Chip & Pin
Author
Discussion

cinque

Original Poster:

833 posts

311 months

Thursday 4th August 2005
quotequote all
Is it correct that all Visa card services are switching to this by mid 2006?

Im not a big fan due to too many pin numbers to remember on other cards & i dont want one pin for all my cards.

Guess its either sign up with AMEX or something else............(which really doesnt help, as visa seems to accepted in much more outlets)!



(and for all the clever sods that say 'its much safer than signing' etc etc, well i dont care, im old fashioned & its the way i like things!!!!)

JagLover

46,763 posts

264 months

Thursday 4th August 2005
quotequote all
I think you will have trouble finding any retailers that will accept a signature rather than a pin.

After all I believe the liability for any card fraud now falls on them.

>> Edited by JagLover on Thursday 4th August 14:37

miniman

30,049 posts

291 months

Thursday 4th August 2005
quotequote all
cinque said:
(and for all the clever sods that say 'its much safer than signing' etc etc, well i dont care, im old fashioned & its the way i like things!!!!)

I don't think it necessarily is safer at all. If someone gets hold of your PIN, then they can go nuts with it as there is no longer a human check of the signature. At least if you have to sign it, then the cashier might have a chance of spotting a forged signature. And as you rightly point out, you either have to have a different PIN for each card, or risk someone with all your cards being able to use all of them with the same number.

One benefit I do see with Chip & PIN is that you don't have to hand the card over to the cashier any more which reduces the chances of it being run through a skimmer.

pdV6

16,442 posts

290 months

Thursday 4th August 2005
quotequote all
miniman said:

I don't think it necessarily is safer at all. If someone gets hold of your PIN, then they can go nuts with it as there is no longer a human check of the signature.

I'm with you there! And the semi-official advice from the banks in response to complaints about having too many numbers to remember is "use one number for all your cards" Nice and safe, then...
miniman said:

One benefit I do see with Chip & PIN is that you don't have to hand the card over to the cashier any more which reduces the chances of it being run through a skimmer.

Yeah - but what's with all the supermarkets having C&P teminals but still taking your card from you and swiping it through the till instead? I'd rather keep hold of my card if that's the way its going to be...

Tank Slapper

7,949 posts

312 months

Thursday 4th August 2005
quotequote all
miniman said:

I don't think it necessarily is safer at all. If someone gets hold of your PIN, then they can go nuts with it as there is no longer a human check of the signature. At least if you have to sign it, then the cashier might have a chance of spotting a forged signature. And as you rightly point out, you either have to have a different PIN for each card, or risk someone with all your cards being able to use all of them with the same number.

One benefit I do see with Chip & PIN is that you don't have to hand the card over to the cashier any more which reduces the chances of it being run through a skimmer.


The reason it is safer is that it drastically reduces the ability of people to skim cards. With the signature system, once the card has been skimmed a blank, or stolen card can be reprogrammed with the stolen data. This is unlikely to be detected by someone checking the signature (and how often do sales assistants check them properly anyway?). In order to do this with the chip and pin system, they would need to replicate the chip itself, which is far more difficult.

pdV6

16,442 posts

290 months

Thursday 4th August 2005
quotequote all
Tank Slapper said:
In order to do this with the chip and pin system, they would need to replicate the chip itself, which is far more difficult.

I don't know any specifics about how C&P cards & chips are implemented, but seeing as you can reprogram the PIN yourself via a cashpoint and POS terminals can check the PIN that you've entered, it must be purely a software issue (i.e. the PIN can be both written & read via the chip's interface).

Can't see it taking too long for skimmers to develop new hardware/software to grab the details and then we're back to square one but without the safety net of a handwritten signature...

Lois

14,706 posts

281 months

Thursday 4th August 2005
quotequote all
From what I have been told through my own work is that there will be no signature fall back available soonish, haven't given specific date so mid 06 sounds likely. Everything will have to be C+P.

Tank Slapper

7,949 posts

312 months

Thursday 4th August 2005
quotequote all
pdV6 said:


I'm with you there! And the semi-official advice from the banks in response to complaints about having too many numbers to remember is "use one number for all your cards" Nice and safe, then...


You are assuming that it is easy for your PIN to be compromised.

With the signature method of authentication, if someone physically steals your card, they have everything they need to make a purchase - they just have to learn your signature. As I said above, if they skim the card or steal the number, they can just use an existing card/signature to charge things to your account.

With Chip & Pin, if someone steals your card they are less likely to be able to use it the more retail outlets switch to this method of authentication.

juice

9,874 posts

311 months

Thursday 4th August 2005
quotequote all
What about tourists, who's cards don't have a chip in them ? (Mine certainly don't) what will happen if you try and pay, will they refuse as you don't have a Chip/PIN ?

r988

7,495 posts

258 months

Thursday 4th August 2005
quotequote all
any system will eventually be cracked, its just a matter of staying ahead as best you can.

pdV6

16,442 posts

290 months

Thursday 4th August 2005
quotequote all
Tank Slapper said:

With Chip & Pin, if someone steals your card they are less likely to be able to use it the more retail outlets switch to this method of authentication.

Yeah, but as I said above, the PIN has to be available via the card's interface, given appropriate hardware and software. Fully expect crims to develop/steal such hw and sw thus breathing new life into the stolen/skimmed card market.

jonnie5

716 posts

282 months

Thursday 4th August 2005
quotequote all
pdV6 said:


I don't know any specifics about how C&P cards & chips are implemented, but seeing as you can reprogram the PIN yourself via a cashpoint and POS terminals can check the PIN that you've entered, it must be purely a software issue (i.e. the PIN can be both written & read via the chip's interface).

Can't see it taking too long for skimmers to develop new hardware/software to grab the details and then we're back to square one but without the safety net of a handwritten signature...


Surely the PIN is stored on the banks computer, not on the card. So maybe the card could be replicated but the 'hardware ID' of the chip is unique I would have thought. Like you, I don't know any specifics about C/P cards but I can't imagine the PIN is stored on the card...

pdV6

16,442 posts

290 months

Thursday 4th August 2005
quotequote all
jonnie5 said:

Surely the PIN is stored on the banks computer, not on the card. So maybe the card could be replicated but the 'hardware ID' of the chip is unique I would have thought. Like you, I don't know any specifics about C/P cards but I can't imagine the PIN is stored on the card...

Hadn't thought of that. Good point.

jonnie5

716 posts

282 months

Thursday 4th August 2005
quotequote all
pdV6 said:

jonnie5 said:

Surely the PIN is stored on the banks computer, not on the card. So maybe the card could be replicated but the 'hardware ID' of the chip is unique I would have thought. Like you, I don't know any specifics about C/P cards but I can't imagine the PIN is stored on the card...


Hadn't thought of that. Good point.


It's OK, it's not like you're a software engineer or something and would have thought this through

Tank Slapper

7,949 posts

312 months

Thursday 4th August 2005
quotequote all
pdV6 said:


Tank Slapper said:
In order to do this with the chip and pin system, they would need to replicate the chip itself, which is far more difficult.



I don't know any specifics about how C&P cards & chips are implemented, but seeing as you can reprogram the PIN yourself via a cashpoint and POS terminals can check the PIN that you've entered, it must be purely a software issue (i.e. the PIN can be both written & read via the chip's interface).

Can't see it taking too long for skimmers to develop new hardware/software to grab the details and then we're back to square one but without the safety net of a handwritten signature...



You may find this interesting. It gives some background on how the system works.

I don't know enough of the specifics to give you a detailed overview myself, but questions like those you have raised have certainly been addressed with this system.


Edited to add: The French have had a similar (though not compatible) system for some time, and the levels of fraud are greatly reduced. It will be interesting to see how much online fraud increases as a result.



>> Edited by Tank Slapper on Thursday 4th August 14:53

pdV6

16,442 posts

290 months

Thursday 4th August 2005
quotequote all
Tank Slapper said:

You may find this interesting. It gives some background on how the system works.

Very interesting.

The bit that worries me is:
that site said:

The basic steps in an EMV chip and PIN transaction are as follows:

1. Power up the chip and negotiate the communications protocol
2. Process the list of EMV payment applications supported by the chip, e.g. credit, debit or purse and giving a choice to the cardholder or asking for their confirmation if appropriate.
3. Select the chosen application and read all the relevant data from the chip.
4. Perform cryptography to validate the chip data.
5. Check the PIN. If not PIN, signature is checked after the EMV element of the transaction is complete.
6. On the basis of floor limits, type of transaction, success of PIN verification, expiry dates, etc. decide whether to approve off-line, go on-line or decline.
7. The chip is then asked whether it would like to override the decision to approve off-line, go on-line or decline.
8. If transaction goes on line, additional EMV chip data is sent to the bank. Part of this is a cryptographic packet that is validated by the issuer. The response from the issuer may also contain a cryptographic packet for validation by the chip. Thus a secure link can be made directly between chip and issuer despite insecure data transmission in between.
9. Part of the response from the bank may contain a script which is processed by the chip, e.g. to disable the chip if it is stolen, unblock the PIN, etc.
10. The chip is asked whether it would like to override the decision to approve or decline the transaction.
11. The EMV element of the transaction is now complete, the chip is powered down and may be removed.
12. If signature verification was required, or if, in the UK, a referral response came back from the bank, these are now processed.
13. At this stage and at the retailer's own risk, they may still approve a transaction which has been declined. There will not be the necessary transaction certificate to put in the settlement file so payment is not secured.

Seems to suggest that the PIN is held on the card - note that the 1st reference to contacting the bank is at step 8 whereas the PIN is verified at step 5.

From this and other information on that site, I guess the whole thing relies on suitably strong encryption of the data on the card. I assume that all hardware and software suppliers to the C&P market must use the same encryption, or else nothing would ever work.

Therefore the entire system is only as secure as the encryption software / keys and frthermore these must be quite readily available in the industry.

Have to say it doesn't entirely fill me with confidence. I guess petty card theft / skimming will decline but "organised" criminals will be working on it...

Mukes

29 posts

258 months

Thursday 4th August 2005
quotequote all
pdv6 - you are correct about encryption. Most Chip and PIN devices have the encryption keys/libraries on board and have to be loaded in a secure environment by accredited manufacturers. Once sealed the devices have to be tamper proof - if someone tries to get at the keys - they are wiped from the device as a result. No system is 100% secure but to crack EMV level 2 devices would require someone with A LOT more technical sophistication than is currently required to duplicate a mag stripe card.

Tank Slapper

7,949 posts

312 months

Thursday 4th August 2005
quotequote all
I think that anti fraud measures can only be a damage limitation excercise. There will always be people prepared to try and circumvent the security so all the banks can do is make it difficult enough to deter the average crook with a little bit of knowhow.

The main standards used are published (www.emvco.com) though there are some card scheme specific variations.

The system does rely quite heavily on encryption, this document (pdf) gives details of how the PIN is handled at the terminal. I don't know how much you know about cryptography, but I can highly recommend Applied Cryptography by Bruce Schneier for a good grounding.

liszt

4,337 posts

299 months

Thursday 4th August 2005
quotequote all
Did a point of sale implementation 2 years ago and we looked at this.

From what I remember the pin is not stored on the card. When you enter the pin it is encrypted and then sent to the bank where it is decrypted and compared.

Mukes

29 posts

258 months

Thursday 4th August 2005
quotequote all
PIN is encrypted on the Chip.