PIN fraud

Apr 15, 2004 196 Replies

Without a hint of irony, Ronald Raygun astounded uk.finance on 17 Apr 2004 by announcing:

Old wive's tale. PINs have never been stored on the mag stripe (with the exception of Italy and some petrol cards).

No it won't. PINs are transmitted in the clear (with the exception of Germany who will be using encyphered PIN, but no cards have yet been issued).

Without a hint of irony, Ronald Raygun astounded uk.finance on 17 Apr 2004 by announcing:

The UK is using offline PIN for the forseeable future. That is, the connection to the bank will only be used to authorise the transaction where needed - the PIN verification will be performed by the card.

The card generates a cryptogram. The cryptogram contains the information necessary to instruct the terminal to authorise/reject/refer the transaction.

Without a hint of irony, john boyle astounded uk.finance on 17 Apr 2004 by announcing:

No encryption is carried on a mag stripe. The only details carried are card number, expiry date, service code, perhaps issue number & start date details where needed. On Track 1, you also may have the cardholder's name. They don't dial up every time - especially if they are on APACS 30/50 with floor limits & hot card files, and the PIN is held on the chip.

Without a hint of irony, "Tumbleweed" astounded uk.finance on 17 Apr 2004 by announcing:

Cards will block after 3 incorrect attempts. They (and the terminal application) may well also incorporate velocity and transaction count checking to guard against the same card being used multiple times.

Without a hint of irony, john boyle astounded uk.finance on 17 Apr 2004 by announcing:

The 'authoriser' is almost certainly themselves. They are most probably using floor limits; they pick up the liability for any fraudulent transactions below a certain value as long as that card wasn't in the last hot card file they were sent by the bank. Any transactions above the limit are referred online.

Without a hint of irony, "Tumbleweed" astounded uk.finance on 18 Apr 2004 by announcing:

formatting link

Without a hint of irony, Chesney Christ astounded uk.finance on 17 Apr 2004 by announcing:

Is it actually an EMV card? Have you used it to pay for purchases using your PIN? Some non-EMV cards have chips but all they do is hold the same information as the mag stripe.

Without a hint of irony, snipped-for-privacy@tiscali.co.uk (James) astounded uk.finance on 16 Apr 2004 by announcing:

Neither is having a credit/debit card at all.

You have no right to a credit or debit card.

Without a hint of irony, "Tumbleweed" astounded uk.finance on 18 Apr 2004 by announcing:

Because the counter's on the card. Simple, innit?

The PIN isn't on the mag stripe - it's in the chip.

EMV terminals invariably use 32bit processors; encryption is a matter of seconds. Besides, see below.

That's what standards are for. There is an ISO (and an ANSI) standard for mag stripes. There is the EMV standard(s) for chips. DES and 3DES Master/Session and DUKPT are fairly well established, as is RSA.

BTW, SDA cards use no encryption on the PIN. DDA cards will probably use RSA since that's already in use on the card for the other crypto functions.

Without a hint of irony, "Tumbleweed" astounded uk.finance on 17 Apr 2004 by announcing:

Well the privacy shielding's available. Some merchants don't like it though...

Without a hint of irony, "Count Zero" astounded uk.finance on 18 Apr 2004 by announcing:

No, not *this* scheme.

However, the UK banks have decided to stick with online transactions.

You're not supposed to be able to use cards to order stuff by phone or over the internet except if it involves delivering the goods to the cardholder's registered address.

Any trader who relaxes that restriction carries the risk himself. OK, that doesn't worry the thief. Yet. But it makes it likely that, as time goes on, traders will refuse to carry the risk, and therefore refuse to sell on that basis.

Tim said on 19.04.04:

Count Zero was a bit negligent in his description. Only the signature- based card payments can be charged back/bounce, debit payments with PIN are guaranteed.

See the overview at

formatting link

Chris

"Tim" schrieb im Newsbeitrag news:c60dvn$aqg$ snipped-for-privacy@sparta.btinternet.com...

Anyone does not mean you can just step into a bank and get a card. Whenever you open an accound your id is verified.

Let's assume i've bought something in a shop and paid with signiture and then chargeback the money. My bank will then give the shop my address an the shop will then send me a letter and ask me to transfer the money to them. If I don't do so they will sue me. Therefore no one does this normally. Apart from that the shop won't accept my card any longer. If the card was stolen the shop woundn't get its money.

For smaller shops there is an alternative: They may ask me to enter my PIN and check this online. Then no chargeback is possiblen, even if the card was stolen. For this service the bank charge a commission of 0.3%. Therefore the larger shops prefere signiture where no commission is charged.

"Christian Bartsch" schrieb im Newsbeitrag news: snipped-for-privacy@cbartsch.de...

Is there a similar site explaining the UK payment system?

Count Zero said on 19.04.04:

If so, I'd love to hear about!

I had a very hard timing coming by any literature on payments in the UK (a personal interest of mine) and all I found was the CFSP traing material on that subject.

Mind you: Both

formatting link
and
formatting link
are just hobby sites I run on the side, so be sure to read the disclaimers ;-)

Chris

In message , Alex writes

Where were they stored then?

In message , Alex writes

In the past, when ATMs werent online all the time, the Pin was held on the mag strip.

I now know that for sure.

It is called a "Neuraliser" - small red light and then bright flash. Of course it erases the memory of it being used as well as the PIN :-)

"Ronald Raygun" wrote

Rubbish. You are assuming that the purchase is of a *physical item* which needs to be delivered. This is by no means necessarily so!

The thief might be purchasing something that is *downloaded* direct to their PC - eg: software programs; software updates; internet service/web space; documents (eg bought from Companies House!) ....

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required