Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I really wouldn't be surprised. The security group at my university do a lot of stuff on banking security, and from what I've heard, this was one of the main reasons behind the switch to chip-and-PIN in the UK --- the user is now liable when his card gets stolen and used.


See, for example, Tetris on a ('secure hardware' platform) chip & pin machine[1]

The same group (security research at cambridge) are also the ones who produced the 'chip and pin is a joke'[2] paper you might be referring to.

[1] http://www.lightbluetouchpaper.org/2006/12/24/chip-pin-termi...

[2] http://www.lightbluetouchpaper.org/2010/02/11/chip-and-pin-i...


That's not really true.

The user is liable if the card is stolen, and it is used to conduct fraud using the PIN code.

If the card is stolen, and the fraudster simply uses it online, or via some place that doesn't ask for a PIN, then you are not liable for that fraud.

I'm sure there are rare edge cases, but my experience with Barclays has always been very good in this regard.


The problem is that there is no way of knowing that the criminal even knows the user's PIN, due to flaws in the chip-and-PIN protocol. See http://www.lightbluetouchpaper.org/2010/02/11/chip-and-pin-i...


And, from many years of personal experience, quite a lot of people don't treat their card and PIN securely. This might be in the form of (and these are genuine examples):

1. Writing the PIN on a post-it note and sticking it to the back of the card.

2. Writing the PIN on some paper and keeping it in the same place the card is kept.

3. Giving the card to someone else (partner, kids, relatives, etc.), along with the PIN, to run an errand for them.

4. Saying the PIN out loud as they type it in.

5. Asking the customer assistant/whoever is dealing with the transaction to enter the PIN for them.

Chip&Pin, while claiming to be more secure, enabled and made convenient basic forms of fraud, such as that in points 3 and 5.

I'd actually argue that the shifting of liability from the card issuer/merchant to the card holder/customer in the UK is a direct consequence of C&P allowing careless people to be more lax with the security of their card.


The worst thing is the chip+pin machines that do not have any shield to hide you punching the pin in, and then to just add insult to injury, they're the kind of buttons that you have to forcefully press with all your might to get them to register. So it's blatantly obvious to anyone taking notice which buttons you pressed.


Here's how I do it

Cover the pad with one hand (and maybe your wallet) and type it with the other

You can do it quite naturally. Of course it helps if you type the pin fast as well (by fast I mean not taking 1s per digit)


Richard Clayton (etc) have lots of interesting stuff about bank security (and the lack of) - they've attacked chip and pin, which means that if someone does manage to defraud the card the owner might have some chance of getting the cash back.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: