Wonga tried to take ~£500 from me today - I've never used it
Discussion
sugerbear said:
And all they can effectively capture is the magstripe data with the PIN which most UK banks will decline unless you have told them you are going on holiday to a certain destination.
The PEd is one of those chip and pin machines, right? I don't think the magstripe goes far enough into the machine to be read, surely? In which case, it's my regular ATM at fault, as that's the only thing that I've used that eats the whole card! Sound about right?wst said:
sugerbear said:
And all they can effectively capture is the magstripe data with the PIN which most UK banks will decline unless you have told them you are going on holiday to a certain destination.
The PEd is one of those chip and pin machines, right? I don't think the magstripe goes far enough into the machine to be read, surely? In which case, it's my regular ATM at fault, as that's the only thing that I've used that eats the whole card! Sound about right?The data on the chip, has and can be easily transmitted to fraudsters.
XDA said:
wst said:
sugerbear said:
And all they can effectively capture is the magstripe data with the PIN which most UK banks will decline unless you have told them you are going on holiday to a certain destination.
The PEd is one of those chip and pin machines, right? I don't think the magstripe goes far enough into the machine to be read, surely? In which case, it's my regular ATM at fault, as that's the only thing that I've used that eats the whole card! Sound about right?The data on the chip, has and can be easily transmitted to fraudsters.
No point in capturing the chip data and transmitting it. The chip data isn't any good by itself as it generates a one time transaction reference. No use during an online sale unless wonga dont capture the card CVC.
The CVC on the chip isn't the same as the CVC on the back of the card. So if they are capturing the chip details then all they have is a cardnumber with an invalid CVC number. And they the CVC on the magstripe is different as well.
So a fraudster would need to photograph the bottom of the card somehow to get the CVC to enable an card not present transaction over the phone or online.
Gassing Station | Speed, Plod & the Law | Top of Page | What's New | My Stuff