safe" please, someone, and I'll be a happy person.

Readers of a Random Walk in Physics may avoid the use of Proof by Blatant Assertion, if they please!

"Jim Ley" wrote

Perhaps people with C+PIN cards, which are reducing the overall level of fraud, don't want to (indirectly) pay for the increased level of fraud via C+Sig cards?

Well you'll just have to stay unhappy then :-)

Of course it isn't "safe". No system is.

It is "safer" than C&S, which is the biggest single reason for its introduction.

But that still doesn't make it completely safe.

Only for those few people who have not been using PINs for years in ATMs.

But yes, I was not considering the "additional" effort involved in remembering a PIN as being a "cost".

I have NEVER suggested that everyone should have one.

I don't know where you get this idea that I am "vigorously defending" an assertion I have never made.

I think that it is a better option for most people, and will try to persuade people of that, but I've never suggested everyone should have one.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required