Credit card fraud and Shell petrol stations
Discussion
hornetrider said:
How does this work? If they have the chip and pin thing on the desk - how can they scan your card? Is it wired up to some kind of reader under the desk?
im interested in this too as i always cover my pin with my other hand plus how do they find out the security code on the back ?J
They only need to capture your pin for planned dodgy transactions authorisd in the UK, most other nations card auth systems will accept a card without a pin... so chip n pin has in no way whatsoever improved security. it was an attempt for the banks to push responsibilty for fraud onto the consumer, and has failed as they left so many holes, and unless implemented globally.
I think the only way this can be dealt with are rolling card numbers like RSA tokens.
Your card number is only valid for auth for an hour and has a printed number on the card of 8 characters, and another 8 rolling on the car or on another device.
I think the only way this can be dealt with are rolling card numbers like RSA tokens.
Your card number is only valid for auth for an hour and has a printed number on the card of 8 characters, and another 8 rolling on the car or on another device.
The only shell station local to me got a few people one of which was my girlfriends mum, found out when the bank rang her to ask if she had been on a trip to somewhere in asia only to be told she doesnt even have a passport, she's never had a passport!!
Ive heard that some places that do it the chip and pin machine stores all the card details on it or something like that.
Ive heard that some places that do it the chip and pin machine stores all the card details on it or something like that.
Oh btw , the new trick is completly hacking the chip and pin machine . In the past few weeks some of the macdonadls kfc and burger kings that had the chip and pin machine have been stolen on order . So what they do , re-program the stolen machines and put them in a petrol garage or somewhere similar. Obviously the cashier knows about this but its imposible to tell if its been messed around with or not .
Makes me laugh as it was meant to be the safest way to make transactions and the banks are trying to cover the severity .
Also the new passports have been cracked , you can have a new identity within minutes ( this was done by a security firm )to prove how unsafe they are
Makes me laugh as it was meant to be the safest way to make transactions and the banks are trying to cover the severity .
Also the new passports have been cracked , you can have a new identity within minutes ( this was done by a security firm )to prove how unsafe they are
Edited by mike_1985 on Wednesday 20th August 08:07
The reason this chip and pin fraud has been mainly occurring at Shell petrol stations is their choice of Chip and Pin Entry Device (PED).
They use a Trintec PED (Pin Entry Device) that is known as a Park and Swipe device - this means the magnetic stripe on the card is swiped every time you put it in the machine even though it isn't needed for a chip and pin transaction - you may have noticed that when you put your card in the black PED at a Shell station it disappears completely into it and it is swiped by the MCR (magnetic card reader) enclosed in the PED. The fraudsters modify the Trintec PED to record the swipe data from your card and also record the pin number as you enter it. Your magnetic data is then written onto a blank card (very easy) and used abroad where Chip and Pin is not used or where the UK version of Chip and Pin is not compatible with their version.
Any Chip and Pin PED where the card is left sticking out when you use it is much safer, as these will have a separate MCR on the side, or there will be a separate by th till MCR. So to get your magnetic card data it has to be swiped manually by the operator.
Chip and Pin devices are meant to meet certain security standards (tested by GCHQ) and are supposed to be tamper proof, but to save money the banks have allowed a lower standard that these devices can meet yet still be used (a bit like TV manufacturers calling TVs HD Ready - suggesting they meet the HD standard when really they are compatible with HD).
So the banks have cleverly pushed responsibility for fraud onto the consumer and the retailers as they are no longer have to automatically pay out for Chip and Pin fraud, but a study by one of the universities has even shown that even the Chip and Pin reader nevermind the MCR in some PED devices can be tampered with due to this lower standard, but it takes a bit of work.
The banks claim Chip and Pin is ultra secure, and therefore if you get "done" they will try and accuse you of giving your Pin number to someone and you will have to jump through hoops to get them to pay out!!! This is obviously not true.
Scary but this is how the world seems to work these days.
They use a Trintec PED (Pin Entry Device) that is known as a Park and Swipe device - this means the magnetic stripe on the card is swiped every time you put it in the machine even though it isn't needed for a chip and pin transaction - you may have noticed that when you put your card in the black PED at a Shell station it disappears completely into it and it is swiped by the MCR (magnetic card reader) enclosed in the PED. The fraudsters modify the Trintec PED to record the swipe data from your card and also record the pin number as you enter it. Your magnetic data is then written onto a blank card (very easy) and used abroad where Chip and Pin is not used or where the UK version of Chip and Pin is not compatible with their version.
Any Chip and Pin PED where the card is left sticking out when you use it is much safer, as these will have a separate MCR on the side, or there will be a separate by th till MCR. So to get your magnetic card data it has to be swiped manually by the operator.
Chip and Pin devices are meant to meet certain security standards (tested by GCHQ) and are supposed to be tamper proof, but to save money the banks have allowed a lower standard that these devices can meet yet still be used (a bit like TV manufacturers calling TVs HD Ready - suggesting they meet the HD standard when really they are compatible with HD).
So the banks have cleverly pushed responsibility for fraud onto the consumer and the retailers as they are no longer have to automatically pay out for Chip and Pin fraud, but a study by one of the universities has even shown that even the Chip and Pin reader nevermind the MCR in some PED devices can be tampered with due to this lower standard, but it takes a bit of work.
The banks claim Chip and Pin is ultra secure, and therefore if you get "done" they will try and accuse you of giving your Pin number to someone and you will have to jump through hoops to get them to pay out!!! This is obviously not true.
Scary but this is how the world seems to work these days.

Edited by Emeye on Wednesday 20th August 08:44
Gassing Station | The Pie & Piston Archive | Top of Page | What's New | My Stuff




.