Notices
Non Scooby Related Anything Non-Scooby related

chip and pin system "flawed"

Thread Tools
 
Search this Thread
 
Old Dec 29, 2010 | 06:51 PM
  #1  
Jamo's Avatar
Jamo
Thread Starter
Cooking on Calor
iTrader: (23)
 
Joined: Oct 2001
Posts: 23,346
Likes: 7
From: in a house full of girls!
Default chip and pin system "flawed"

has anyone had a read of this?

http://uk.finance.yahoo.com/news/Ban...478931782.html

and this is the publication. quite an interesting read, im sure the crims with a brain will like it too.

http://www.cl.cam.ac.uk/~osc22/scd/

what are your thoughts on it?
Reply
Old Dec 29, 2010 | 06:55 PM
  #2  
Terminator X's Avatar
Terminator X
Owner of SNet
iTrader: (7)
 
Joined: Oct 2003
Posts: 11,513
Likes: 0
From: Berkshire
Default

Does seem a tad irresponsible to publish albeit no wonder if the card companies have been sat on their ***** since 2009

TX.
Reply
Old Dec 29, 2010 | 07:07 PM
  #3  
AndyC_772's Avatar
AndyC_772
Scooby Regular
iTrader: (2)
 
Joined: Mar 2001
Posts: 9,096
Likes: 0
From: Swilling coffee at my lab bench
Default

There's not really enough information in that article to tell whether the disclosure was responsible or not. Usual etiquette is for someone uncovering a loophole to disclose it to the owner of the system first, to give them a reasonable amount of time to fix it before the information is made public.

It's not clear to me whether this is how the information was published in this case; I suspect that if it's a student's thesis then probably not - and that's where the complaint has come from.

He does say that the "no pin" software isn't available - and the device does look a bit clunky to covertly use when buying stuff...
Reply
Old Dec 29, 2010 | 07:23 PM
  #5  
Simon C's Avatar
Simon C
Scooby Regular
 
Joined: Sep 2003
Posts: 8,677
Likes: 0
From: At the diesel pump...
Default

Its pish easy to get round chip and pin if you know where to look.
Reply
Old Dec 29, 2010 | 07:27 PM
  #6  
PaulC72's Avatar
PaulC72
Scooby Regular
 
Joined: Sep 2006
Posts: 5,108
Likes: 0
From: RIP Tam.
Default

TBH I always thought the C&P thing was a little bit of waste of time it is as flawed as the signature strip as pins are too easy to see people enter and in some countries they don't use them so it makes them useless.

Really what is needed is a photograph of the card hold put onto the card and the system then linked up to the passprot system so the pics can be matched, this would probably cost too much but what is the cost of the current card frauds....
Reply
Old Dec 29, 2010 | 07:44 PM
  #7  
ALi-B's Avatar
ALi-B
Moderator
20 Year Member
Liked
iTrader: (1)
 
Joined: Apr 2002
Posts: 38,078
Likes: 310
From: The hell where youth and laughter go
Default

Originally Posted by Simon C
Its pish easy to get round chip and pin if you know where to look.

Just press the "customer not present" button on the machine
Reply

Trending Topics

Old Dec 29, 2010 | 07:46 PM
  #8  
ALi-B's Avatar
ALi-B
Moderator
20 Year Member
Liked
iTrader: (1)
 
Joined: Apr 2002
Posts: 38,078
Likes: 310
From: The hell where youth and laughter go
Default

Originally Posted by PaulC72

Really what is needed is a photograph of the card hold put onto the card and the system then linked up to the passprot system so the pics can be matched, this would probably cost too much but what is the cost of the current card frauds....
Lloyds used to offer to print your photograph on their Gold cards at one point. Stupid thing was, on certain transactions, people still asked for your passport as ID...even though the credit card clearly had your photograph printed on it!

Last edited by ALi-B; Dec 29, 2010 at 07:47 PM.
Reply
Old Dec 29, 2010 | 09:00 PM
  #9  
scud8's Avatar
scud8
Scooby Regular
iTrader: (1)
 
Joined: Feb 2001
Posts: 1,204
Likes: 0
Default

The reason the banks want the information suppressed is that if money is taken from your account and their records say the PIN was used the burden of proof is on you to prove that you have taken reasonable care not to disclose it. If this loophole gets widely known then it will shift the burden back to them.

I gather Barclays was the only bank to fix the problem promptly. I'm assuming the others don't care because it won't be them losing money.
Reply
Old Dec 29, 2010 | 09:43 PM
  #10  
mart360's Avatar
mart360
Scooby Regular
 
Joined: Jul 2005
Posts: 12,329
Likes: 0
Default

I posted similar about 2 years ago, when my wife had her handbag lifted,

they hit three cards, withdrew cash & tried to buy loads of stuff.

Her CC card company's were on the ball, and blocked the cards / detected

fraud within two small transactions.

Her bank on the other hand were useless, and refused to play ball, stating

that because the pin number was used, the transactions were valid/

authorised, and that she had been negligent and allowed her pin to be

compromised / known (left with the cards)

We pointed them to the articles posted re the failings of chip & pin, (Re failed data comms between

merchant payment authoriser , & interception of and modification of data sent) , which is incidentally

referred to in the article and asked them to prove that my other half was negligent.

They decided to refund the losses as a gesture of goodwill.

Mart

Last edited by mart360; Dec 29, 2010 at 09:49 PM.
Reply
Old Dec 29, 2010 | 10:36 PM
  #11  
Terminator X's Avatar
Terminator X
Owner of SNet
iTrader: (7)
 
Joined: Oct 2003
Posts: 11,513
Likes: 0
From: Berkshire
Default

Originally Posted by PaulC72
Really what is needed is a photograph of the card hold put onto the card and the system then linked up to the passprot system so the pics can be matched, this would probably cost too much but what is the cost of the current card frauds....
They tried pics on cards ... when they were testing it, some people had pics of animals on their card & the shop staff were still letting them buy stuff! Not that useful needless to say.

TX.

PS

Mart, just as well you knew the score as you'd have been screwed otherwise

Last edited by Terminator X; Dec 29, 2010 at 10:37 PM.
Reply
Old Dec 30, 2010 | 12:23 AM
  #12  
Adrian F's Avatar
Adrian F
Scooby Regular
 
Joined: Nov 2001
Posts: 2,122
Likes: 0
Default

Terminator X as said above main reason to move to chip and pin was to move the responsibility back to the individual and away from the bank/retailer.

Now days in a lot of shops the retailer doesn't even touch the card you put it in the machine and take it out so printing anything on it is a waste of time.
Reply
Old Dec 30, 2010 | 06:29 PM
  #13  
PaulC72's Avatar
PaulC72
Scooby Regular
 
Joined: Sep 2006
Posts: 5,108
Likes: 0
From: RIP Tam.
Default

I suggested that the pictures were on the eletronic part not actually on the cards so the image was digital and linked to the passport system where the images could be cross checked...although the main flaw being not everyone has a passport lol...
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Mattybr5@MB Developments
Full Cars Breaking For Spares
28
Dec 28, 2015 11:07 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
12
Nov 18, 2015 07:03 AM
Ganz1983
Subaru
5
Oct 2, 2015 09:22 AM
sedge69
Wanted
0
Oct 1, 2015 09:44 PM
InTurbo
ScoobyNet General
21
Sep 30, 2015 08:59 PM




All times are GMT +1. The time now is 08:39 PM.