Slashdot Mirror


Judge Allows Small Businesses To Sue Credit Card Giants For Forcing Them To Adopt Chip Readers (computerworld.com)

An anonymous reader quotes a report from Computerworld: A federal judge has ruled it is plausible that four national credit-card companies improperly conspired "in lockstep" to set a deadline of Oct. 1, 2015 for requiring retailers to upgrade their technology to accept embedded chip cards for credit and debit card purchases. In an order issued Friday (Case number C 16-01150 WHA), U.S. District Court Judge William Alsup agreed with two small Florida businesses -- B and R Supermarket and Grove Liquors -- which brought the lawsuit in March. Alsup's ruling also allows the antitrust case against Visa, Mastercard, American Express and Discover Financial Services to move forward in federal court for the Northern District of California. The two retailers are seeking to create a class-action case involving millions of small retailers who have been required under the Oct. 1, 2015 deadline to assume liability for fraudulent card charges if they haven't upgraded to the more-secure chip card technology instead of magnetic-stripe cards. The retailers believe there was industry conspiracy over creation of the deadline that violates fair trade practices. In the same ruling, the judge allowed two other retailers -- Los Angeles-based gourmet food chain Monsieur Marcel and New York-based grocery story chain Fine Fare -- to intervene in the case. Lawyers for the retailers have said a class-action lawsuit could include 8 million U.S. small businesses. They would seek repayment of the cost of upgrading to chip card readers and related software, estimated at $6 billion. However, the National Retail Federation has recently estimated the total cost of the conversion in the U.S. at up to $35 billion.

311 comments

  1. Down the rabbit hole by mattyj · · Score: 1, Interesting

    The processing of nearly every credit card purchase in the US eventually trickles down to one firm, so perhaps it wasn't the 'big four' conspiring.

    I'm not really sure why them setting the same date for themselves affects anyone. Just upgrade your damn terminal already.

    1. Re:Down the rabbit hole by m0hawk · · Score: 2

      Any idea on who pays for the terminal upgrade, it wasn't mentioned in the article? If it is being forced on a business, then the credit card company should be sending them out free of charge (assuming that the terminal will be paid off with transaction fees). I'm guessing this is not the case.

      Otherwise, why is there are problem rolling out new terminals?

    2. Re:Down the rabbit hole by ragnar_ianal · · Score: 1, Informative

      It makes sense to impose some or all of the cost on the retailer because the retailer controls the number of terminals involved. If a retailer wants a greater number of secure transaction points it makes sense that the retailer pay for this business decision.

    3. Re:Down the rabbit hole by EvilSS · · Score: 5, Informative

      Just upgrade your damn terminal already.

      Many of them did. The problem is that the new terminals then need to be certified by each card company before they can be turned on, for each business (not just a hardware certification for the mfg, each deployment requires certification). The card companies have been dragging their feet getting them certified, particularly for small to mid sized businesses. However they did not extend the deadline for those companies that installed the terminals but can't yet use them. So these businesses did what they were supposed to do but they are in a bind now with liability shifted to them but they are unable to even accept chip cards because they can't get the big 4 to certify their installations.

      This happened to my local grocery chain. They have the new readers, had them well before the deadline, but they can't use them, even now almost a year after the deadline passed, because they are still in the queue for certification.

      --
      I browse on +1 so AC's need not respond, I won't see it.
    4. Re:Down the rabbit hole by ShanghaiBill · · Score: 4, Insightful

      Any idea on who pays for the terminal upgrade, it wasn't mentioned in the article?

      The terminal is owned by the merchant, so they pay for it.

      If it is being forced on a business, then the credit card company should be sending them out free of charge

      It isn't being forced on them. They have the alternative of not accepting CC transactions, which is something many businesses do. At some point we need to have progress, and magstripes need to die. Many technical standards have deadlines where old features stop being supported.

      The merchants have had plenty of time to upgrade, and plenty of warning that the end was coming. Most merchants support the change, since it is the merchants that pay the biggest price for fraud. That is why the plaintiffs are having problems organizing a class action. It is only a few whiners that are complaining.

    5. Re:Down the rabbit hole by taustin · · Score: 5, Informative

      It isn't being forced on them. They have the alternative of not accepting CC transactions, which is something many businesses do.

      They also have the choice continuing to use the old equipment, but they then accept responsibility for fraudulent transactions that could have been prevented by using chip cards. Hell, as far as I know, they still have the option of imprinting paper slips and depositing them at the bank like checks, but the costs all end up on the merchant, as they should.

      At some point we need to have progress, and magstripes need to die. Many technical standards have deadlines where old features stop being supported.

      Mag stripes will be around for at least a decade, and probably two or three. But they'll be slowly phased out over the next few years for most people most of the time.

      The merchants have had plenty of time to upgrade,

      Sort of, but not really. Unless you're Walmart or Home Depot, you don't write your own processing software, you rely on your point of sale vendor, and very few point of sale vendors were ready by October of last year. Many small businesses simply did not have the option to start doing EMV by the deadline.

      and plenty of warning that the end was coming. Most merchants support the change, since it is the merchants that pay the biggest price for fraud. That is why the plaintiffs are having problems organizing a class action. It is only a few whiners that are complaining.

      Liability issues aside, any merchant complaining about EMV (with point of point encryption) is an idiot. EMV isn't about protecting consumers from fraud against their card (hence the chip & signature instead of chip & PIN), it's about protecting banks and merchant services from idiotic merchants who can't keep their network secure. Implement EMV with P2P encryption, and the merchant never sees the card in at all, and if someone breaks into their network, there's nothing to steal. Makes PCI compliance easier, and pretty much eliminates the chance of the merchant having to pay six figures to investigate a breach.

    6. Re:Down the rabbit hole by taustin · · Score: 1

      You're smoking dope, and they're feeding you a line. The software has to be certified, but even then, not by deployment. And for a small business, that's handled by the point of sale vendor, not the merchant. If your local grocery chain is doing their own processing software, they're not pushing on getting their stuff certified, and that's entirely on them.

      There is a point about not extending the deadline - again - for those merchants who had the hardware but couldn't get the software from the POS vendors, but it's a small point unless the business is so poorly run that it gets a lot of fraudulent activity to begin with.

    7. Re:Down the rabbit hole by peragrin · · Score: 4, Interesting

      Ah but that is half the issue. Chip readers once installed needed to be certified by the card companies. That certification. Is on average 12 months behind.

      So you see a terminal but do not use sticker? The software stack, connections, etc haven't been certified to use chips.

      Credit card companies failed to provide enough certifiers, and enough time to begin the change over. It has been mentioned by MasterCard executives that they never once talked about processing speed of the transactions, which is why Chip readers, take 30% longer to process after sending your card data.

      MasterCard Visa cared about their bottom line, and pushed responsibility to merchants, but didn't provide the tools for merchants to do it right.

      Lastly an October 1st deadline is irresponsible, as the slightest hiccup destroys holiday shopping, which is what happened last year. A Feb 1st deadline with a 6-12 month soft start 50% of fraud is paid both issues, and merchant would have been more successful,and less lawsuit prone.

      --
      i thought once I was found, but it was only a dream.
    8. Re:Down the rabbit hole by TigerTime · · Score: 1

      Additionally, they can keep using the magstripe, they just have to take full responsibility for and false charges that may occur at the business as opposed to the credit card company taking that liability. So really, the merchants only have to upgrade if they want to accept CC and be free of any credit card fraud liability. Seems reasonable to me.

    9. Re: Down the rabbit hole by rickb928 · · Score: 3, Interesting

      Terminal hardware is certified before they are shipped.

      Software is updated, and verified before deployment.

      Nobody ships untested terminals. That's disastrous.

      --
      deleting the extra space after periods so i can stay relevant, yeah.
    10. Re:Down the rabbit hole by youngone · · Score: 3, Informative
      I'm not in the US, but where I live the merchant pays for the terminal. There are several suppliers and we have had chip and pin type cards for maybe 5 years.

      I can't remember the last time I saw a mag stripe machine, and if I did see one, I would pay cash.

    11. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      The processing of nearly every credit card purchase in the US eventually trickles down to one firm, so perhaps it wasn't the 'big four' conspiring.

      I'm not really sure why them setting the same date for themselves affects anyone. Just upgrade your damn terminal already.

      Good point, merchant services providers straddle all the card associations and there isn't such a thing as just a Visa POS terminal.

      Say they did stagger the rollout dates somehow. It's still going to happen, so what were these businesses hoping to do, scurry over to Discover or Amex and stop taking Visa/MC until well.. eventually all four of them would push EMV, there's no doubt.

    12. Re:Down the rabbit hole by Anonymous Coward · · Score: 1

      Failed to provide enough certifiers my ass. This is n't new. The reason everyone is behind is because businesses waited till the very last second to even start looking at the issue.

      I deal with this crap daily. It's a hassle to do the change, but so what, you have had years of notice and you along with everyone else waited until the cutoff date to implement or thinking about implementing. How the hell is that the credit card processors fault.

    13. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      "Just upgrade your damn terminal already."

      I doubt you would be so quick to say that if YOU were the small business owner having to pay $2,200 plus for EACH new terminal on top of interchange fees, monthly fees, fraud prevention fees, etc.

    14. Re:Down the rabbit hole by jrumney · · Score: 1

      This is one instance when conspiring is good for the market. If they didn't conspire, small retailers would be buying four different card readers instead of one, and they'd have four different deadlines to remember instead of one. A market getting together and deciding on standards are not really in the same league as price-fixing and other types of conspiracy that adversely affect consumers.

    15. Re:Down the rabbit hole by jrumney · · Score: 2

      If it doesn't make business sense, don't take credit cards. If you decide it is worthwhile for your business to take credit cards, then shell out for the equipment, and be prepared to update it every 10-20 years. Do you ask the central bank to supply you a cash register free of charge?

    16. Re:Down the rabbit hole by DRJlaw · · Score: 3, Informative

      You're smoking dope, and they're feeding you a line. The software has to be certified, but even then, not by deployment. And for a small business, that's handled by the point of sale vendor, not the merchant.

      Now explain why the POS vendors are losing revenue due to certification delays. Is is your theory that they're tanking their business to support the line? Or selling the dope? My theory is that you simply don't understand that level 3 certification is literally by deployment and too self-satisfied to consider that you might be wrong.

    17. Re:Down the rabbit hole by ShanghaiBill · · Score: 1

      Lastly an October 1st deadline is irresponsible, as the slightest hiccup destroys holiday shopping

      The obvious solution for a merchant is to upgrade before the deadline. The deadline is the last day to upgrade. Any merchant that waits until then to start the process deserves what they get.

    18. Re: Down the rabbit hole by dfeifer · · Score: 1

      Not necessarily. We have 3 were I work and they are actually owned by pnc bank.

    19. Re:Down the rabbit hole by plover · · Score: 1

      Any idea on who pays for the terminal upgrade, it wasn't mentioned in the article?

      The merchant pays for the terminal, but the upgrade is not being "forced" on them. If they don't want to upgrade to a secure terminal, they don't have to, but then they take on the risks of the customers' cards being stolen and misused.

      So if they think their shitty ancient card readers are secure from hacking, and they're willing to bet the cost of fraud that they're so great, they can keep them. Seems fair.

      --
      John
    20. Re:Down the rabbit hole by jittles · · Score: 5, Interesting

      Just upgrade your damn terminal already.

      Many of them did. The problem is that the new terminals then need to be certified by each card company before they can be turned on, for each business (not just a hardware certification for the mfg, each deployment requires certification).

      That is untrue. You do NOT have to certify each deployment with the card companies. You have to certify the terminal hardware, the kernel on the hardware (card brand specific), the communication from the card terminal to the gateway, and the communication from the gateway to the processor. The processor has to certify from them to the card brand. Most gateways are offering certified hardware + software deployments that only require you to certify with the processor if you develop against their software. If you just take a package that is already certified, you have to do nothing other than meet your PCI requirements that you're already obligated to do. I spend my life writing card terminal drivers and everything I do has to be certified from the terminal to the payment gateway. This is my every day life. You would only need to certify if you made your own software implementation somewhere in that chain. If you write software below the gateway then you may not even need to certify with the card brand, you may be able to just certify with the gateway, depending on what exactly you did.

      The card companies have been dragging their feet getting them certified, particularly for small to mid sized businesses. However they did not extend the deadline for those companies that installed the terminals but can't yet use them. So these businesses did what they were supposed to do but they are in a bind now with liability shifted to them but they are unable to even accept chip cards because they can't get the big 4 to certify their installations. This happened to my local grocery chain. They have the new readers, had them well before the deadline, but they can't use them, even now almost a year after the deadline passed, because they are still in the queue for certification.

      Which chain is this? Publix, for instance, chose to write their own card terminal application which requires all kinds of certifications with the card brands, terminal manufacturers, etc. That's a time consuming process. But I've personally had such a project go through certification in a matter of weeks. It's not the card brands holding things up.

    21. Re:Down the rabbit hole by Anonymous Coward · · Score: 4, Interesting

      In many cases (our stores, for example) the hardware was not available (from our credit card processor).

      We got our first chip capable machine in January -and it did not work. I plugged it in, ran a transaction, and got an error. After a couple of software updates -nope still not working with chip cards. Swap the hardware -still not working. Swap the hardware again -finally everything works. Hey look, it's February, 2016!

      We were charged extra fees from October thru February for not having compliant hardware in place. Hardware which was not available -according to the company charging us the extra fees for not having it yet.

      Who paid for the equipment? We did. We paid the credit card processor the amount they chose to charge us for the equipment that they said we had to have in order to do business.

      I think the upgrades were worth doing, but the rollout was handled poorly, and the companies responsible for setting the timeline profited off of the merchants inability to meet the deadline.

    22. Re:Down the rabbit hole by drinkypoo · · Score: 1

      So if they think their shitty ancient card readers are secure from hacking, and they're willing to bet the cost of fraud that they're so great, they can keep them. Seems fair.

      The problem is that the shitty new card readers aren't secure either, because here in the USA we are chip and sign and not chip and PIN. All the same attacks against a stolen card will still work.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    23. Re:Down the rabbit hole by Anonymous Coward · · Score: 1

      Did you ever notice that a lot of the "certified" chip reading terminals have an exposed USB port on them. Makes me think they forgot about physical security during the certification process. I wonder how long until someone figures out how to use those USB ports as an entry way to the whole processing system. It's going to be interesting, especially if a large well organized group figures out how to take over the terminals.

    24. Re: Down the rabbit hole by Anonymous Coward · · Score: 0

      It doesn't matter. This is another Capitalistic quagmire caused by unreasonable and maybe ill-educated judges reading more into this than what would be reasonable. They need to get off their asses and get the job done. Get 'er done already, dammit!

    25. Re: Down the rabbit hole by Anonymous Coward · · Score: 0

      Physical stolen credit cards are rare to the point of being not an issue. Cardless transactions are subject to anti fraud detection analysis. With mag stripe you can be sure that the card wasn't cloned. Cloned cards where someone makes a fake credit card with you number encoded onto it are actually a bigger problem than physical stolen cards. People have a variety of ways of getting your card number.

    26. Re: Down the rabbit hole by drinkypoo · · Score: 1

      Physical stolen credit cards are rare to the point of being not an issue.

      I wouldn't call 14% of all credit card fraud "not an issue".

      With mag stripe you can be sure that the card wasn't cloned.

      What? Who told you that?

      Cloned cards where someone makes a fake credit card with you number encoded onto it are actually a bigger problem than physical stolen cards.

      Yeah, and EMV actually has inadequate protection against cloning, because it has inadequate standards for the use of the chip, and "some EMV implementers have merely used counters, timestamps or home-grown algorithms to supply" the nonce for the transaction. That does require a compromised reader, but you don't have to compromise the reader itself, only its communications channel. This can often be done from outside a building.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    27. Re:Down the rabbit hole by larryjoe · · Score: 2

      It isn't being forced on them. They have the alternative of not accepting CC transactions, which is something many businesses do.

      They also have the choice continuing to use the old equipment, but they then accept responsibility for fraudulent transactions that could have been prevented by using chip cards. Hell, as far as I know, they still have the option of imprinting paper slips and depositing them at the bank like checks, but the costs all end up on the merchant, as they should.

      At some point we need to have progress, and magstripes need to die. Many technical standards have deadlines where old features stop being supported.

      All of this is true and still tangential to the anti-trust case. Anti-trust collusion that forces actions that are in the interests of society are still illegal. The ends do not justify the means. The key point is that the change was indeed forced upon the retailers because they were denied the right to choose a competing supplier, a right that was illegally removed through collusion.

    28. Re:Down the rabbit hole by plover · · Score: 3, Insightful

      The problem is that the shitty new card readers aren't secure either, because here in the USA we are chip and sign and not chip and PIN. All the same attacks against a stolen card will still work.

      Federal law caps your liability at $50, but under the current PCI liability rules if your chip card is stolen and misused your bank is 100% liable for the fraud, because they could have put a PIN on the card but didn't. Neither you nor the retailer is responsible for a dime of the loss.

      The chip has all the anti-skimming technology, regardless of whether it requires PIN or signature authentication, and both are equally excellent at preventing cloning full card data.

      What all cards (both chip and mag stripe) still suffer from is the ability to steal the PAN and use it for online fraud. Mag stripes have the worst security, and are almost as easy to clone as pushing the green button on a copier machine. Europe's experience has proven that the effect of chips was to move the fraud online. But eliminating mag stripes is the next step in securing credit. None of the other measures can have much of a beneficial effect on security until that weakest link is removed.

      And if chip and signature bothers you that much, nothing is stopping you for applying for a MasterCard from a bank that requires PIN authentication. Your current bank may not offer one, but some of the major retail banks do. Take action instead of whining.

      --
      John
    29. Re: Down the rabbit hole by Anonymous Coward · · Score: 0

      Oops I mean aight magstripe you cannot be sure that its not a cloned card.

    30. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      If your business’ payment-system implementation is relatively simple with few or no customizations, then most of the Level 3 certification may not apply to your business. This includes simple implementations like single terminals, as well as specific, pre-made software packages that are certified to handle EMV transactions without heavy customization.

      So for small places there is no onsite certification.. For some larger, and especially for the ones that do customizations there is a requirement for the site-certification.

      If you run a larger business that uses a customized processing setup, then you may have to play a more active role in your business’ Level 3 certification.

      If your business falls into this group, you should talk to your payment processor, ISV and acquirer for guidance. They will be more than happy to offer advice on what you’ll need to complete certification.

      and

      Again, depending on the degree of customization and complexity of your payment system, the timeframe for completing Level 3 certification can be as little as two weeks or as long as eight months.

      In order to accelerate your business’ certification, work with your ISV to make sure that your customized software is ready for testing before you start the testing process.

      So the ones that requires certification can take some time, and usually the larger the place the longer the certification-process..
      They even mention 8 months on that page.. And from experience in different certification processes (i have experience in a different area than payment systems) is that if you don't book your timeslot for doing the certification in time, or when demand for it goes up, those estimated times will shoot up quite quickly.. The other way to make sure the certification process takes way longer than needed is *not* having a dedicated person for jumping through all the hoops and having a fast turnaround to all questions from the certifier..

    31. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      That sounds like a quite high price. Where i live the price for a terminal was about $1000 less around 5-8 years ago.. for the transaction-fees i know they have some minimal type of account (talking less than $100 per month in fixed fees) and then a 2% charge for all transactions..

      But still.. $2200 as a cost for something that will be used for the next 10 years that will remove the local management of cash and reducing the risk of robberies.

      $220 per year.. or $18 per month.. would still consider that as a minimal expense for the hardware.. Even with the $100 + 2% it would still be lower than the cost of having the bank do cash-pickups and the increased risk (insurance cost) of robberies when having loads of cash on the premise.

    32. Re: Down the rabbit hole by Chrontius · · Score: 1

      Yeah, and EMV actually has inadequate protection against cloning, because it has inadequate standards for the use of the chip [arxiv.org], and “some EMV implementers have merely used counters, timestamps or home-grown algorithms to supply” the nonce for the transaction. That does require a compromised reader, but you don’t have to compromise the reader itself, only its communications channel. This can often be done from outside a building.

      And if you don’t trust your logistics chain - PS, you shouldn’t - you might crack open a terminal and find a burner cellphone inside that’s MitMing every single credit card transaction.

      It’s not a new thing, Schneier wrote this in 2010.

      With an electronic sticker, you can intercept the command from the EMV card saying the PIN is wrong, and re-write the acceptance command. Alas, the PIN confirmation isn’t encrypted.

      Another good walkthrough of what’s become known as a “wedge attack”.

    33. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      Do your homework.

      In the state of Floridia, unless the merchant is part of a large corporation and can afford their own credit card processing department they do not own the terminals. The terminals are leased, usually with a package deal about processing transactions. Small businesses are charged for every kind of card transaction including debit card.

      The chip terminals are more expensive and processing comes at a higher rate. And to top on that chip cards will deny use of the swipe on certain terminals, not just old ones. This means that those new debits cards will be unable to shop at local merchant stores. It's not just credit cards.

      For every transaction on a card with a Visa or MasterCard or whatever those companies get a cut of the transaction cost. They own the technology from the card to the processing. And flooding the market with a card that forces small merchants to pay higher costs and then blocking alternatives is a real problem for your progress there.

    34. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      If that were the case then strip and PIN would be as safe as chip and PIN.
      The difference is that the chip is supposedly harder to copy.
      With a strip it is fairly trivial to modify a card reader to store a copy of the card when the victim eats at a sketchy establishment and with a camera in the right place they have your PIN.

      The PIN is there to prevent a thief from using a stolen card. The chip is there to prevent unauthorized copies of the card.
      A criminal can still grab the numbers from the card and buy something online, but to benefit from that they have to put a delivery address in somewhere.

    35. Re:Down the rabbit hole by davester666 · · Score: 1

      Actually, most/many of them have. But the problem is, that the 'big four' ALSO require that each retailers system be certified/test to be compliant with whatever protocol in order to transfer liability off the retailer to the bank/credit card company. And, for some reason, many of these companies can't even get a date from the big four as to when they MIGHT be able to start the process of being certified compliant. In the meantime, the retailer is responsible for all fraud...

      --
      Sleep your way to a whiter smile...date a dentist!
    36. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      I'm not in the US, but where I live the merchant pays for the terminal. There are several suppliers and we have had chip and pin type cards for maybe 5 years.

      I can't remember the last time I saw a mag stripe machine, and if I did see one, I would pay cash.

      I travel a lot for work and the only "first world" countries I've seen that still use mag stripes are the US and Japan.

    37. Re:Down the rabbit hole by dwillden · · Score: 1

      Yet most merchants waited until the last second to install the readers. So who was at fault for the delays? I saw some proactive merchants install chip capable readers in 2014, but most stuck with swipe only readers until just before the deadline, then rushed to install all the new readers. Had they not all waited until the last second there would not have been such a back-up. Plenty of advanced notice was given. The tech was not new or novel it's been in use in Europe for years, the merchants just tried to delay until the last second and then surprise there were delays due to the sudden rush.

      This suit has no merit. The retail industry was not willingly moving to the more secure tech as had been done in Europe, so the CC companies who bear the brunt of fraud costs forced the move. If they had not we'd still be years from full deployment and acceptance. We're still a ways from that as I see one of my CC's and my Debit card are still not chipped and they were both replaced after the Oct 2015 deadline.

      --
      I'm too lazy to compose a creative sig.
    38. Re:Down the rabbit hole by swalve · · Score: 1

      It's probably for an external pin pad.

    39. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      "The plaintiffs are organizing a class action".

      Has nobody else seen this for what it is? Evidently the merchants CAN sue the processors. As a cardholder, I'm left with a pathetic "right" to binding arbitration if I have a dispute with the CC holder. How utterly one-sided.

    40. Re:Down the rabbit hole by peragrin · · Score: 1

      The hardware wasn't available until he last minute for most places anyways. I didn't get my american express chip card until june of 2016, I didn't get my visa chip card issued by my back until may of 2016.

      The hardware often failed and had to be replaced at the merchants expense several times. from just a terminal side of things the hardware roll out was a mess.

      lastly i know at work we were not told of the roll out until 6 months before the deadline. never knew it was coming or what we would have to do to be acceptable. For us we ended up ditching the card readers all together and just process all credit cards through a internet processor. it was lower fee, and works better for our business anyways since we often have to store credit card data for repeated transactions.

      --
      i thought once I was found, but it was only a dream.
    41. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      I'm not forcing you to put down rat poison, I'm just throwing rats in your front yard, its your decision to put down rat poison or not.

    42. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      You'd think that POS systems would have the same kind of contract/purchase arrangements that cell phone companies have been using for the last two decades.

      Given most of these POS systems are all made by about only two vendors, and are resold by the banks.

      But as far as conspiracy is concerned, I'm going to say the card companies were justified in colluding on a switchover date because otherwise one of them not complying would be disadvantaged as the fraud upticks to them.

    43. Re:Down the rabbit hole by ThatsNotPudding · · Score: 1

      I saw a mag stripe machine, and if I did see one, I would pay cash.

      Until that is phased out for being 'too expensive', meaning 'impossible to real-time track everyone using cash'.

    44. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      >Sort of, but not really. Unless you're Walmart or Home Depot, you don't write your own processing software, you rely on your point of sale vendor, and very few point of sale vendors were ready by October of last year. Many small businesses simply did not have the option to start doing EMV by the deadline.

      Nonsense. Canada and UK switched over a decade ago. They've had a decade to switch.

    45. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      Sadly despite all of this chip support is still very low, even among large merchants, and even when they already have hardware that has a chip reader, so what the hell is holding everyone back? Hell, Target only started supporting it after a huge compromise. HEB (large grocery chain in Texas) has had chip/NFC readers in stores for at least the last 4 years, if not longer, yet STILL neither are enabled. It's so dumb.

    46. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      Can't speak for him as he said he's not in US, but in the US getting completely rid of cash is impossible depending on how the business ran because of that little line "for all debts public and private". If you provide a good or service before payment you have no choice but to accept cash should the customer want to use it.

    47. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      Credit card companies are not really competing suppliers though. Merchants need to support all of them anyway or lose customers. Credit card companies compete for the consumers not the merchants.

    48. Re:Down the rabbit hole by DRJlaw · · Score: 2

      If your businessâ(TM) payment-system implementation is relatively simple with few or no customizations, then most of the Level 3 certification may not apply to your business. This includes simple implementations like single terminals, as well as specific, pre-made software packages that are certified to handle EMV transactions without heavy customization.

      So for small places there is no onsite certification.. For some larger, and especially for the ones that do customizations there is a requirement for the site-certification

      I must have missed the official announcement that "most" actually means "all."

      "No onsite certification" is bunk. There is a suite of scripts that have to be run at each deployment to check for functionality and security. The Intuit material also says:

      Level 3 is an end-to-end certification conducted between the merchant and the brand, with checks made with your processor, acquirer and any ISV(s) you are working with. It checks the integrity of the payment chain by testing every type of possible transaction that the terminal can do.

      Depending on the types of transactions and CVMs you want to process, you could be looking at upwards of a few hundred tests, especially if you accept all four brands.

      The problem is that EMVCo has been riding the "too may businesses waited to schedule certification until the deadline" excuse for more than a year -- as if that wasn't entirely predictable from the start. EMVCo is also owned by Mastercard and VISA (and JCB), which don't exactly have a lot of incentive to speed up the certification process now that transaction liability can be shifted to the retailers (they're not banks, but the banks are their largest and highest volume customers). They've cut down the number of testing scripts required and changed the rules to prevent chargebacks for low dollar transactions ($25), but otherwise haven't addressed the delays and their backlog of certification work.

    49. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      I should add that this doesn't count if they posted or notified of acceptable payment methods before providing the good/service. If they put up a sign then what I said doesn't apply.

      As always, though, IANAL.

    50. Re:Down the rabbit hole by bluefoxlucid · · Score: 1

      It's not an illegal trust action unless it abuses power. They have to use one monopoly to move into a new market, or they have to collude to enforce something like price fixing or some other profitable behavior.

      Take price fixing, for example. If three manufacturers make a widget for $15 and try to sell it for $75, they can price war with each other until it's a $20 widget. If they all collude to sell for $75, they might not get a competitive edge; but they do get $55 more per unit, which is way more than getting three times as much business at $5 per unit ($55 is more than $15).

      In this case, they've agreed on a processing and operating standard. This is similar to agreeing on the standard behind Wifi, or all agreeing to use USB-C instead of Mini-USB to charge cell phones. Someone else actually sells the terminals, which avoids the conflict of interest: the upgrade cost isn't part of the card companies's revenue stream.

      So the companies have all standardized on a technology (chip-and-pin, NFC) and a security standard. Cryptographically-secure identifying transactions ensure the cardholder is physically present at POS, unless his card was stolen; magnetic stripes are vulnerable to card cloning and thus more-frequently allow fraudulent purchases. Retailers engaging in insecure practices are responsible for the consequences.

      The card companies all adopted this standard at the same date. That means none of them is allowed to hang back and reap further profits by allowing the consumer to face a greater risk of credit card fraud. They protect the consumer from this fraud, and in doing so they reduce their costs from that fraud; this allows them to operate with lower fees (read: they don't have to raise processing fees as quickly--they might lower, or they might end up 0.3% higher rather than 0.8% higher 5 years from now), ultimately lowering the price of products (which factors in credit card processing fees) and maximizing the consumer's buying power.

      None of this abuses the consumer or the retailer: the retailer is free to use an old, insecure standard, if they're willing to accept the costs that standard imposes (cost of fraud). Likewise, it doesn't drive a revenue stream to the credit card companies: they don't sell (or don't exclusively sell) processing terminals. There's not much ground for an anti-trust suit here.

    51. Re:Down the rabbit hole by bluefoxlucid · · Score: 1

      The chip contains an encryption key signed and certified by the bank. During processing, a challenge is sent to electronic circuitry on the card, and it uses the encryption key to create a digital signature and provide a response. That key is non-recoverable, unless they use a weak encryption standard (some early cards did).

      It has to actually identify itself in a mathematically-meaningful way; it's basically PGP.

    52. Re: Down the rabbit hole by Anonymous Coward · · Score: 0

      Chips are in use in Europe for at least ten years, and even Canada has them for at least five years. There is no shortage of manufacturers of terminals for chip cards.

    53. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      Getting together and deciding the standard isn't the problem here. The problem is getting together, setting a standard, then announcing that on the exact same date you will be doing X or paying Y. Honestly, if Racketeering and Extortion aren't included it shows a potential lack of creativity by the plaintiffs attorneys.

      That said, I've been in the financial industry for over 3/4 of my career and have been waiting for this to come to the US.

    54. Re: Down the rabbit hole by Anonymous Coward · · Score: 0

      All it sounds like your fault; were not told etc.. You are the one making money. Making money while putting customers at unnecessary risk of identity theft is kind of wrong. So paying for terminal update is a reasonable burden on you.

    55. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      It's more about the liability shift from my perspective (work in the retail POS industry). Get the new card readers, and now any fraud is on you, not the credit card company. Even though the chip system really isn't all that secure. The CC companies know it's not much more secure, but aren't admitting it, they just want to shift the burden of fraud from their crappy systems to someone/anyone else.

    56. Re:Down the rabbit hole by CrimsonAvenger · · Score: 1

      As long as we have that "legal tender for all debts, public and private" thing on our currency, that's not really an option....

      --

      "I do not agree with what you say, but I will defend to the death your right to say it"
    57. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      This is the most correct post. I think we can all agree in this case that chip cards are a decent idea. But it wasn't a law/government that was forcing compliance.Instead a group of companies got together and made up their own "law" because they colluded to make sure no company would service businesses that did not accept the chip cards terms. Just because the collusion wasn't about PRICE of services doesn't make it not anti-competitive. Many things about a product offering are not captured in price and that is why price collusion is not the only type of anti-competitive collusion.

      What if all car companies decided that we will not longer use gasoline or diesel but instead will use compressed natural gas. They set a deadline for everyone to comply and all existing car companies are participating. Is this ok?

    58. Re:Down the rabbit hole by drinkypoo · · Score: 1

      Your current bank may not offer one, but some of the major retail banks do.

      Your solution is to ditch my credit union, which puts money into my community, and switch to a major bank, one of the organizations responsible for the current economic and housing crises? Fuck you.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    59. Re: Down the rabbit hole by Anonymous Coward · · Score: 0

      Terminal hardware is supposed to be certified before they are shipped.

      Software is supposed to be updated, and verified before deployment.

      Every vendor shipped untested terminals. That's disastrous.

      FTFY.

    60. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      The competing supplier would be the POS vender, which they still have plenty of choice on.

    61. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      As long as we have that "legal tender for all debts, public and private" thing on our currency, that's not really an option....

      Emphasis mine. The thing about debts is that they only exist after goods have been sold; there's no legal reason why a merchant can't refuse to sell their wares for cash. Restaurants are more of a grey area because they're usually paid after the food has been provided and consumed.

    62. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      Or use the card to buy bitcoin...

    63. Re:Down the rabbit hole by DontTrustWhatIType · · Score: 1

      But the benefit is not so clear. There is no evidence that the embedded chips have increased security wholesale "in the wild". The sum of all evidence so far (but not yet published) suggests that it's a wash. If there is an effect size, it's almost certainly going to be small. Moreover, notable experts in the field were skeptical of the claims and it was (and continues to be) largely those with conflict of interest who prance around saying that the chips will save the world (*cough* chip manufacturers, card makers, and dumbass CIO/CISO's who drank the kool aide and now need to cover their asses... *cough* *cough*).

      Regardless of whether there is a (small) security benefit or not, the chip has added a significant burden to businesses and consumers, adding an average (again, not fully publish ready) of about 15-20 seconds per transaction. Let's assume that part of this added time is because people have not done the song and dance 100,000 times on average like we've learned to do with swipe (this seems unlikely, since there is a rapid drop in time the first 30 or so times someone uses them and then a plateau, for which we can control), and let's assume it's only 7 seconds. If it were 7 seconds for a lot more security, go for it! But at 7 seconds (go ahead and count them out as you pretend to impatiently wait for the person in front of you to finish) for statistically insignificant changes across a few million transactions -- that's bad all around. The added time means you have to have more cashiers on hand, your customers are less happy, and you lose some amount of business.

      If these numbers pan out, I'm guessing that the CC companies will want to do something about it, because they do make more with higher numbers of transactions. Unfortunately, they just rammed something down the throats of a few million merchants, so they can't do that level of change again anytime soon. Which means that I silently want to smash that new card reader into the CC companies CIOs every time I'm asked to stick it in and wait for the *beerp berrp beerp* sound telling me it's finally over.

    64. Re:Down the rabbit hole by plover · · Score: 1

      I was assuming you were at one of the Evil Corp megabanks already, because none of them support PIN. I got my PIN based card through a retailer.

      Since you have a nice credit union already, ask them to add PIN to their cards. Or don't, and don't worry about what happens if the card is stolen.

      --
      John
    65. Re: Down the rabbit hole by Anonymous Coward · · Score: 0

      Y2k and software managers. Companys that neither upgraded their software nor their hardware. Then call me on Jan 1 2000. It was a conspiracy of retired cobol programmers?

    66. Re:Down the rabbit hole by lsatenstein · · Score: 1

      Chip readers have been the norm in Canada since 2005. There was a transition period allowed to accommodate card holders with cards that had only the mag stripe. Even today, if there is a problem for the reader to interpret the chip, the customer can swipe the card as the CC comes with both chip and mag stripe.

      The requirement to upgrade should have in part been financed by the CC companies. Using the chip as a standard cuts losses substantially. And with the cut in losses, it would cover the shared price of readers.

      Some CC companies rent out the reader at around $10/mo.

      --
      Leslie Satenstein Montreal Quebec Canada
    67. Re: Down the rabbit hole by Grishnakh · · Score: 1

      They can only use equipment and solutions that are actually available on the market. Merchants don't have the ability to make their own card-readers and make them conform to standards, just like you're unlikely to be able to build your own car that meets all emissions and crash-safety standards. If driving on public roads suddenly requires having new cars that meet certain standards, and you have 6 months to upgrade, but there's no carmakers actually selling these cars, what do you do?

      It looks like they found a solution anyway: ditch the card reader and use an internet payment processor like Stripe.

    68. Re: Down the rabbit hole by rickb928 · · Score: 1

      Where I work, an unrecognized (uncertified) terminal will not recieve responses. It will recieve error messages.

      --
      deleting the extra space after periods so i can stay relevant, yeah.
    69. Re:Down the rabbit hole by Grishnakh · · Score: 1

      It's just a sign of the times in America. We simply can't get anything done any more, unless it only involves a single company. If it involves regulation at all, forget it, it just won't get done or it'll be completely broken.

    70. Re:Down the rabbit hole by Grishnakh · · Score: 1

      It's probably not a big problem in Japan because people there actually care about their society. Consequently, you don't see a lot of stuff there like littering, cutting in line, etc. Even the mobsters have a sense of serving their community.

    71. Re:Down the rabbit hole by Grishnakh · · Score: 1

      What makes you think that'll always be there? It only takes a small change to the printing presses to fix that, or they could just shut down the presses altogether and pass a law requiring all transactions to be electronic.

    72. Re:Down the rabbit hole by Grishnakh · · Score: 1

      Ridiculous. There's nothing in the Constitution that I know of that says anything about that, so there's nothing stopping Congress from passing laws making the use of cash more difficult or even illegal.

    73. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      If you can't budget $2200 per POS terminal five years in advance, maybe you are too stupid to run a business.

      This has been planned for years. On a per-month basis, this is probably less than the electric bill for most small businesses.

    74. Re:Down the rabbit hole by youngone · · Score: 1
      We have been messing with our cash for as long as I can remember. Inflation took away the usefulness of 1,2, 5 and 10 cent coins, (they have been removed from circulation) and our 1 and 2 dollar notes have been coins for (can't remember) maybe 15 years.

      Our notes are plastic so they last longer, and have got smaller too.

      I guess cash is expensive.

    75. Re:Down the rabbit hole by Anonymous Coward · · Score: 0

      yeah and when a vendor is compromised and there is a fraudulent transaction the cc companies won't tell you who it was with the piss poor security. we could have had chip and pin a decade ago if these crooks weren't in cahoots this whole time.

    76. Re:Down the rabbit hole by cwsumner · · Score: 1

      Not only do the retailers have to pay full price for the terminals, the new terminals do not all have the software drivers to handle chipcards (even now)!

      But it is not just the cost of the terminals, but that the agreement for the old terminals was changed.

      I'm with you: Sell new terminals at the option of the buyer, buyer should pay. But mandate new terminals, then the provider should pay!

    77. Re:Down the rabbit hole by Hognoxious · · Score: 1

      The American people would never stand for such a violation f our fundamental hey, didn't she used to be Honey Boo Boo? What a pig! Get me a Bud while you're up.

      --
      Confucius say, "Find worm in apple - bad. Find half a worm - worse."
  2. Retailers are holding us in the stone age by Anonymous Coward · · Score: 5, Insightful

    They're just not happy about the liability shift strong-arming them into this. But honestly? They SHOULD be liable when they're the roadblocks preventing customers from having good security. They're dragging their feet on this because it's an externality--they don't care if their customers get screwed, as can be seen with, e.g. the Target hack, but they do see a cost for newer, more secure equipment.

    And I can tell you right now that they won't make proper upgrades unless someone holds a gun to their heads.

    1. Re:Retailers are holding us in the stone age by Mitreya · · Score: 2

      They SHOULD be liable when they're the roadblocks preventing customers from having good security.

      Bah, security of the credit card itself was never an issue because customer is not liable anyway

      If credit cards issuers stopped granting credit based on address+birthday+SSN, that would be a bigger improvement.

      I'd much rather my credit card number leaked compared to hack losing address/SSN info. Credit card can be blocked and re-issued. Address/SSN info, not so much.

    2. Re:Retailers are holding us in the stone age by Pinky's+Brain · · Score: 1

      The problem from the credit card company PoV was that if they were the only one to implement the liability measure the shops would simply start refusing their cards and the competitors would get their customers.

    3. Re:Retailers are holding us in the stone age by Anonymous Coward · · Score: 1

      Re: "Bah, security of the credit card itself was never an issue because customer is not liable anyway"

      Way to go! With one statement you missed the point of the OP, which isn't about the customers. It's about the vendors and the credit card companies. You also personalized the story, when the story is actually about mass fraud and card skimming. That fraud adds up and, though not normally visible to the consumer, I'll bet a week's pay that the consumer ultimately is paying for it. The CC companies will simply boost the interest rates they charge, or the fees, or whatever.

      Chip and PIN works. Wherever implemented, CC skimming rates go to zero, or near enough to zero that it amounts to the same thing. And while chip cloning is technically possible, the barriers remain sufficiently high that it's a non-issue in the wild.

    4. Re:Retailers are holding us in the stone age by taustin · · Score: 4, Informative

      They're just not happy about the liability shift strong-arming them into this. But honestly? They SHOULD be liable when they're the roadblocks preventing customers from having good security. They're dragging their feet on this because it's an externality--they don't care if their customers get screwed, as can be seen with, e.g. the Target hack, but they do see a cost for newer, more secure equipment.

      EMV has nothing to do with protecting consumers, and has zero effect on security for the consumer. Steal the card, and you can use it, same as before (since it's almost entirely chip & signature rather than chip & PIN) The consumer isn't protected buy the technology, the consumer is protected by the law, with a $50 limit on liability on a stolen card.

      EMV is about protecting the banks and processing companies, who have nearly all the liability for fraud, and secondarily protecting merchants, because when fully implemented, EMV with P2P encryption means the merchant never sees the card info at all, and has nothing on their network to steal. All the worst breaches in recent years have been of retailers' networks, stealing millions (or 100 million+) card numbers at a time. And if the retailer is PCI compliant (as Target was, apparently), the banks eat the loss. EMV/P2P encryption eliminates that vector. That is the point of it.

      And the upgrade is very, very much in the merchants' best interests because of that.

    5. Re:Retailers are holding us in the stone age by taustin · · Score: 1

      Chip and PIN works.

      Pity virtually no US chip cards are chip and PIN.

    6. Re:Retailers are holding us in the stone age by orlanz · · Score: 2

      ..That fraud adds up and, though not normally visible to the consumer,..

      Yeah, it adds up to about 1 in 1000 transactions and about $7 in $10,000 of credit spend. THATs why it is normally not visible to the consumer.

      Other fraud & costs that consumers pay for:
      Theft by Employee > 0.5% of sales
      Shoplifting > 0.5% of sales
      Spoilage Losses > 8%

      So in comparison... we are wasting a lot of money on this whole PIN & Chip crap. If it stopped 1/1000 fraud transactions, but due to the added inconvenience we lose 1/100 transactions... its basically a net loss even without the infrastructure sunk costs.

    7. Re:Retailers are holding us in the stone age by tipo159 · · Score: 1

      Chip and PIN works.

      Pity virtually no US chip cards are chip and PIN.

      This is what the US card issuers should be sued for. How is Chip-and-Sign any more secure than mag strips?

      Is this yet another way that the powers-that-be discourage Americans from international travel so that they can't see that much of the rest of the world has the same freedoms that America has?

    8. Re:Retailers are holding us in the stone age by marka63 · · Score: 1

      I don't know about you, but I hate it when I'm forced to change credit card numbers due to fraud being detected on the old number.

      Getting to the state where cards can't be skimmed is a good thing for consumers. It should also reduce the costs of goods marginally where there are only card present sales as the merchant fees should be reduced.

      You can't get to a state where cards can't be skimmed until all the point of sale equipment has been upgraded to support chips. This takes time and the US is at the end of the line in doing this.

    9. Re:Retailers are holding us in the stone age by swalve · · Score: 1

      In some comment above it is shown that chip and pin can be defeated with a simple sticker. So stop.

    10. Re:Retailers are holding us in the stone age by mjwx · · Score: 1, Informative

      EMV has nothing to do with protecting consumers, and has zero effect on security for the consumer. Steal the card, and you can use it, same as before (since it's almost entirely chip & signature rather than chip & PIN)

      I cant beleive you wrote that entire post just to say "I know nothing about EMV".

      EMV was never designed to protect against fraudulent transactions or to block stolen cards, it was designed to protect against card cloning. In this endeavour it has been hugely successful. Whilst you can clone EMV cards, it's such a PITA that no-one bothers.

      Now the real defence that is stopping stolen cards that is going along with EMV is the elimination of signatures for purchases. This is because signatures are easily faked (including removing the old signature and putting your own on, which is pretty redundant as no-one checks it anyway). You cant sign for a purchase any more and enforcing this means getting rid of the old terminals which would ask for a signature. EMV is about protecting the banks and processing companies,

      Again, you're wrong.

      EMV terminals push the liability onto the banks and processors, non EMV terminals push the liability onto the merchant. So if a merchant using an EMV terminal has a fraudulent transaction, they're covered and the cost is worn by the bank or processor.

      --
      Calling someone a "hater" only means you can not rationally rebut their argument.
    11. Re:Retailers are holding us in the stone age by taustin · · Score: 1

      Chip and PIN works.

      Pity virtually no US chip cards are chip and PIN.

      This is what the US card issuers should be sued for. How is Chip-and-Sign any more secure than mag strips?

      EMV has nothing to do with security at point of purchase. EMV is the first step to point of point encryption (which is available on may systems now), which eliminates breaking into Target's network and stealing 100 million+ card numbers at the same time.

      Is this yet another way that the powers-that-be discourage Americans from international travel so that they can't see that much of the rest of the world has the same freedoms that America has?

      A week ago today, I was in Iceland, mostly using my magnetic strip card for everything. I had zero trouble doing so. The only minor issue was that you can only buy fuel for your car with a card that has a PIN, and their system does weird-ass things with authorizations on ATM cards. But I had no trouble buying a gas card with my mag strip card. I just had to walk inside to do so. Big deal.

    12. Re:Retailers are holding us in the stone age by taustin · · Score: 1

      I cant beleive you wrote that entire post just to say "I know nothing about EMV".

      That says more about you than it does about me, or EMV.

      Now the real defence that is stopping stolen cards that is going along with EMV is the elimination of signatures for purchases. This is because signatures are easily faked (including removing the old signature and putting your own on, which is pretty redundant as no-one checks it anyway). You cant sign for a purchase any more and enforcing this means getting rid of the old terminals which would ask for a signature.

      With chip & PIN, perhaps, but since virtually no credit cards in the US are chip & PIN, you have no idea what you're talking about. My employer had gotten to where we didn't need a signature on small transactions. With the implementation of EMV, since most cards are chip & signature, we now must get a signature on all transactions again, even for less than a dollar. That'll change, but you clearly have no idea what you're talking about.

    13. Re:Retailers are holding us in the stone age by Anonymous Coward · · Score: 0

      Re: "due to the added inconvenience we lose 1/100 transactions... "

      You are talking out of your ass. Seriously, I use Chip and PIN every day, or near enough. It is neither more nor less convenient than the mag stripe based transactions.

      And the infrastructure sunk costs? A percentage of the infrastructure is replaced every year anyways. While I imagine the odd retailer will have to replace nearly new readers, this is going to be a smaller part of the whole rollout.

      Avoiding losses due to fraud is a good thing. And often you have to take the opportunities to reduce system losses when the opportunity presents itself. Many systemic losses are difficult to address at their root. Chip and PIN directly attacks skimming at the root.

  3. Not Sure if... by jittles · · Score: 5, Insightful

    I'm not sure if I have any sympathy for these retailers. The card industry did not force them to accept chip transactions, they forced them to accept liability if they refused to accept chip transactions. You can still, to this day, accept magnetic stripe data instead of chip data. You can also choose to take cash at any time. They also gave the warning more than a year in advance and even basically extended the deadline past October 2015.

    Disclosure: I do make money off the chip card transition. However, I make money off of magnetic stripe implementations also.

    1. Re:Not Sure if... by Anonymous Coward · · Score: 1

      In other words it was a conspiracy.

    2. Re:Not Sure if... by cayenne8 · · Score: 4, Interesting
      I hate the fucking chip things....

      I keep almost leaving my fucking card in the slot and walking away.

      With no PIN, I can't see how it is really any safer to me.

      And these days, half the time I get it wrong, if I plug it in, they say "no..still need to swipe", or vice versa.

      --
      Light travels faster than sound. This is why some people appear bright until you hear them speak.........
    3. Re:Not Sure if... by markdavis · · Score: 5, Insightful

      I would +1 you if I had points.

      The chip thing is a disaster as far as I am concerned:

      * It is slow as molasses. Just unreal!
      * It encourages you to forget your card.
      * The other day it took 5 MINUTES for it to finally work at a store, the stupid contacts on my card are already corroded and the card is only 4 months old. Guess what, if it doesn't read, they wouldn't allow me any other way to use the card (key it in or swipe it). So it is NOT RELIABLE.
      * There is still no PIN, so it doesn't prevent anyone from picking up my card and using it.
      * It doesn't protect anything with online purchases.

      Fail for consumers
      Fail for stores
      Fail for security
      Fail for convenience
      Fail for economy

      *FAIL*

    4. Re:Not Sure if... by Anonymous Coward · · Score: 0

      ROTFLMAO, I have been using Chip cards for YEARS in New Zealand, and contactless payments with the card for years too.
      I dont even need to take it out of my walled, jut open it up and flip it on the reader and away I go. Nice this is, because it sits in the middle of my wallet all the other cards and crap I have stop it from being read, so walk by skimming is not an issue either.

      Next you are going to tell me the US is still using the imperial system of measurements

      So backwards....so so backwards.

    5. Re:Not Sure if... by Anonymous Coward · · Score: 0

      With no PIN, I can't see how it is really any safer to me.

      It isn't. If anything, this system makes you less safe by giving the issuer an excuse to blame you for any fraud committed using your account. Becuase "Hey, our systems are now super-duper secure". So not only are you left with the task of repairing your credit history, your request to have charges removed is denied.

    6. Re:Not Sure if... by Anonymous Coward · · Score: 1

      It prevents the mag stripe reader from keeping a copy of your card. Michaels, Home Depot, and Target were all hacked and the data on mag stripe were used in fraud. I believe 2 of those companies kept that data, the other got the readers hacked. A chip card in the same circumstances would be immune, they wouldn't be able to clone the card, PIN or no PIN.

      I can't help you forgetting your card, but most of them have an annoying beep to remind you.

      As for the slowness, there is no reason it has to be. The code the merchants are using is written poorly trying every possible program on the card. If they could agree to use just 1 and all implement it, the reader would be nearly as fast as mag stripe.

      Not telling you chips are better, just trying to let you know it stops a specific type of fraud and doesn't have to be as bad as it currently is.

    7. Re: Not Sure if... by Anonymous Coward · · Score: 3, Informative

      Maybe this is an American problem, who knows. In Canada, we have been using Chip and Pin exclusively for 5 years now. No swipe. We have even moved past chip and pin to a new technology called Tap, where we can just tap our card on the reader for any purchase under $50, or $75 at gas stations and grocery stores.

      Both are safer because they use rolling codes built in to the chip. If someone skims your card the data they get is only valid for a few minutes after its used .

      You get used to it. You don't forget your card. Time to join the modern era America.

    8. Re:Not Sure if... by xevioso · · Score: 1

      At least we aren't upside down, our toilet water circulates in the correct fashion when flushed, and we drive on the correct side of the road...

    9. Re: Not Sure if... by Opportunist · · Score: 4, Informative

      Europe here, same deal. I can't remember when I actually used that magstrip of my card outside of the US. Even third world countries have had chip readers in operation for years now, only in the US this seems to be a huge issue.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    10. Re:Not Sure if... by ArylAkamov · · Score: 1

      It is slow as molasses. Just unreal!

      This is the biggest annoyance for me. It took a few seconds before, now it takes anywhere from 20 to 30 seconds for it to process. Might be because I'm in a small town in the US, I've heard the equivalent over in the UK is just as fast.

    11. Re:Not Sure if... by ADRA · · Score: 1

      From a Canadian, you'll get used to it.. eventually.

      I'd say the lack of PIN requirement was your country's fuck up, but *shrugs*.

      Slowness depends entirely on your retailer's merchant broker. Some big box companies like (Walmart Canada) has responses back within a second or two. Others require a frigging dial-up connection before issuing the chip challenge. Ultimately, if you're sick of waiting, poorly performing retailers will suffer and you'll visit their services less. The better responding retailers will actually spend some money to make sure your experience is good.

      I have had my card defrauded a couple times (once from card stolen, once from the card numbers being copied for online purchases). Both times, I've had literally 0 problems challenging and refunding the expenses. Almost 100% of the bad charges were made in the US, so it leads me to believe there's a lot of credit fraud happening there (at least when my cards were stolen).

      --
      Bye!
    12. Re: Not Sure if... by Anonymous Coward · · Score: 0

      No. Please kill yourself.

    13. Re:Not Sure if... by Anonymous Coward · · Score: 0

      I had no problem with that either.

      EXCEPT...

      Now they are charging us $5/month for NOT having a chip enabled terminal. This is after they pawned off the liability to me already so their 'costs' are LESS if anything.

      God I need a new business model to keep up....how can I charge half the amount to NOT buy my products?

    14. Re:Not Sure if... by houghi · · Score: 2, Insightful

      The only fail I agree with is that you do not use your PIN.

      It takes about 15 seconds for the payment. Due to postings here, I have tested it and also looked at other people trying it out.
      I have NEVER forgotten my card, ever. I put it in, type my PIN and take it out while I have my wallet in my other hand. Almost everybody does it like that. Why would you NOT take it out again.
      Corroded card? I have been using these cards for I do not know how long. Never had that issue. It does happen that sometimes the card or the reader fails. However when you see how many million of transactions fail, this is an minute amount and the magnetic strip fails more than the chip percentage wise. It is just not used that much any more in Europe.

      It was not intended for online purchase security. You could even claim that it does not help open a beer and even if true, it is not relevant.

      So I agree with the PIN part, the rest are apparently issue that have to do with the Imperial system as the rest of the world does not have an issue with it and many have moved on to even more modern things, like wireless payments for smaller amounts.

      So yes, we get it: people do not like change. It happened when people where forced to go from Win3.1 to Win95. It happens all the time when things change. I know people moaned when HD was deemed stoopid for TV. It is happening now allover again. People do not like change.

      There is also a reason that many banks in Europe block the cards for the USofA and you have to ask them to activate it. If that is the case, how bad is the issue in the US you think? Or do you think that walking around the city and throwing in windows is good for the economy, because the window makers are making more money?

      --
      Don't fight for your country, if your country does not fight for you.
    15. Re:Not Sure if... by Vadim+Makarov · · Score: 1

      Don't get me started on the toilet water. We run a data collection, and it failed to remove the shit 4 times out of 102. That's in our rental house in Canada, though.

      --
      17779 eligible voters in a district, 17779 'vote' as one. This is Russia.
    16. Re:Not Sure if... by taustin · · Score: 1

      I hate the fucking chip things....

      I keep almost leaving my fucking card in the slot and walking away.

      That says far more about your than it does about chip cards.

      With no PIN, I can't see how it is really any safer to me.

      It's not intended to be. It's safer for the banks, and indirectly, for the merchants. You're not protected by the technology, you're protected by the law.

    17. Re:Not Sure if... by PrimaryConsult · · Score: 1

      If you're a small business you could go back to cash only. Usually I pay cash at small businesses anyway since I know the 3% card fee is more painful to them than it is to McDonald's or Home Depot...

    18. Re:Not Sure if... by houghi · · Score: 1

      Read here on /. tyhat it is because instead of just using only the standard check that dopes it all, they load in every check available. So basically it needs to the the same check 50 times.

      The data is not that much different then what is send when you do a swipe. Even with the PIN there is not that much extra that is being send. And it does not matter that the I do a payment in Belgium or in Spain or anywhere else in the world. The speed is about the same.

      I live in Belgium and I did a wireless payment in Spain. That basically means tapping the card on the reader and not entering your PIN and I could walk away in seconds. Adding the entering of the card and pressing the pin might add 10 seconds or so.

      it is crazy that this worked with cards I had in Belgium from an American Bank and that people I know that have US cards with chip and use them in Belgium do not have the same problem here.

      So the knowledge is available and has been used worldwide. The problem detection has been done a LOT already and beta testing has been concluded in the rest of the world for decades and the US is STILL able to fuck it up?

      And yes, there are smaller towns in poorer countries that are more remote then where you live where it works better.

      --
      Don't fight for your country, if your country does not fight for you.
    19. Re:Not Sure if... by houghi · · Score: 1

      Yeah, but the amount of water you need to that is INSANE.

      --
      Don't fight for your country, if your country does not fight for you.
    20. Re:Not Sure if... by jezwel · · Score: 1

      The US version is a failure, due to the implementation requirements causing significant increases in processing the transaction. It's been detailed somewhere here before already in a previous story.
      Every other country I've been to where you can use chip & pin (even tap & pin), will have the transaction completed in 5 to 15 seconds.

    21. Re:Not Sure if... by Anonymous Coward · · Score: 0

      well, get your head out of your ass. EVERY machine I've used that I have to put my cards into for the chip read fucking BEEPS at you to pull the card out before completing the transaction.

      your own stupidity

    22. Re:Not Sure if... by Anonymous Coward · · Score: 0

      So backwards....so so backwards.

      And this from New Zealand who waited until 1996 to ban leaded gasoline!

    23. Re:Not Sure if... by Anonymous Coward · · Score: 0

      It was an industry decision to implement better security. If that is criminal conspiracy then so is every other industry decision.

    24. Re:Not Sure if... by Anonymous Coward · · Score: 0

      That is a verifone problem with their crappy java readers. If you go to a place that has a cheaper style reader (no mutli-color lcd display) they tend to be noticeably faster.

    25. Re: Not Sure if... by maliqua · · Score: 2

      Time to join the modern era America.

      You're talking about the country that still fears the metric system

    26. Re:Not Sure if... by SvnLyrBrto · · Score: 0

      1) Even if it did take only 15 seconds every time, That's more than 3x as long as it takes me to swipe a magstripe card and put it back in my wallet. And, if I'm at a store that accepts ApplePay, that's about 4x as long as it takes to double-pop the button on my watch and hold my wrist up to the scanner. So either way, wasted time for no benefit.

      2) It not take only 15 seconds all the time. There are definitely some implementations that are better or worst than others. Target seems to be the worst offender that I encounter with any regularity. It's rare for their terminals to take less than 30 seconds, 45 is more common, and I've had to leave my card in their terminal for over a minute before. And yes, I did time it. So, on the average, even more wasted time for no benefit.

      3) Since we stupidly went with the chip but skipped the PIN, there's absolutely no additional protection for me if I get mugged or lose my card. The culprit can still use it just as easily as they could the mag stripe. So even if the transaction did take less time than the stripe or ApplePay, there is STILL absolutely ZERO benefit.

      4) Even if we did implement the PIN, maximum liability under law for fraudulent charges is $50. And all but one of my cards waive that. So, divided out by the 7 cards, the only possible benefit to a full-out chip+PIN implementation would essentially be $7.14, which is essentially negligible. And if I were to divide my salary out to figure how much of my time equates to $7.14, I'll bet that the chip cards have already wasted more than $7.14 worth of my time just in this last year.

      --
      Imagine all the people...
    27. Re: Not Sure if... by SvnLyrBrto · · Score: 1

      The difference is that there are actually benefits to the metric system, which is superior to imperial measurements in every way except perhaps for using Celsius in weather reports instead of Fahrenheit. Yeah, I know the freezing and boiling points of water make a lot of sense from a scientific point of view. But for the weather: 0 degrees being a horribly bone-chillingly frigid day, 100 degrees being an insanely and sweltering scorchingly hot day, and 50 degrees being a nice and normal comfortably mild day, does make a decent amount of sense IMO. Pounds, feet, quarts, and the like though, I'd happily say good riddance.

      The chip cards, OTOH, provide me with zero benefits without the PIN. And even with the PIN, the benefits would be minimal. And they waste a ridiculous amount of my time vs. swiping the mag stripe. So, I still maintain that they are an epic fail.

      --
      Imagine all the people...
    28. Re:Not Sure if... by jittles · · Score: 1

      I would +1 you if I had points.

      The chip thing is a disaster as far as I am concerned:

      * It is slow as molasses. Just unreal!

      That's an implementation problem - one I see all the time. This has to do with the way they set up their AID Candidate list, most likely. An EMV transaction should take 1-2 seconds.

      * It encourages you to forget your card. * The other day it took 5 MINUTES for it to finally work at a store, the stupid contacts on my card are already corroded and the card is only 4 months old. Guess what, if it doesn't read, they wouldn't allow me any other way to use the card (key it in or swipe it). So it is NOT RELIABLE.

      The US region still has what they call technical fallback. They're not supposed to decline to accept your card if it fails to read 3 times then they are supposed to proceed with it as magnetic stripe. There is no fraud liability shift in this case, at least for now.

      * There is still no PIN, so it doesn't prevent anyone from picking up my card and using it.

      It protects your card from cloning, which is the most common type of card fraud in the US

      * It doesn't protect anything with online purchases.

      None of the current card technologies protect against Card Not Present transactions

      Fail for consumers Fail for stores Fail for security Fail for convenience Fail for economy

      *FAIL*

      I don't personally see any failure except in the development teams that do not know how to properly implement EMV.

    29. Re:Not Sure if... by Anonymous Coward · · Score: 0

      Actually, (most) rock is more dense (heavier) than water.

      As there is more land in the northern hemisphere , it is therefore logically heavier.

      Now earth rotates the sun in fairly much a vacuum, so friction is minimal to none. That would allow the heaver north to rotate/sink to the bottom, and by that logic it does mean the southern hemisphere is actually at the top. So, therefore it is YOU who is upside down.

      You can prove this by putting something heavy on one end of a cork and placing this in water, the heavy side will go to the bottom.

      I will give you the water in the toilet thing only because it goes clockwise where you are.

      As for driving.... Most people are right handed. By driving on the RHS it put the driver on the LHS of the car.
      This by extension means that the drivers right hand is in the middle of the car.
      This also means that in most cases the drivers gun hand is in the middle of the car.
      This is not "right" as such, but it seems a logical safety precaution.

      In New Zealand, with most drivers also being right handed, it ensures that the right hand is on the steering wheel while the left hand changes the gears as it is in the middle of the car where the gear stick is, therefore it is "more safe" for more people (we don't have a redneck or a gun problem here).

      So NZ will take that one too which puts us in the lead with a 2 to 1 winning margin.

    30. Re:Not Sure if... by markdavis · · Score: 2, Informative

      >The only fail I agree with is that you do not use your PIN.

      We don't HAVE a PIN, so there is nothing was and choose to use or not use. There is no choice. No PIN.

      >It takes about 15 seconds for the payment. Due to postings here, I have tested it and also looked at other people trying it out.

      15 seconds is about 10 times longer than it used to take.

      >I have NEVER forgotten my card, ever. I put it in, type my PIN and take it out while I have my wallet in my other hand. Almost everybody does it like that. Why would you NOT take it out again.

      Because instead of swipe and put in wallet, which takes 1 second, you have have to insert the card, wait for 15 to 30 seconds or longer, someone is distracting you, cashier asks questions, does something, hands receipt.... all the while, the card is still there saying "DO NOT REMOVE" and you don't notice when it says remove. Again, THERE IS NO PIN. There is no interaction with the system whatsoever after inserting the card. So it is easy to forget during that long delay.

      >Corroded card? I have been using these cards for I do not know how long. Never had that issue.

      That's great for you. But my card, which is stored only in a clean wallet, had fouled contacts in just 4 months. VISA card.

      >So yes, we get it: people do not like

      Don't be so condescending. I have no problem with change, I have problems with change that makes something WORSE that it was before- more annoying, less convenient, more time consuming, less reliable. And that is my experience with this so far.

    31. Re:Not Sure if... by Anonymous Coward · · Score: 0

      >With no PIN, I can't see how it is really any safer to me.

      To create a fully working cloned magstripe, you simply need the information that the reader gets from a single swipe of that card.

      To create a fully working cloned chip, you need to get the private key located on the chip, which never leaves the chip in normal use.

      Bottom line: with just the magstrip, someone could clone your card if you ever bought something at a store with a comprimized reader. This is not true for the chips.

    32. Re:Not Sure if... by Anonymous Coward · · Score: 0

      I use cards with chip + pin daily.. The card i have usually lasts >2 years and that is actually more than what the cards with magstripes managed to take (with the amount of usage i have)..

      Encourages you to forget your card? Never had a problem with that..

      A typical purchase (with pin) for me is:
      1. Insert card while they are scanning the goods.
      2. Wait for it to read card and scanning of goods to complete.
      3. Get amount and approve amount with pin.
      4. 2 seconds later it approves the transaction and i can remove my card..

      Right now i'm on a business trip to the states and paid for the taxi with my chip-based card.. (they used signature instead of pin)
      1. Insert card
      2. See amount i'm going to be charged
      3. Sign with finger on display.
      4. Remove card.
      Took the same amount of time as when using a pin...

      The benefits you as a customer have:
      - Less chance of someone skimming your card since making a copy of the chip is a lot harder than making a copy of the mag-strip.
      - Removes the risk of being double-charged for something. Each transaction requires a pin or signature.
      - You will never loose sight of your card since you will be required to enter pin or sign. (harder for anyone to make a copy of number + cvc)

      But lets look at your statements...

      * It is slow as molasses. Just unreal!

      Usually never have an issue with that.. except when there are communications-issues to the bank to verify that the amount is available on the card. I would say this is due to the requirement of validating the transaction with the bank every time.

      * It encourages you to forget your card.

      Eh what? Used chip + pin for 10 years or so here and never forgot my card..

      * The other day it took 5 MINUTES for it to finally work at a store, the stupid contacts on my card are already corroded and the card is only 4 months old. Guess what, if it doesn't read, they wouldn't allow me any other way to use the card (key it in or swipe it). So it is NOT RELIABLE.

      I would say it's the other way around.. it takes me > 3 years to wear out a chip.. Magstrips got worn out a lot faster in those days. I do remember the early days of chip based cards where i live and it took the banks a few rounds to find good enough cards.. some of the early ones would crack or stop working without reason.... but that's like >10 years ago..

      * There is still no PIN, so it doesn't prevent anyone from picking up my card and using it.

      When chip-terminals are out there they can start migrating people to using pin instead of signature.

      * It doesn't protect anything with online purchases.

      As above.. It removes the situation where you don't have control over your card.. With chip+sig or pin you can always have physical control over the card reducing the risk of a shop making a copy of the cvc.

    33. Re: Not Sure if... by Anonymous Coward · · Score: 0

      Metric vs Imperial
      Cold enough that you will fight to stay inside.. -30C == -22F
      Cold enough that you may go outside for some skiing or other winter sports. -10C == 14F
      Where water starts to freeze and roads become slippery. 0C == 32F
      Not too cold, but still need a thin jacket. 10C == 50F
      Nice day with comfortable weather 20C == 68F
      Warm day that it preferable to spend at the beach 30C == 86F

      I would still say that metric is better than imperial.. but that's just my preference and i think your preference is just that you grew up with it and can easily associate the different types of weather with the temperature in F.

    34. Re:Not Sure if... by Anonymous Coward · · Score: 0

      The US has still not banned it.

    35. Re: Not Sure if... by Anonymous Coward · · Score: 0

      They are harder to clone. I am in the UK and every time I was contacted by my bank about fraud, the purchase was in America.

    36. Re: Not Sure if... by nnull · · Score: 1

      It is mostly an US problem because it's been very poorly implemented in the United States. And since a lot of fraud is moving online, it does nothing to prevent that.

    37. Re:Not Sure if... by AmiMoJo · · Score: 1

      Hmm, maybe the system is different in the US, but in other countries it works really well and is faster than the old signature method.

      Because you insert the card and hold your hand by the the terminal while you enter your PIN, it's almost impossible to forget to take your card. The old swipe way where you want the card to the cashier was worse for that.

      Corroded contacts? Ew, your wallet must be soaked in sweat or something. I've never heard of that happening to anyone. Or maybe US banks are really cheap on the contact material and don't plate it for corrosion resistance.

      European cards often don't even work without the PIN. When I'm in Japan using a UK card it will sometimes pass for small amounts without the PIN, but signing isn't an option for anything over about 3000 yen (~$30).

      Maybe you should get your bank to issue a PIN number, might make the whole thing work better for you.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    38. Re:Not Sure if... by markdavis · · Score: 1

      I still don't think you understand...

      >Because you insert the card and hold your hand by the the terminal while you enter your PIN, it's almost impossible to forget to take your card.

      I told you, we don't and can't have a PIN... so the way YOU use it doesn't apply here. We insert the card and just wait forever.

      >Corroded contacts? Ew, your wallet must be soaked in sweat or something.

      Nope, it is clean and dry and perfect. Perhaps the contaminates came from the card readers. I don't know.

      >Maybe you should get your bank to issue a PIN number, might make the whole thing work better for you.

      Terminals here don't work with a PIN, it is not an option. So requesting a PIN wouldn't help or change anything because I wouldn't be able to use it anywhere I shop.

    39. Re:Not Sure if... by Anonymous Coward · · Score: 0

      Every place I've used a chip card has a beeper go off when it is time to remove the card, the screen also flashes. I'd suggest that if you are deaf, blind and forgetful then any sort of money transaction is a bad idea ( oops I forgot my stack of $100's).

      Many merchants have a ceiling on tap and go transactions. If your payment is less than the amount you can just tap the card with no PIN. If it is above then you insert the card and type in your pin. The pin length is small but has been set so that their call centres don't get too many "I forgot my PIN" calls. The comments about end to end encryption where the merchant doesn't have the card info makes sense.

      Processing time seems to be more dependent on connection time. If the unit has a fast network connection it is fast, if it dials up it is slow.

      BTW, all costs are eventually paid for by the customer's. If they aren't then the business eventually stops operating.

    40. Re:Not Sure if... by mjwx · · Score: 1
      Having had an EMV capable card since 2007, you couldn't be more wrong. I've also installed these terminals as they were being rolled out in Australia from 2010 onwards.

      * It is slow as molasses. Just unreal!

      Its faster than swiping. The hold up is not with the reader, it's with the network. If your merchant has a slow link, any processing is going to be slow.

      * It encourages you to forget your card.

      Only if you're a forgetful idiot.

      The other day it took 5 MINUTES for it to finally work at a store,

      Again, this is due to a slow or unreliable link.

      * There is still no PIN,

      This is due to the implementation in your country, blame your banks or better yet, the technophobes and laggards that are holding you all in the dark ages.

      It doesn't protect anything with online purchases

      Because it's physical security, not online security. As physical security designed to prevent card cloning it has been extremely effective the world over.

      The only fail here is yours, you have to be a complete dolt to leave your card in a machine and walk away. This is a very rare occurrence in Europe, rare to the point of it being practically unheard of, every now and then old Ms Beryl from down the lane leaves it in the local Waitrose, but the staff just give the card back to her along with everything else she forgets on a regular basis the next time she pops by for some milk and jam (but I guess that kind common sense is what you call European style Communism(TM) 'round your parts).

      However if you're that forgetful, just start using cash. Its faster (eliminating the slow link problems you're having) and you don't have to retrieve it from a machine where you forgot it. It also cant be stolen online.

      --
      Calling someone a "hater" only means you can not rationally rebut their argument.
    41. Re:Not Sure if... by Anonymous Coward · · Score: 0

      Use a debit card instead, you will get a pin. I have chip+pin in the US right now.

    42. Re:Not Sure if... by Anonymous Coward · · Score: 0

      USA ban was also 1996, California was in 1992.

    43. Re: Not Sure if... by Anonymous Coward · · Score: 0

      I don't think you realize how big the US economy is compared to the rest of the world. Its pretty big.

    44. Re: Not Sure if... by Anonymous Coward · · Score: 0

      USA here; I just visited Europe for the first time this spring and I was amazed at how well everything worked. I have no idea what our problem is, but finally seeing things first hand is really an eye opener.

    45. Re:Not Sure if... by Anonymous Coward · · Score: 0

      The most common type of card fraud in the US is not card cloning, and hasn't been since the late 1990's.

      The most common type of card fraud in the US is card-not-present transactions (read: online purchases) being performed after taking a picture of the front and back of a card while the cardholder isn't looking, then entering those numbers (and the easily-seen CVV2) into a checkout form. Then you have the freight drop-shipped to some unsuspecting sucker that has agreed to re-ship things for you.

      Magstripe, chip, signature, PIN, none of these matter. Your card is skimmed by having the account numbers printed on it, and the bank will do fuck-all to fix that, pretty much ever.

    46. Re: Not Sure if... by cayenne8 · · Score: 1

      You're talking about the country that still fears the metric system

      No fear of it really...just no USE for it really.

      I mean, of most of the US citizenry, there is absolutely NO compelling reason to change. It would not benefit their lives, but it would prove to be a BIG PITA to have to learn everything...I know how to dress when it is 72F outside intuitively.

      Without googling it every time, I have no fucking idea how to dress for some random metric temp like 45C.

      I cook with cups, TBSP, etc...I can measure those without even needing a measuring vessel many times....

      So, for the general public, there is no compelling reason to change, but many reasons not to cause ourselves a couple of generations of hassle.

      --
      Light travels faster than sound. This is why some people appear bright until you hear them speak.........
    47. Re:Not Sure if... by cayenne8 · · Score: 1

      I have NEVER forgotten my card, ever. I put it in, type my PIN and take it out while I have my wallet in my other hand. Almost everybody does it like that. Why would you NOT take it out again.

      That's not how it works here in the US.

      You plug the card in...no PIN required, BUT a message pops up on the screen and says "Please card in slot"...etc. The transaction take much longer than a swipe does apparently. Well, during that time I'll often take my attention away from it to usually chat with the clerk, or line mates, etc.

      Anyway, after they finish ringing my stuff up, I often forget the fucking card is in the slot and walk out.

      In the past, I would pull card out while things were going on, swipe it and immediately put it back in my wallet and be done with it....

      --
      Light travels faster than sound. This is why some people appear bright until you hear them speak.........
    48. Re: Not Sure if... by fuzzywig · · Score: 1
      How long does it take for your chip+PIN transactions?
      Here in the UK, the person behind the counter says "that'll be £X please" and presses a button so the total appears on the reader (elapsed time, maybe half a second).

      You put the card in, wait about two seconds for it to be read, type in your PIN and press enter, then wait about another three to five seconds to verify. Then just take your card out and walk off.

      Admittedly it's been about 10-15 years since I last had to use the mag stripe, but I remember it taking much longer waiting for the receipt to print out, signing it, passing that back to the person behind the counter etc. etc.

    49. Re: Not Sure if... by Anonymous Coward · · Score: 0

      It's about one fifth of the size of the economy of the rest of the world. However, I do not see how the size of the economy would make it any more difficult (or easier) to switch to a somewhat more modern way of accepting credit cards.

    50. Re:Not Sure if... by Anonymous Coward · · Score: 0

      On the upside, pretty much all new terminals support contact-less payment. The forced upgrade means everyone has new terminals.

      I've been using apple pay for most of my transactions and it's faster than chipped cards by a mile. Fingerprint scan, wave phone, done.

    51. Re:Not Sure if... by Anonymous Coward · · Score: 0

      If you are a consumer you can switch to using cash for most things. It takes a bit more planning, but it isn't a big hassle. I've never heard of a scheme to hack cash from thousands of miles away without any involvement from the cardholder. Using cash also allows you to opt out of a significant amount of bulk surveillance. I've not used my card for any in-person purchases in at least 3 years.

    52. Re: Not Sure if... by Anonymous Coward · · Score: 0

      The difference is this:

      Magstripe:
      Swipe the card. The machine beeps to show that it's read the card.
      Put my card back in my wallet.
      The machine takes 5 seconds to bring up the "scrawl your 'signature' here" view.
      My card is now put away, I scribble on the signature pad and hit "OK"
      I pick up my purchase and go.

      Chip:
      Insert the card. Wait 1 second for the machine to beep indicating that it's connected to the card (frustration 1).
      Stand and stare at the screen, indicating "Authorizing..." (frustration 2)
      The machine takes 5 seconds to bring up the signature view.
      I scribble on the signature pad and hit "OK".
      The machine beeps at me. I take my card out of the machine.
      Now I take another 5 seconds to get my card and wallet put away.
      I pick up my purchase and go.

      5 seconds vs. 11 seconds. In a retail checkout lane, that feels like an eternity.

    53. Re:Not Sure if... by Anonymous Coward · · Score: 0

      Which is LESS secure, because you don't have the same legal protections on a debit card that you do with a credit card, AND you've just given the crook access to your bank account.

      It's also not going to do anything to speed up a slow terminal.

      I'll take quick swipe + strong consumer protection law over chip + anything. It's just better.

    54. Re:Not Sure if... by Anonymous Coward · · Score: 0

      No, it's slower than swiping. I frequently go to a nearby Kroger. Their machines require the chip if your card has one. I have one card with, and one card without.

      The swipe card is read and back in my wallet in less than two seconds, before the cashier is even done. The transaction completes nearly instantly once the cashier finishes. The chip card can't be inserted until the cashier finishes, then has to stay in the reader for 15-30 seconds. I know you think it's a network issue, but it isn't - same network, same card reader, chip is significantly slower.

      And blaming the customer for being a "forgetful idiot" is utterly unhelpful, and hides the fact that by forcing a 15-30 second wait with the card in the terminal, you've created a situation where large numbers of people are going to be "forgetful idiots" because they're human. It's unacceptable, it means the user interface is bad.

      I (and I suspect most people) don't really give a rat's ass about the bank's security. Credit card fraud is one area where the US actually has really good consumer protection law, and it's not my problem if the card number is stolen, it's the bank's problem.

    55. Re:Not Sure if... by markdavis · · Score: 1

      >The only fail here is yours, you have to be a complete dolt to leave your card in a machine and walk away. This is a very rare occurrence in Europe

      DUH!!! WE ARE NOT IN Europe. As I said in several replies now, there are NO PIN CODES HERE. So there is nothing to interact with on the terminal. You put in the card and wait forever, with nothing inbetween. If you can't realize there is a very different process without the PIN and how that plus the long delays can lead to forgetting the card, then you are the dolt, not me. (Plus I will say I have never left my card, I said I have almost done so a few times).

      The chip is NOT faster than a swipe. NO WAY. I used to swipe the card instantly and put it back in my wallet. Done. The fastest I have EVER seen the chip card operate before I had my card back in my wallet was about 6 seconds. Huge difference.

    56. Re: Not Sure if... by david_thornley · · Score: 1

      0 degrees being a horribly bone-chillingly frigid day

      Speaking as a Minnesotan - Wimp! I lost a lot of my cold resistance a few years back, but 0 still isn't that bad. You're saying that the Fahrenheit system suits your own temperature preferences more than Celsius. That isn't a really good argument for people living in areas that actually get cold or hot.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    57. Re:Not Sure if... by david_thornley · · Score: 1

      I've actually been at one US retailer that had chip and PIN enabled, and it took me a moment to remember which PIN it had. I don't remember it as being significantly faster than the agonizlingly slow chip & signature.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    58. Re:Not Sure if... by david_thornley · · Score: 1

      Its faster than swiping. The hold up is not with the reader, it's with the network. If your merchant has a slow link, any processing is going to be slow.

      Dude, not all of us can live in a First World nation. Some of us are in the US. I don't know the technical details, but chip transactions are always far slower than magnetic swipes and require the card to be stuck in the reader the whole time. In a swipe transaction, I take the card from my wallet, swipe it, and put it back in my wallet. It is never out of both my hand and my wallet. The time needed to get the damn transaction to work is plenty enough for people to get distracted and forget their card is still there, particularly if they're not used to it yet. People talk about fast transactions if they live in fully developed countries, and that would help a lot with the problem.

      From my point of view, it doesn't matter if my bank sucks or somehow every retailer in the area has a slow unreliable internet connection (which I don't believe for a moment). Not being an insider, I can only report on my experience, which is that chip transactions suck.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    59. Re: Not Sure if... by DarkVader · · Score: 1

      It's about the same for the total to appear. Then you put in the card, wait 15-30 seconds, put in the PIN for debit cards, or hit enter for credit cards, then sign screen. Wait another random amount of time for it to verify (typically 5-30 seconds), then take card and walk off.

      With swipe, it's swipe card while cashier is still scanning, put card back in wallet. When cashier finishes, put in PIN or sign screen, and walk off.

      Yes, it's the terminal manufacturers' fault it's slower. But it's still MUCH slower.

      Oddly, Apple Pay is typically far faster if it's available, it's nearly instant.

    60. Re: Not Sure if... by DarkVader · · Score: 1

      I deal with both systems on a fairly regular basis, I'd prefer we just switch to metric so I can stop thinking in both, it's annoying.

      And at 45C, you don't dress for it, you stay inside where it's air conditioned. That's Phoenix in oven season hot. (Phoenix has four seasons; summer, oven, second summer, and slightly cooler).

    61. Re:Not Sure if... by Anonymous Coward · · Score: 0

      You definitely want the gun hand in the middle of the car, because you keep your gun in the center console that way, within easy reach in case you need it.

    62. Re:Not Sure if... by DarkVader · · Score: 1

      That's for cars, 100LL is still available for airplanes.

    63. Re:Not Sure if... by Anonymous Coward · · Score: 0

      On some machines it does take tens of seconds to process. On other machines you can't count 2 seconds after entering the PIN before it is approved. The performance seems to be terminal/bank specific.

      Answer: It doesn't have to be bad. It is the choice of crap systems, their configuration, or hardware that are the problem, not the technology itself. Complain to the vendor.

    64. Re: Not Sure if... by Anonymous Coward · · Score: 0

      Japan. Around 1/3 of all merchants there only take cash. Last time I was there (5 yrs ago), they hadn't even connected their banks to the world banking networks so the only place I could withdraw money from my account was Citibank, which is connected. When it comes to money, the Japanese are luddites. FYI, they also still get most of their music from physical CD shops and books are still mostly paper there (because they are profitable industries so Apple & Amazon were told to eff off by their music and book industries, unlike the rest of the world where those industries were already losing money and had to accept A & A's horrendous deals).

    65. Re:Not Sure if... by houghi · · Score: 1

      I am talking 15 seconds for the whole transaction. That means taking out my wallet, taking the card, putting it in the slot, waiting for the beep, entering the code+ENTER, wait for the OK, take out my card, get the receipt, put the receipt and the card in my wallet and pit away my wallet, so I can pick up my stuff.

      So with you the swipe will take 1 second, the entering, waiting, pin and taking is about 4-5 seconds. So still slower, but not ny an amount that should bother anybody.

      I also have seen cards with borked magnetic strips, so there is that.

      So again: the real issue is that you did not adapt the PIN way.

      --
      Don't fight for your country, if your country does not fight for you.
    66. Re:Not Sure if... by markdavis · · Score: 1

      >So with you the swipe will take 1 second, the entering, waiting, pin and taking is about 4-5 seconds. So still slower, but not ny an amount that should bother anybody.

      No.

      With me, like everyone else in the USA, there is NO PIN. So with swiping, it would be swipe card 1 second and put it in wallet, done. If the transaction is under some large dollar amount, there is no signing or anything either.

      With chips, it is insert the card, and now stand there waiting anywhere from 5 to 20 seconds for it to eventually finish so you can finally put it back in your wallet. Net effect is, it is now annoyingly slow- we went from nearly instant to standing there holding a wallet, waiting and waiting for it to tell us to take our card out.

      >I also have seen cards with borked magnetic strips, so there is that.

      Oh, that is true. But so far it seems those are at least as reliable, based on my limited time with chips.

      >So again: the real issue is that you did not adapt the PIN way.

      There is no PIN way, we don't have PINs. Has nothing to do with me adapting, it has to do with me standing there waiting 5 to 30 times longer than I used to before I can move on to my next task. If we did have PINs, at least there would be something to do in that time that justifies the inconvenience.

    67. Re: Not Sure if... by lars_stefan_axelsson · · Score: 1

      Yes, well, the European union economy is larger, and we have a couple hundred million more people (which means more CC interactions), and we managed. For quite some time now. So I don't know why that should be an excuse.

      --
      Stefan Axelsson
    68. Re: Not Sure if... by Anonymous Coward · · Score: 0

      Admittedly it's been about 10-15 years since I last had to use the mag stripe, but I remember it taking much longer waiting for the receipt to print out, signing it, passing that back to the person behind the counter etc. etc.

      France switched to chipped cards fairly early. So if you were using a foreign card there add to the list "cashier looks at you like you're an alien, calls the manager, etc.".

      To be fair, there was a Chinese supermarket in the smaller Chinatown, and the third time I went there the checkout lady recognised me & knew what to do. Better than some Belgian cunt in Blankenberge who refused my card and threatened to call the police.

  4. Hope they get fined big for this by guruevi · · Score: 1, Interesting

    There is no reason to upgrade to chip cards except to benefit the card cartels. Forcing a small business owner to eat the fraudulent card charges is a big middle finger to these businesses, you can still fraudulently charge a chip card and the cost-benefit is just too insane for a business. Chip card transactions often not only cost more, but the readers and associated systems are a magnitude more expensive than their mag-stripe counterparts, for no good reason, I can get a Chinese chip card reader for $25, but the bank doesn't certify units under $250 and charge hefty monthly fees to use 'their' (same model) units.

    At least with a mag stripe, a developer could interface with a verifiable fully secure API, now you have to trust the banks and manufacturers not to screw with the system. To the strict letter, they can't even be considered PCI compliant because the owners have no control to change the passphrase or keys on them.

    --
    Custom electronics and digital signage for your business: www.evcircuits.com
    1. Re:Hope they get fined big for this by thegarbz · · Score: 1

      There is no reason to upgrade to chip cards except to benefit the card cartels.

      Yeah. There's also no reason to upgrade my 80s muscle car because it's only 1985. What it's not 1985? The rest of the world has adopted chip+pin for the added security? Some countries have outright banned swiping even as a fallback?

      We often joke about the USA being a backwards country, but we were only poking fun at you guys, we didn't mean it. You don't need to actually be backwards too.

    2. Re:Hope they get fined big for this by tlhIngan · · Score: 2

      There is no reason to upgrade to chip cards except to benefit the card cartels. Forcing a small business owner to eat the fraudulent card charges is a big middle finger to these businesses, you can still fraudulently charge a chip card and the cost-benefit is just too insane for a business. Chip card transactions often not only cost more, but the readers and associated systems are a magnitude more expensive than their mag-stripe counterparts, for no good reason, I can get a Chinese chip card reader for $25, but the bank doesn't certify units under $250 and charge hefty monthly fees to use 'their' (same model) units.

      At least with a mag stripe, a developer could interface with a verifiable fully secure API, now you have to trust the banks and manufacturers not to screw with the system. To the strict letter, they can't even be considered PCI compliant because the owners have no control to change the passphrase or keys on them.

      Newsflash - retailers always had to eat fraudulent charges. This is true with swipe, and even the imprint machines (which are still used).

      The chip machines shift the liability to whoever is least secure - if your bank still gave you a swipe card and the retailer can take chip, the liability shifts to the bank. If it is all the way, then liability shifts to the cardholder (for not protecting their card and PIN).

      And yes, the machines are more expensive, but not by much, because everyone by now has been making chip-enabled machines for years. Heck, I'd be surprised if 90% of the readers actually had chip support, but was disabled because the rest of the world used chip. (In Canada, this happened a few years before the chip migration - and yes, retailers had to swap their "chip capable" machines with the exact same model, because the old unit had the chip unit disabled).

      And yes, magstripe security. Yes, it was convenient to swipe at the POS and handle it all on one piece of paper. Unfortunately, Target, Home Depot, and dozens of other retailers have shown the folly of it. (Now the machines talk to the card machine and the amount is transmitted,and a success/failure is returned). The chip machines are a black box and communicate with the bank directly, so even stupid retailers can't be stupid anymore.

    3. Re:Hope they get fined big for this by spire3661 · · Score: 1

      Banking is based on trust, not absolute security. The Chip+PIN combo i have been subjected to is incredibly inconvenient only to push the liability to my side of the table. It is not any more secure. The only one benefiting from this whole thing is the credit card companies.

      --
      Good-bye
    4. Re:Hope they get fined big for this by citylivin · · Score: 1

      "There is no reason to upgrade to chip cards except to benefit the card cartels."

      Are you high? Chip and Pin, the standard for most of the world, works perfectly fine and the reason it is implemented is to protect the merchants! Right now if i go to USA and swipe my card, a fucking signature(!!!) is all the authentication that you need!

      This isn't the 1970s, my god. I couldn't even believe how much fraud I could have done with basically zero effort down there. I can't believe that there isn't massive credit card fraud in the USA. Sure, chip cards can be cloned and pins can be captured with hidden cameras, but thats orders of magnitude more effort than simply stealing someones card number and faking their signature. It would be like vendors accepting personal cheques! Mag stripes are relics from a bygone age.

      And if you cant program for chip and pin cards, you need to refresh your skills. Every POS software I have worked with in the last 5 years at least, is chip and pin. You get around all PCI compliance issues because cc numbers are never stored or transmitted in plain text anything at any point. The pin authorizes the card at the pinpad and simply transmits a pass or fail to the bank, encrypted. The payment processor has an agent installed on the PC if they are integrated. Or so I understand, i just service them, not a programmer. But the systems are ubiquitous.

      --
      As a potential lottery winner, I totally support tax cuts for the wealthy
    5. Re:Hope they get fined big for this by Anonymous Coward · · Score: 0

      > The chip machines shift the liability to whoever is least secure - if your bank still gave you a swipe card and the retailer can take chip, the liability shifts to the bank. If it is all the way, then liability shifts to the cardholder (for not protecting their card and PIN).

      In the US, the cardholder legally cannot be held liable for more than $50, and all major credit card issuers have promised to cover that. That's part of the reason why the US uses signature instead of PIN- there's not as much benefit for the banks to make us use PINs.

    6. Re:Hope they get fined big for this by amicusNYCL · · Score: 1

      There is no reason to upgrade to chip cards except to benefit the card cartels.

      Do you realize that most of the rest of the world, including places like Africa, Latin America, and the Caribbean, has been using this since 2005? Hell, France was doing it in 1992. The only reason the US switched at all is because credit card fraud had finally reached the tipping point around 2012 when banks finally figured out that it was going to be cheaper to switch everything than it would to cover the increasing cost of the fraud.

      Here you go:

      Most card fraud occurs in the United States. In fact, a 2015 research note from Barclays stated that the U.S. is responsible for 47 percent of the world’s card fraud despite only accounting for 24 percent of total worldwide card volume.

      The high level of debit and credit card fraud in the United States also impacts other countries. Among U.K.-issued cards in 2015, 35 percent of fraud-related losses occurred in the United States, compared to 10 percent in France and Australia, 9 percent in Canada and 6 percent in Germany.

      Cross-border fraud occurs when criminals use a consumer's credit or debit card data in one country to make fraudulent transactions in another country. In 2014, 47 percent of fraudulent cross-border transactions on U.K. credit cards took place in the United States.

      U.S. credit card fraud is on the rise, too. About 31.8 million U.S. consumers had their credit cards breached in 2014, more than three times the number affected in 2013.

      That fraud isn't cheap. Nearly 90 percent of card breach victims in 2014 received replacement credit cards, costing issuers as much as $12.75 per card.

      Most experts believe that the reason the U.S. has a disproportionately high amount of fraud is because it has been slow to adopt EMV, a global standard in which credit cards carry computer chips that cut down on counterfeiting by dynamically authenticating card transactions. Countries that have deployed EMV have enjoyed a decrease in counterfeit fraud as a result -- 70 percent in the U.K., for example, between 2005 and 2013.

      --
      "Our two-party system is like a bowl of shit looking at itself in a mirror." - Lewis Black
    7. Re:Hope they get fined big for this by guruevi · · Score: 1

      Although I agree that 'something has to be done', the chip cards in the US at least are no more secure than mag stripes. If you ever have the chance to hook a chip reader to a computer, you can read most of the data from a chip, unencrypted, the same way you do from a mag stripe (primarily for compatibility reasons). Hell, I have a fully encrypted card and it's useless at many large retailers in the US, my parents came here from Europe with their non-magstripe card which was completely useless even though it was issued as international by MasterCard, except for Tim Hortons (for whatever reason) the readers at Walmart and other places simply refused to work and the machine asked to swipe (on a non-magstripe card lol)

      Additionally, there have been papers that describe how to abuse and crack the chip cards, the encryption on these things is about 2-3 decades old by now. On the other hand there are hundreds if not thousands of reports of these chip-and-pin countries (like Netherlands and France) of people that got fraudulently charged but because it was 'chip and pin' now the consumer has to eat the cost.

      As far as USian sources: http://www.washingtontimes.com...

      --
      Custom electronics and digital signage for your business: www.evcircuits.com
    8. Re:Hope they get fined big for this by lgw · · Score: 2

      Chip and signature is not chip and PIN. Nothing you said is relevant to the US. This "upgrade" has downsides and no upside for the consumer.

      But do go on about the entirely unrelated system you like.

      --
      Socialism: a lie told by totalitarians and believed by fools.
    9. Re:Hope they get fined big for this by petermgreen · · Score: 1

      The chip machines shift the liability to whoever is least secure - if your bank still gave you a swipe card and the retailer can take chip, the liability shifts to the bank

      What i've always wondered is what happens if a criminal clones a chip card onto a magstripe only card.

      Is there some mechanism to warn the merchant in this case or does the merchant get screwed for doing a magstripe transaction on a clone of a chipped card?

      --
      note: i'm known as plugwash most places but i screwd up registering that here somehow in the past and now can't register
    10. Re:Hope they get fined big for this by mattack2 · · Score: 1

      I realize this is indirect, and not directly related to switching to chip cards.. The new readers ALSO allow (if the business has the functionality turned on) NFC based payment (e.g. Apple Pay, etc.). With that, the business gets the lower fee version due to lower fraud possibility PLUS it's faster than the insert-chip-card-and-wait, or even the swipe method (due to not having to take out your card).

    11. Re:Hope they get fined big for this by marka63 · · Score: 1

      The mag stripe says this is a chip card and the terminal will request that you use the chip reader.

      You need to modify the data when cloning.

      The next step will be to not accept swipes once the pos terminals are upgraded.

    12. Re:Hope they get fined big for this by thegarbz · · Score: 2

      The Chip+PIN combo i have been subjected to is incredibly inconvenient only to push the liability to my side of the table. It is not any more secure

      Except for everywhere in the world where chip+pin has been implemented where the liability has not changed, the transaction is processed at a MUCH faster rate and the added security has decimated credit card fraud.

      But other these little things your post was ... errr.... grammatically correct?

    13. Re:Hope they get fined big for this by spire3661 · · Score: 1

      I was relating my experiences so far, in the US rollout of the Chip+PIN. Perhaps the Chip and PIN we have is different. Its slow, inconvenient and not at all universal.

      --
      Good-bye
    14. Re:Hope they get fined big for this by thegarbz · · Score: 1

      Perhaps the Chip and PIN we have is different

      This sounds like it may be an understatement. I'm not sure on the specifics but there's definitely differences starting with the name Chip + Signature.

  5. Good by somenickname · · Score: 4, Insightful

    This "upgrade" is a complete farce. If they had moved to chip and pin then, yes, it would make sense for all businesses to adopt it. As it is, they moved from a "something you have" model to a slower "something you have" model. Without a "something you have and something you know" model, the upgrade is mostly just an inconvenience to all involved parties (except the credit card companies who can now defer more blame).

    1. Re:Good by Hylandr · · Score: 1

      +1 insightful Pls.

      --
      ~ People that think they are better than anyone else for any reason are the cause of all the strife in the world.
    2. Re:Good by Xenx · · Score: 2

      While chip alone may not be as secure as chip and pin, it is still more difficult to skim than the magnetic stripe. Further, the hardware change to chip is still required for chip and pin. It can always be implemented at a future point when the hardware migration is complete.

    3. Re:Good by Anonymous Coward · · Score: 0

      Chip and Pin is horseshit too. Chip and Pin was just another system that attempted to absolve banks and CC processors from responsibility of securing their systems.

    4. Re:Good by naubol · · Score: 1

      https://www.citi.com/credit-cards/credit-cards-citi/citi.action?ID=chip-technology-questions

      How is it a complete farce if the chip is more secure? My understanding is that the magnetic strips were frequently swiped into card readers in order to steal, but the chip is harder to steal in this way. To use your terminology, it moves from a model where it's "something you can both have" to a model where "only one of you can have it."

      --
      Reality is a slackware box running on a 386 tucked away in god's sock drawer.
    5. Re:Good by PrimaryConsult · · Score: 2

      I have a (apparently rare) US issued chip and pin card - I didn't even ask for the pin, the bank offered me the one time option of setting it, which I did. If I use it in any of these terminals, or anywhere in Canada, it actually prompts for the PIN. So while chip and signature is the "norm" with these new readers, the only roadblock for chip and pin is now the card issuer thanks to the mandate that the readers be upgraded.

    6. Re:Good by Anonymous Coward · · Score: 0

      While chip alone may not be as secure as chip and pin, it is still more difficult to skim than the magnetic stripe.

      New Security Flaw in Credit Card Chip System Revealed
      by Jose Pagliery
      August 5, 2016: 1:04 PM ET

      Computer researchers claim to have found yet another flaw in the upgrade to the chip-based credit cards in the United States.

      The chip on these credit cards have been praised for making them nearly impossible to counterfeit. While the cards also contain a magnetic strip, that strip is supposed to tell the payment machine to use the chip.

      But there's a relatively easy way to knock down that safeguard.

      Computer security researchers at the payment technology company NCR demonstrated how credit card thieves can rewrite the magnetic stripe code to make it appear like a chipless card again. This allows them to keep counterfeiting -- just like they did before the nationwide switch to chip cards.

      They presented their findings at the Black Hat computer security conference on Wednesday.

      This claim of a glaring hole in EMV, the chip-based system, is possible because of the way many retailers are upgrading their payment machines: They're not encrypting the transaction.

      "There's a common misperception EMV solves everything. It doesn't," Patrick Watson, one of the researchers, told CNNMoney.

      On Thursday, a banking and retail industry group that monitors the EMV system cast doubt on the theory.

      "If the data on the magnetic stripe is altered it might fool the terminal," said U.S. Payments Forum director Randy Vanderhoof. But on the back end, the system would "reject the transaction."

      But the discovery of this possible flaw bolsters the retail industry's complaints against the upgrade, which was forced upon shops by banks.

      The National Retail Federation has long complained about the upgrade, which is estimated to cost American retailers $25 billion.

      This latest research shows that retailers could spend millions of dollars upgrading to EMV and still not protect their customers from a massive credit card theft like the Target and Home Depot hacks two years ago.

      Adding to the problem, payment terminal makers keep producing machines that don't have the encryption by default.

      And vendors who sell and install these machines at shops don't simply flip the switch and turn on encryption. Retailers have to pay extra for basic security.

      The major machine makers, Verifone and Ingenico, both asserted they offer point-to-point encryption on retailer's machines -- but it's up to retailers and their partners to turn it on.

      Currently, retailers focus on protecting the computer network that support their payment system. But that leaves the actual conversation between your credit card and the machine in plain text, readable to any hacker who breaks into the system.

      It's a mistake, said Mike Weber, vice president at the IT auditing firm Coalfire.

      "They're assuming the environment is okay," he said. It's not.

      During their presentation, the NCR researchers advised shops to "encrypt everything" in a transaction. They also said consumers should pay with special apps on their phones and watches whenever the high tech option is available.

      CNNMoney (Las Vegas)
      First published August 3, 2016: 9:02 PM ET

    7. Re:Good by Anonymous Coward · · Score: 0

      And still are, I've yet to receive a card that ONLY has a chip and no mag stripe.

      I agree chip and sign blows

      Chip and pin would be better but if you still produce the cards with a mag stripe then you defeat the whole purpose. Also if you have this fancy CHIP it would also be helpful to stop writing the card number on the card with the exp. and CVV2. How about just a chip that would be safer.

    8. Re:Good by somenickname · · Score: 1

      While chip alone may not be as secure as chip and pin, it is still more difficult to skim than the magnetic stripe.

      I don't doubt that it's "more difficult" but, after a few years, will it prove to be "less frequent"? Probably not. If someone is determined to commit credit card fraud, the security that the chip provides is just a new technology to adapt to.

      Further, the hardware change to chip is still required for chip and pin. It can always be implemented at a future point when the hardware migration is complete.

      That's reasonable. But, they made the switch without adding the security part. If you are going to the trouble to redo the infrastructure of credit card processing, why not, I dunno, make it more secure while you do it? It's not like entering a PIN number is a foreign concept to people.

    9. Re:Good by marka63 · · Score: 1

      The moved it to from a something that can be cloned to something that can't be cloned.

      It would be better if they moved it to something that can't be cloned + something you know.

    10. Re:Good by marka63 · · Score: 1

      And the next step is to just stop supporting swipe only transactions like some countries have already done.

    11. Re:Good by Xenx · · Score: 1

      That's reasonable. But, they made the switch without adding the security part. If you are going to the trouble to redo the infrastructure of credit card processing, why not, I dunno, make it more secure while you do it? It's not like entering a PIN number is a foreign concept to people.

      Honestly, because people hate change. It's going to be easier to force one change on people than two. I don't know what other reasons were involved, but that can be a big one. We want things to just work, and work like they always have. For most people, credit card fraud is someone else's problem. People only want security as long as it doesn't inconvenience them.

    12. Re:Good by Larry+Lightbulb · · Score: 1

      Who issued it? I've been trying for years to get one.

    13. Re:Good by taustin · · Score: 1

      The part that isn't talked about much, and not yet a mandatory part of the system, is the point of point encryption that goes hand in hand with EMV. When fully implemented, the store never sees any card information at all, it's all tokenized. That means that when somebody breaks into their network, there's nothing there to steal.

      That is the point of EMV. It's got nothing to do with protecting the consumer. It's about reducing losses for the banks.

    14. Re:Good by slomike1 · · Score: 1

      Many people do not have or know the pins for their credit cards. They likely know their ATM card, but that is about it.

    15. Re:Good by Anonymous Coward · · Score: 0

      While they failed on the security part, they at least said that if you follow our protocol then we will take the risk, if you refuse then the risk is on your head.

    16. Re:Good by Loconut1389 · · Score: 1

      It also does nothing to stop the clerk or anyone from writing down your number, exp, and cvv2 and going on to amazon. I don't know how to fix that without requiring computers have chip readers too, which honestly would be a good move and open people up for chip based authentication/login... Or otherwise coming up with another way with an authentication token and an api provided by the card companies or something, in conjunction with a TOTP or HOTP physical device.

    17. Re:Good by Anonymous Coward · · Score: 0

      What, no pins? That's weird... You mean to say the US went from 'what I have and what I know' to only 'what I have'? That doesn't sound right...

    18. Re:Good by Anonymous Coward · · Score: 0

      Just curious, as long as the cards still have the magnetic stripe, what's preventing them from being cloned?

    19. Re:Good by PrimaryConsult · · Score: 1

      First Niagara... which is about to be eaten by Key Bank, so I don't know if they'll still offer it (I know they do not for their own customers). Those of us 'grandfathered in' will get to keep it though until the card expires. I have no idea if I'll be able to change the pin, either.

      It was the only credit card that worked in the machines to refill my Opal card [transit pass] in Sydney... so I'd much rather keep it working.

    20. Re:Good by PrimaryConsult · · Score: 1

      Sorry for the second reply, but here is the article about First Niagara choosing pin over signature as well as their press release.

      Apparently it is unique in the US in that it will *only* do PIN if you use the chip. Swiping still works for signature, of course.

      Chase was almost going to but backed down at the last minute. Almost all other chip and pin are chip+signature+pin ones from my research, and it will choose signature over pin.

    21. Re:Good by Anonymous Coward · · Score: 0

      >As it is, they moved from a "something you have" model to a slower "something you have" model.

      No, they moved from a "something you have or data from a previous transaction" model, to a slower "something you have" model.

    22. Re: Good by Anonymous Coward · · Score: 0

      Why would a store owner care if chip+ship is not secure? The cc company will pay for fraud, not the store owner.

    23. Re:Good by LordLucless · · Score: 1

      Nothing's stopping people from cloning the strip. Which is why they're trying to get merchants to use the chip instead.

      --
      Just because you're paranoid doesn't mean there isn't an invisible demon about to eat your face
    24. Re:Good by Cro+Magnon · · Score: 1

      I don't know the PIN (if any) for my credit card because I've never used it. If I used one on a regular basis, I'd remember it.

      --
      Slow down, cowboy! It has been 4 hours since you last posted. You must wait another few hours.
    25. Re:Good by Anonymous Coward · · Score: 0

      What you just stand there and watch someone write down your numbers without stopping them? If the place is still using swipe at say a restaurant, then they could walk away with your card. But as swipe dies out that will stop happening.

    26. Re:Good by Anonymous Coward · · Score: 0

      My signature is something I know.

      The problem is, nobody else knows it, so nobody else can judge whether it's correct or not.

      Then again, in the US, most card transactions are cached for off-peak batch processing anyway, so the PINs aren't exactly verified on the spot either. No, not even for debit cards (which do use a PIN and have always done so).

  6. How can a judge force a CC company... by mark-t · · Score: 1

    ... to accept the business of a company that doesn't want to do things the way the CC company requires?

    1. Re:How can a judge force a CC company... by PopeRatzo · · Score: 1, Informative

      How can a judge force a CC company to accept the business of a company that doesn't want to do things the way the CC company requires?

      Because they are a federally subsidized and insured bank with monopolistic allowances.

      If you want to be able to borrow money at 0% and lend it at 20%, then fuck you, do as you are told.

      --
      You are welcome on my lawn.
    2. Re:How can a judge force a CC company... by Anonymous Coward · · Score: 0

      Because Visa and MasterCard have a duopoly and get special protection from the government thus they have to agree to play by the rules. Because the government destroyed any competition to their duopoly and puts people in prison for even trying, they should follow the rules. Look at Costco. They hate their customers so much they no longer allow them to use a good credit card. They force a horrific one down our throats. Also, they illegally took charges from our AmEx cards and put them on our crappy new card without telling us thus generating hundreds of thousands of credit dings since they didn't notify us that we had a new card with money owed. I had to pay a higher rate on my mortgage because Costco did this. I looked into suing, but my lawyer said the credit card agreement from Costco allowed them to register new credit cards in my name and move charges onto it without our permission. Costco is going to cost me nearly $5k in interest, but they don't care since they're supporting the duopoly. That is all they care about is making sure the banks destroy all competition. They're in bed with the banks and hate their employees and their customers

    3. Re:How can a judge force a CC company... by mark-t · · Score: 1

      Let's say I'm a CC company, and I notice that I'm taking a substantial hit on my profits because of fraudulent transactions traceable to not securing transactions in a certain way, If I decide that I'm going to try and secure my transactions that way to avoid the loss, while still being willing to take hits for fraudulent transactions that occur with the new method, why should I continue to take the financial hit for companies that don't want to use the newer system?

    4. Re:How can a judge force a CC company... by Anonymous Coward · · Score: 0

      You can. As an individual company. Because others can then go to the other companies if they want. Conspiring with the other companies to do that, that's a problem.

      That's what they're alleged to have done.

      Now if they'd gotten Congress to pass it as a law, it'd be another story.

    5. Re: How can a judge force a CC company... by Anonymous Coward · · Score: 0

      $5000 in interest? You really should examine your spending and quit living beyond your means.

    6. Re:How can a judge force a CC company... by mark-t · · Score: 1

      Even if they *had* collaborated (or "conspired", as you say) on the idea, why should they be forced to continue to take a financial hit on a system that they don't even want to continue to support in the first place? Are you suggesting that they conspired to take financial losses with the other method? I hope you realize how ridiculous that sounds.

    7. Re:How can a judge force a CC company... by Holi · · Score: 1

      In what way are VISA Master Card or AMEX subsidized?

      --
      Sorry, teleporters just kill you and then make a copy. A perfect, soul-less copy.
    8. Re:How can a judge force a CC company... by Holi · · Score: 1

      They are responsible for fraudulent purchases over $50 by law, so why do we deny them the opportunity to secure their payment system. Or should they just stop their business?

      --
      Sorry, teleporters just kill you and then make a copy. A perfect, soul-less copy.
    9. Re:How can a judge force a CC company... by Holi · · Score: 1

      Collaboration does not equal conspiracy. None of this was done behind closed doors, none of this was a surprise, and most of all none of this was illegal.

      --
      Sorry, teleporters just kill you and then make a copy. A perfect, soul-less copy.
    10. Re: How can a judge force a CC company... by Anonymous Coward · · Score: 0

      5000 additional interest on a mortgage is not out of range.

    11. Re:How can a judge force a CC company... by Anonymous Coward · · Score: 0

      Collaboration does not equal conspiracy. None of this was done behind closed doors, none of this was a surprise, and most of all none of this was illegal.

      That's for the defendants to argue, the plaintiffs will nonetheless argue otherwise, and the judge found they had a plausible case for it. Which is a lower standard than proof, but getting more is later.

    12. Re:How can a judge force a CC company... by Anonymous Coward · · Score: 0

      Visa and Master Card are NOT responsible for fraudulent purchases. The card issuer that signed with Visa and Master Card is responsible for fraudulent purchases. Community financial institutions e.g. credit unions, community banks, and regional banks, have delaying EMV deployments because for many of them, the implementation will generally cost more than 3 years worth of fraud and it's not uncommon for it to be more than 5 years worth of fraud.

    13. Re:How can a judge force a CC company... by Anonymous Coward · · Score: 0

      I'm not suggesting anything, even a resolution to the problem. I'm not a plaintiff in the suit, so I'm not required to make a case for resolution anyway, I even pointed out that it was an allegation that they conspired together.

      That is a problem, hence the lawsuit. The plaintiffs have made a plausible case, so now the judge will let it go to trial. Now the plaintiffs have a chance to show there was a conspiracy, not a collaboration, a conspiracy, where they can attempt to demonstrate the harm they suffered due to that conspiracy

      But as I said, if they had collaborated in lobbying, it'd have been another story. But apparently they didn't.

    14. Re:How can a judge force a CC company... by PopeRatzo · · Score: 0

      In what way are VISA Master Card or AMEX subsidized?

      They are subsidized by the Fed, who loan them money at 0% and by the government, which allows them to turn around and lend that free money at >20%.

      And, they're subsidized by having capital requirements of less than 5%, so they can take the same dollar and loan it out 20 times.

      The card companies are only proxies for their member institutions, remember.

      --
      You are welcome on my lawn.
    15. Re:How can a judge force a CC company... by mark-t · · Score: 1

      All they had allegedly "conspired" to do was simply to have the same effective date past which they would no longer support the older method... a method that they had assessed to be less secure, and there is no sane reason that they should ever be obligated to continue to support the older system after they have given plenty of advance warning of the change, both to consumers and vendors, even if they *did* secretly agree upon an effective date of implementation (although how you call something that they publicly announced years ago a secret is beyond me). There is no way that this could reasonably be considered illegal or unfair because the newer system is considered less likely to have fraudulent transactions in the first place.

    16. Re:How can a judge force a CC company... by david_thornley · · Score: 1

      Some posters have claimed that the credit card companies are not only involved in setting the chip deadline, but also were cozy with the companies that make the machines, which apparently cost a lot more, and and require certification that they don't provide in a timely manner, so it has been impossible for quite a few businesses to get their chip machines operating by the deadline.

      As a credit card user, I wouldn't mind a class action suit against the companies that slow down the chip payment process (it isn't the retailers, it's too universal for that).

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    17. Re: How can a judge force a CC company... by Anonymous Coward · · Score: 0

      Ah, but one of their complaints is that despite purchasing the equipment, the companies have not enabled it for them, which mean they are being penalized even though the fault isn't on their end.

      And that they all knew it, makes it a conspiracy.

    18. Re:How can a judge force a CC company... by mark-t · · Score: 1

      The october 2015 deadline was announced in the latter half of 2011, with Amex and MC announcing the same deadline in early 2012. There was no lack of time to make the switch. Some retailer are even being given until 2017 owing to the expense of completing the switchover (most notably involving fuel pump card readers).

    19. Re:How can a judge force a CC company... by Anonymous Coward · · Score: 0

      How can a judge force a CC company... to accept the business of a company that doesn't want to do things the way the CC company requires?

      Pretty simple, actually, if the CC company is breaking the law.

      Doing business in any legal system is always conditional on following the law. There are many options for the courts to force compliance.

      Given how few credit card companies there are, the conduct of those companies is a matter of particular concern to the public, and hence the question arises as to whether that conduct is consistent with rights "retained by" the people (9th Amendment) or "reserved to" the people (10th Amendment).

      I can tell you that the some of major banks issuing credit cards are violating fundamental rights. It happens on a routine basis, much as is the case for certain government agencies that are also routinely violating fundamental rights. Both groups tend to shield themselves behind the high costs of litigation and bought politicians. Sooner or later, however, this will probably piss off enough people to force change - or somebody with sufficient funds will decide to do something about the problem.

      In addition to the Bill of Rights, there are also lessor laws - such as those enacted by Congress - that may be applicable.

    20. Re:How can a judge force a CC company... by Anonymous Coward · · Score: 0

      Apparently it wasn't enough time, as the plaintiffs are going to argue, and the conspiring companies knew that, which is why they set the date, so they could advantage themselves from it.

      One of the perils of NOT acting independently, you get suspected when things coincide.

    21. Re:How can a judge force a CC company... by david_thornley · · Score: 1

      When did machines and software systems become available to retailers? What about certification? Knowing doom is coming doesn't help if nobody's going to sell doom-proof underwear for another few years.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    22. Re:How can a judge force a CC company... by mark-t · · Score: 1

      The only way the CC companies would see any financial advantage from this is if a retailer that regularly allowed fraudulent transactions to go through continued to do so after the CC company shifted liability to them.

      You may be right about it not being enough time, however.

  7. was there a double dip? by um...+Lucas · · Score: 2

    I can't figure out why retailers would refuse new terminals, unless they were being asked/demanded to pay for them.

    If these new terminals are trully going to save the credit card companies so much money, it ought to have been a no brainer to provide them to retails on their own dime and see the return on investment come over time, rather than, essentially, demand the retails make investments solely for the credit card companies benefit (with the exception that if the cc co's are going to turn liability over to the retailers, then, yes, they would stand to save their own money, but only because of a change in business dynamics)

    Again, I could just be shooting in the dark as I didn't read the article, just chiming in with an opinion and nothing to back it up, which is what slashdots all about, right? :)

    1. Re:was there a double dip? by Njorthbiatr · · Score: 1

      The retailers can just decide not to use them.

    2. Re:was there a double dip? by Phantom100 · · Score: 1

      My understanding is that the chip enabled terminals were not being made fully functional for the retailers, but they were still being forced to accept liability.

      http://www.nytimes.com/2016/03...

      http://blog.credit.com/2016/03...

    3. Re:was there a double dip? by Anonymous Coward · · Score: 0

      Having heard about this before, the issue is essentially that the credit card companies have pushed the burden for fraudulent charges onto the merchants if they aren't using terminals that accept the chip cards. The merchants are claiming that the credit card companies have deliberately been dragging their feet in certifying new terminals, so that the merchants can't get the new terminals even if they want to, and this is all so that the credit card companies can trouser the money that they would normally be paying out to reimburse the merchant for fraudulent charges.

    4. Re:was there a double dip? by Anonymous Coward · · Score: 0

      And credit companies can just decide to pay for them.

    5. Re:was there a double dip? by Anonymous Coward · · Score: 0

      2/3 of my daily business is via credit card.

      Turning away most of my business is not an option... it's a strong arm tactic.

  8. In the UK, we've had chip and pin for years! by Anonymous Coward · · Score: 0

    It works well, efficiently, quickly and I'd be shocked if I came across a retailer that only took magnetic stripe. I literally cannot remember the last time I signed for something, it seems arcane. I can't believe Americans are fighting against it. Faking a magnetic stripe is piss easy, I imagine copying a chip is quite challenging in comparison. I feel no compassion for these retailers, whether the word of the law is broken or not, this seems stupid.

  9. Wow by Anonymous Coward · · Score: 0

    US banking is so behind...

    All point of sale machines have read chips in Canada for YEARS.

    Also, stores in the US still accept checks...

  10. Enter the 21st century, get sued? by thegarbz · · Score: 4, Interesting

    I mean it's high time that the USA got dragged kicking and screaming into the 2000s, but to sue the banks over it as well? I mean the USA has the current second highest amount of credit card fraud in the world behind Mexico who are also still in an age where they are marvelling about this fancy new thing called the internet.

    Being forced to upgrade to something which in every other country in the world has caused a significant drop in credit card fraud is a damn good thing, not a sueable offence.

    1. Re:Enter the 21st century, get sued? by Anonymous Coward · · Score: 0

      Retailers brought it on themselves. They refuse to check ID, they refuse to check signatures, and they refuse to check if the last four digits match the magnetic stripe data. I realize it's possible to confirm all of these and still get defrauded, but they liked the speed of getting customers through the line without doing anything to confirm it's a valid payment and let the banks take the hit.

    2. Re:Enter the 21st century, get sued? by Anonymous Coward · · Score: 0

      We have laws against the major players colluding and forcing their will upon those they have a monopoly over. In theory, anyway.

      I don't think anyone would have sued if the chips weren't slow as dog shit most of the time.
      Also, none of the ones I've seen yet have done away with the need for either a PIN or signature. It's irritating the customers one after another in most of the places I have shopped lately, and it should have been "more optional" until the bugs have been worked out.
      So, to break it down:
      Customers: Slower. More confusing. Do I still need to sign? Do I use my PIN code if it's debit? Oh, I still swipe if it's debit here? But at the last place I was at, I had to use the chip for my PIN code. Why is it different here?
      Retailsers: Slower multiply by 3x due to the interaction above.

    3. Re:Enter the 21st century, get sued? by Anonymous Coward · · Score: 0

      Meanwhile we're still using paper checks, can't make personal account to account direct transfers, And, oh yeah, the majority of our power lines are still swinging in the wind and getting knocked down by falling trees instead of being buried. But at least we're still #1. USA USA USA.

    4. Re:Enter the 21st century, get sued? by Anonymous Coward · · Score: 0

      But we DIDN'T upgrade to what everyone uses. It is some half-ass setup that benefits the CC processors without much gain for anyone else and several downsides.

      Our usual response it seems.
      We need X to modernize. We have Y it works-dont wanna change. OK, then we'll do 1/2X+1/4Y+1/4Z then instead which is a little better and ALMOST works....

    5. Re:Enter the 21st century, get sued? by stephanruby · · Score: 3, Insightful

      Being forced to upgrade to something which in every other country in the world has caused a significant drop in credit card fraud is a damn good thing, not a sueable offence.

      The new chip system in the US works differently than the chip system in Europe, so no, the US isn't being forced to adopt what the rest of the world is already using.

      For instance, in France I can use a European chip card in a restaurant in the middle of nowhere where there is no cell phone reception (or no landlines), and the transaction gets reconciled later when the transactions get uploaded. In the US, under the new system, no one is allowed to keep the data around for later reconciliation, even in an encrypted form, so that means that the multitudes of authentication handshakes must occur correctly before the transactions get authorised (even if the amounts in question are tiny).

      This is why using smartcards in Europe takes no time at all to get authorized, they're actually faster than magnetic debit/credit cards. But this is also why the current smartcards in US (when used through the chip) are so slow, although in theory they're supposed to be more secure than the European smartcards.

    6. Re:Enter the 21st century, get sued? by radarskiy · · Score: 2

      "They refuse to check ID"
      Retailers are prohibited from checking ID, unless specifically requested by the bank.

      "they refuse to check signatures"
      The signatures on the card are not for authentication purposes. Also, there's no way a minimum wage clerk is going to be able to do handwriting recognition.

    7. Re:Enter the 21st century, get sued? by jittles · · Score: 4, Informative

      Being forced to upgrade to something which in every other country in the world has caused a significant drop in credit card fraud is a damn good thing, not a sueable offence.

      The new chip system in the US works differently than the chip system in Europe, so no, the US isn't being forced to adopt what the rest of the world is already using.

      For instance, in France I can use a European chip card in a restaurant in the middle of nowhere where there is no cell phone reception (or no landlines), and the transaction gets reconciled later when the transactions get uploaded. In the US, under the new system, no one is allowed to keep the data around for later reconciliation, even in an encrypted form, so that means that the multitudes of authentication handshakes must occur correctly before the transactions get authorised (even if the amounts in question are tiny).

      This is incorrect. The US requirement for "Online Only" is strictly for fraud liability. You can use offline PIN in the US (though it can be attacked). Furthermore, all EMV cards, including those issued in France have what is called a velocity limit on the card. When this limit is hit, the card itself requires the next transaction to go online no matter what. If the terminal tells the card that it cannot go online, then the card itself will either reverse a pending ARQC (online request) or will just immediately return an AAC (decline). This is true in all regions where EMV has been implemented.

      This is why using smartcards in Europe takes no time at all to get authorized, they're actually faster than magnetic debit/credit cards. But this is also why the current smartcards in US (when used through the chip) are so slow, although in theory they're supposed to be more secure than the European smartcards.

      This is also incorrect. The chip transactions in the US are slow because most banks have insisted on implementing EMV incorrectly. A properly configured terminal will process an EMV request in 1-2 seconds in the US. That's not (noticeably) slower than an offline approval. It is literally a few hundred milliseconds longer.

    8. Re:Enter the 21st century, get sued? by Anonymous Coward · · Score: 0

      Being forced to upgrade to something which in every other country in the world has caused a significant drop in credit card fraud is a damn good thing, not a sueable offence.

      Sorry but you are factually incorrect.

      Although I would only need to list one other country using a different system to disprove your "every" qualification, I can do you one better.

      EVERY EU member country uses chip and pin, despite your claims that they do not.
      That's what, a hundred countries?

      Not to mention Japan, Australia, even Russia all use chip and pin, despite your claims that they do not.

      Can you even name a single country that does not use chip and pin other than the US and Mexico?
      The US and Mexico are not "every country in the world".

    9. Re:Enter the 21st century, get sued? by Anonymous Coward · · Score: 0

      Moreover, merchants need the very same terminals anyway to accept bank cards, which switched to EMV chips many years before credit cards did.

    10. Re:Enter the 21st century, get sued? by thegarbz · · Score: 1

      The slower and more confusing thing is only because Americans are somehow incapable of remembering 4 digits, and are also incapable of making a single switch.
      I mean at least write the 4 digits on the card then you'll be no worse in security as what you have now.

      As for confusing about swipe vs chip, that shouldn't be confusing. In the rest of the world it was chip if you have it. Any attempt at swiping a chipped card would result in a message on the terminal saying "insert card" and an arrow pointing to the chip.

      Mind you in the USA do retailers pay for the cost of the reader or are they leased by the banks like in the rest of the world? Because those large pieces of crap including touchscreen and 10 bloody confirmation messages when you use them are both annoying and look expensive as heck compared to the traditional machines which look the same as they always did in the rest of the world.

    11. Re:Enter the 21st century, get sued? by thegarbz · · Score: 1

      And, oh yeah, the majority of our power lines are still swinging in the wind and getting knocked down by falling trees instead of being buried.

      There's a good reason for that, and if you want validation of your choices I can send you my monthly electricity bill for comparison.

      I've lived in several countries which decided that power outages were intolerable during my stay. In each the electricity price has rise by a factor of about 7. Burying stuff isn't cheap.

    12. Re:Enter the 21st century, get sued? by Anonymous Coward · · Score: 0

      Chips have been in use (even) in Brazil for years. The readers clearly are using cellular networks for connectivity, and still the payment does not take more than maybe 20 seconds to complete.

      In Europe, I think chip cards came already more than ten years ago.

      It's sometimes funny to compare the US systems to the rest of the world. Yes, there's the Silicon Valley (that runs on H1-Bs), SpaceX and Tesla, but step a bit further away and it is Medieval, technologywise...

    13. Re:Enter the 21st century, get sued? by Anonymous Coward · · Score: 0

      Hmm I make account to account direct transfers all the time, you just have to know how. Overhead power lines are not unique to the US by any means. But feel free to keep complaining about non-issues.

    14. Re:Enter the 21st century, get sued? by david_thornley · · Score: 1

      There's nothing wrong with the US customers. There's no point in remembering four digits, since almost nobody accepts chip & pin. Swiping is a one-second action that keeps my card in my hand at all times. Using the chip is a slow process in which my card sits in the machine. If someone leaves their card in the machine and walks away, there's no reason some other person couldn't grab the card, and since it's chip and signature rather than chip and pin the card would work for anyone.

      If you want to criticize something about US card processing, there's plenty of blame, but blaming US shoppers for not using capabilities that aren't enabled or not wanting to switch to a considerably less convenient transaction method is just wrong.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    15. Re:Enter the 21st century, get sued? by david_thornley · · Score: 1

      One neighborhood over, the lines are buried, and I'm not aware that they get charged any more. The electric company publishes its rates. Is it that much more expensive?

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    16. Re:Enter the 21st century, get sued? by david_thornley · · Score: 1

      We make account-to-account transfers, although they really aren't convenient.

      Then some friends of ours needed a substantial loan fast, and transferring a few thousand from one of our accounts to theirs was going to be slow and expensive. We wound up sending them a check.

      (They'd asked us to cosign, but I don't do that with friends. If I lend money to friends, I don't want to have to think about it afterwards. Nor do I lend more money than I'm willing to lose, since I'm not going to trash a friendship over money.)

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    17. Re:Enter the 21st century, get sued? by thegarbz · · Score: 1

      That's because the utilities don't discriminate on the final link. The costs are spread out over the country. New neighbourhoods are cheaper to plumb with electricity than old ones where utilities play dodge the services as they try and cut users over. Not that it matters. Gold plating may sound like it's good on a neighbourhood scale, but it gets done on a state scale.

      Yes it's that much more expensive. When a politician says "we must not tolerate outages" expect a several fold increase in prices over a couple of years. Or maybe not, a recent example from South Australia which had a state wide outage due to many downed powerlines shows politicians reaching a new peak stupid and blaming solar and wind power for the outage. So maybe their stupidity is at an internal stalemate where they can't do any more damage.

      In any case power outages where I lived went down, but really they weren't that high to begin with. In serious weather the cities I lived in had at most 1% of the population without power for maybe 1-5 days per year, and rarely more than 2 days in a row (in which case the utilities at least when I lived in Australia were forced to compensate home owners). When I left we were lucky to have a single day outage in any given year. Hurrah. Wasn't worth the doubling of my electricity bill though. It was nice not having overhead lines in many streets though, and the ring mains finally actually looked like ring mains on drawings, rather than half of a ring with the other feeder marked "future".

    18. Re:Enter the 21st century, get sued? by DarkVader · · Score: 1

      There are 5 credit/debit cards in my wallet, plus the contactless card for charging my car and the various "reward" cards that I have to avoid being overcharged at grocery stores and drug stores.

      I don't even know/never set PINs for the credit cards, and I have no desire to do so.

      And the retailers typically own the terminals. They just had to buy new ones to replace perfectly good swipe terminals.

    19. Re:Enter the 21st century, get sued? by DarkVader · · Score: 1

      Not in the US. Debit cards were also magstripe cards until last year.

    20. Re:Enter the 21st century, get sued? by david_thornley · · Score: 1

      As far as I can tell, power prices where I live are fairly low still.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
  11. Small business here: not sure I'm rooting for this by Anonymous Coward · · Score: 0

    What I would object to is the absurd price points for the technology upgrade given we are talking abut mass produced technology. Especially given the security it'll provide is little more than snake oil.

  12. Boiling frog parable [Re:Not Sure if...] by Tablizer · · Score: 1

    They should have ramped it up gradually. For example, increase the percent of retailer liability by say 5% a month.

    I don't know if that makes it "fairer", but it's better "customer relations" psychology. There's a right way and wrong way to be a jerk. (Both prez candidates are doing it the wrong way.)

  13. Resistant To Change? by labnet · · Score: 4, Insightful

    I wonder what makes Americans so resistant to change, and when they implement change, it has so many compromises to be unworkable?

    Whether it be.
    - Adoption of the metric system
    - More sensible gun management
    - Universal basic health care
    - Writing dates mm-dd-yy
    - Reform of you court/prison system

    Australia has changed completely to chip cards. Mag swipe is no longer accepted.
    For most merchants, transactions below $100, contact-less is used.
    For over $100, a pin is required (and for some cards like amex, you need to insert the card for a chip read).
    The transactions take around 2 seconds.

    It works great. The $100 threshold is a good compromise for convenience vs fraud risk.

    I assume you are complaining because your banks have stuffed up the implementation???

    --
    46137
    1. Re:Resistant To Change? by Anonymous Coward · · Score: 1

      America did adopt the metric system. It is not forced for consumers (but it is for suppliers). It is taught in schools and universally used in scientific fields.

    2. Re:Resistant To Change? by Anonymous Coward · · Score: 0

      Not like the date method you want to use is any better... yyyy-mm-dd is the only one that makes sense, but most of the rest of the world does that backwards, so...

    3. Re:Resistant To Change? by Anonymous Coward · · Score: 1

      yyyy-mm-dd.

      Your date implementation is not an ISO standard and has an 'every century' problem. Furthermore, it doesn't alphabetize in chronological order.

      AC

    4. Re:Resistant To Change? by Anonymous Coward · · Score: 0

      >- Writing dates mm-dd-yy

      yyyymmdd is the only proper way to write dates. That way, they fucking sort right.

    5. Re:Resistant To Change? by Anonymous Coward · · Score: 1

      Shh! Any US centric news means its time for "The Hour of Hate" by any English speakers.

      The tiniest petty things like being binumeral instead of bilingual will be dragged out yet again. Others that are outright frauds like ignoring the 10:1 ratio of deaths and fetal alcohol syndrome in western nations versus the US while pretending that severe gun laws didn't just shift murder weapons to different categories. All while German beer kills 25 times as many innocent people per capita as American bullets.

      Pathetic show that pedantry and elitism means more to them than human lives.

    6. Re:Resistant To Change? by jrumney · · Score: 1
      While we're trolling Americans...
      • - adoption of different size and color banknotes to make them more easily distinguished.
    7. Re:Resistant To Change? by jrumney · · Score: 1

      Little-endian has some issues for naive sort algorithms, but now that we're past the mid 80's in terms of computing power, it isn't really a major issue compared with dealing with middle-endianness.

    8. Re:Resistant To Change? by YukariHirai · · Score: 1

      Australia has changed completely to chip cards. Mag swipe is no longer accepted.

      Not strictly true; it does still exist as a fallback if chip and contactless fail, and there are still cards out there that lack chips. Australian cards that lack chips are getting much rarer, but I still see a fair few foreign cards that are mag swipe only.

    9. Re:Resistant To Change? by Solandri · · Score: 1

      Credit cards were first implemented in the U.S., so the U.S. has a much larger installed base of the older magstripe credit card readers than any other country. That means a lot more inertia against change.

      Countries which implemented credit cards after the U.S. had the benefit of the lessons learned in the U.S. - like the security problems - which eventually led to chipped cards. It's the same reason why Africa has the highest ratio of cellular to landline phones. They basically got to skip the landline phone stage entirely because everyone else went through it.

    10. Re:Resistant To Change? by AC-x · · Score: 1

      Also don't forget ISO paper formats.

      The main downside of ISO paper is it would break that stupid printer joke, as "PC LOAD A4" is instantly obvious to everyone outside of North America.

    11. Re:Resistant To Change? by mjwx · · Score: 1

      Australia has changed completely to chip cards. Mag swipe is no longer accepted.

      Not strictly true; it does still exist as a fallback if chip and contactless fail, and there are still cards out there that lack chips. Australian cards that lack chips are getting much rarer, but I still see a fair few foreign cards that are mag swipe only.

      I think what he means is that new cards are not being issued with magstripes. My last card issued in Jan last year didn't.

      --
      Calling someone a "hater" only means you can not rationally rebut their argument.
    12. Re:Resistant To Change? by Anonymous Coward · · Score: 0

      At least we're free.

    13. Re:Resistant To Change? by Anonymous Coward · · Score: 0

      but it is insane to expect us to migrate from mm-dd-yyyy to dd-mm-yyyy because that is ambiguous during the change (01-02-2015 refers to what day?). yyyy-mm-dd however is a no brainier and how i personally write dates now.

    14. Re:Resistant To Change? by Anonymous Coward · · Score: 0

      - Metric sucks as much as imperial, just in different ways. Better the devil you know... (What is a meter again? And don't give me that back-defined speed-of-light shit. Nobody remembers that number off the top of their head anyway. No, a meter is roughly one one-millionth of the distance from the north pole, or somewhere near there, to some arbitrary, and poorly defined, spot in Paris, France. That just happens to be one just-under-three-hundred-millionth of the distance light travels in a second.)

      - Guns don't kill people. You've heard this one. It's actually true. I live in a "gun friendly" area and have never been shot. You don't live here, so you don't get to cry about the rules here. IOW, FOADIAF.

      - Universal healthcare would be nice, I admit. Realistically, though, it would result in lower standards of care than what US residents are used to. We do actually get what we pay for, even if it carries some sticker shock with it.

      - US dates are strange, but follow the english-language verbal conventions (October sixth, 2016 -> 10/6/2016). Euro dates are strange because they don't follow those spoken conventions, and are also backwards. Nobody does things in from-specific-to-generic order. ISO dates are the One True Date Format. Year, then month, then day. So again, Europe is wrong.

      - Our court system is just fine, though it periodically roots out corrupt actors. Our prison system is genocidal and should be destroyed with utmost indifference for the lives of all who brought it to bear on its victims. So, you're about half right.

      Hey, half-of-one out of five ain't bad!

    15. Re:Resistant To Change? by Anonymous Coward · · Score: 0

      Yes, big brother, nanny state, sexist, racist prison colony should totally be advising others on what changes to make.

    16. Re:Resistant To Change? by Anonymous Coward · · Score: 0

      You forgot that they still haven't gotten rid of pennies.

    17. Re:Resistant To Change? by Anonymous Coward · · Score: 0

      Metric sucks as much as imperial, just in different ways. Better the devil you know... (What is a meter again? And don't give me that back-defined speed-of-light shit. Nobody remembers that number off the top of their head anyway. No, a meter is roughly one one-millionth of the distance from the north pole, or somewhere near there, to some arbitrary, and poorly defined, spot in Paris, France. That just happens to be one just-under-three-hundred-millionth of the distance light travels in a second.)

      All imperial units are defined in terms of metric units, which tend to be well-defined. Using imperial units is just using metric units in a very inconvenient way.

      Guns don't kill people. You've heard this one. It's actually true. I live in a "gun friendly" area and have never been shot.

      Most people have never been shot, but the probability of getting shot in the US is several times larger than in a country without a large number of idiots walking around with guns.

      Universal healthcare would be nice, I admit. Realistically, though, it would result in lower standards of care than what US residents are used to. We do actually get what we pay for, even if it carries some sticker shock with it.

      I am not so sure about that. The US has a low standard of healthcare compared to other developed nations, both with and without universal healthcare.

      US dates are strange, but follow the english-language verbal conventions (October sixth, 2016 -> 10/6/2016). Euro dates are strange because they don't follow those spoken conventions, and are also backwards.

      That may be true in American English, French and perhaps a few other languages, but in most other European languages, including standard English, the day is always spoken before the month. The US date order is illogical and confusing to the 95% of the world that does not use it.

      Our court system is just fine, though it periodically roots out corrupt actors. Our prison system is genocidal and should be destroyed with utmost indifference for the lives of all who brought it to bear on its victims. So, you're about half right.

      While I agree completely about the prison system, the US court system is crazy and broken. The burden of proof is low, there is far too much emphasis on case law, juries of random people determine verdicts, expert witnesses are chosen by the parties rather than the court and judges need not actually have studied law and are even elected in some cases. This leads to hugely unpredictable outcomes, which, combined with the extremely tough sentencing in criminal law and the concept of punitive damages, makes for a very broken and unfair legal system.

      [Disclaimer: I am not GP nor do I claim to represent GP's views]

    18. Re:Resistant To Change? by sl3xd · · Score: 1

      I can think of zero reasons to switch paper standards. (And there are zero reasons against it too... it' snot like our printers are incompatible or anything).

      In this case, the status quo (using Letter/Legal sized paper) requires zero effort, while switching requires almost nothing.

      Really, it's just shelf space in stores and trying to move old stock.

      Any migration would require governmental decree -- and if you know anything about current US politics, the moment you talk about changing something as, um... traditional as paper sizes, we'll get an entire generation to spew from every orifice against governmental intervention.

      Seriously, we're deep enough in shit, and paper size is not the battle to pick.

      Interesting point: Amazon doesn't sell A4 in the US (though you can get it from other sellers through Amazon... at 3x the price of Letter sized)

      --
      -- Sometimes you have to turn the lights off in order to see.
    19. Re:Resistant To Change? by david_thornley · · Score: 1

      - The US is on the metric system. All of the customary weights and measures are specified in metric: The inch is defined as 25.4 mm. It isn't an IS unit, but it is metric. It would be nice to see the metric system used straight more often, but it's getting there. The bottle of water on my desk is a half liter.

      - The US government is one of the oldest in the world (the US is not the oldest country by a long shot, but most other countries have radically changed their government, voluntarily or otherwise, since the US Constitution was ratified), and we have some problems with that. One example is the stupid Electoral College, another is the Second Amendment that makes it extremely difficult to restrict weapons. It's not a competence problem, it's a structural problem.

      - Universal basic health care - you're dead on there. It would also be nice if the US government, like all others I'm aware of, was legally permitted to negotiate drug prices using it's vast bargaining power.

      - The only decent way to write dates is some form of YYYY-MM-DD. DD-MM-YY and MM-DD-YY are both unsatisfactory.

      - Once more you've hit on a real US problem. It's more difficult to change since we have a minimum of fifty-one court systems required by the Constitution, and it's difficult to regulate campaign spending without violating the First Amendment to the Constitution.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    20. Re:Resistant To Change? by david_thornley · · Score: 1

      Right now, I have plenty of envelopes that are sized right for letter and (sometimes) legal paper sizes. I don't think A3 or A4 would fit nearly as well. There would be hassle during the changeover, and I really don't see the upside.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    21. Re:Resistant To Change? by Anonymous Coward · · Score: 0

      How does gun management get more sensible than:

      I want a gun.

      I find somebody who wants to sell a gun.

      I buy a gun.

      I have a gun.

      It doesn't. That's the most sensible gun management system I could imagine, it doesn't get more sensible than that.

      And that's exactly how I bought my gun. The government had nothing to do with it, because it would be stupid for the government to have anything to do with it. The government has no idea whether I have a gun or not. And they don't care.

    22. Re:Resistant To Change? by DarkVader · · Score: 1

      mmm-dd-yyyy works just fine, and is completely unambiguous. That way today is Oct-06-2016, it works with the US standard way of thinking about dates, and nobody in the world is going to be able to confuse it with Jun-10-2016.

    23. Re:Resistant To Change? by DarkVader · · Score: 1

      Right. And I'll just go get a different size wallet for each denomination.

      They've got numbers on them. Green and black works just fine for me.

      Honestly, I wish we would go back to the old standard, where the President on a given note is in an oval in the center, and the numbers are in the corners. I HATE the new notes. The new hundred is awful, get rid of the color.

      At least the one is still good.

      I do think we need to ditch Andrew Jackson on the twenty, he was a shithead, the Trail of Tears is inexcusable. And once Obama is dead we can put him on the 50 and get rid of that shithead Grant too. But we need to keep Washington on the one and Lincoln on the five, and Alexander Hamilton really does deserve his place on the ten.

    24. Re:Resistant To Change? by jrumney · · Score: 1

      Right. And I'll just go get a different size wallet for each denomination.

      Seriously, that is your concern? Does your OCD trigger a meltdown down in the middle of the store when someone tries to give you two dimes and a nickel in change and you only brought your quarter purse?

    25. Re:Resistant To Change? by labnet · · Score: 1

      While we're trolling Americans...

      • - adoption of different size and color banknotes to make them more easily distinguished.

      Yep.. and their still thinking corks are superior on wine bottles

      --
      46137
    26. Re:Resistant To Change? by DarkVader · · Score: 1

      I throw the coins all in the coin sorter when I get home, then roll them up when a tube fills and take the tube to the bank, I keep a few of them in a coin holder in the car, which has separate spaces for each coin type. About the only thing I use them for is parking meters.

      And no, I wouldn't really get a separate wallet for each different size of paper money, but it would be very, very annoying.

    27. Re:Resistant To Change? by Anonymous Coward · · Score: 0

      [Mag swipe] still exist as a fallback if chip and contactless fail

      That should not be the case because theoretically the mag stripe should have a flag that identifies the card as having a chip, and the terminal should refuse the transaction via mag stripe. At least that's as far as I understand the EMV standard rules, and how it worked in Canada and New Zealand (where some terminals crashed and needed to be power cycled when used with my chip card), and mag stripe was rejected as well. In Australia, mag stripes were accepted if chip payment had failed. I have no idea why.

  14. Simple solution by Anonymous Coward · · Score: 0

    The card companies should adjust the merchant fees per transaction tech. So chip transactions would have a slightly lower merchant fee (assuming fraud costs are lower) and magstripe readers would have the same merchant fee as when all readers were magnetic.

    No mandate necessary and the seller can decide on their acceptable burden.

  15. Re:In the UK, we've had chip and pin for years! by sjames · · Score: 1

    We're not getting Chip and PIN, just Chip. And the retailers are expected to foot the bill.

  16. Are you fucking kidding me? by bistromath007 · · Score: 1

    There's a million and one reasons small businesses SHOULD sue credit card companies. This is one is stupid garbage.

  17. Ehhh.... by XSportSeeker · · Score: 1

    Wild guess, but this here might be why the change took this long, and was this half-assed. :P

  18. Re:In the UK, we've had chip and pin for years! by whoever57 · · Score: 1

    Actually, the infrastructure supports Chip and PIN. What makes the card Chip and Signature is something baked into the card by the issuers.

    While the new terminals do support Chip and PIN, places like restaurants will need to buy wireless terminals to allow customers to enter a PIN at their table. I haven't seen any wireless credit card terminals in use in the USA.

    --
    The real "Libtards" are the Libertarians!
  19. Force? by TheGrimmReaper · · Score: 1

    Um... where they forced to accept credit cards? If you are accepting someone's 3rd party method of payment, aren't agreeing to THEIR terms?

  20. BS Retailers by Anonymous Coward · · Score: 0

    It's the cost of doing business, suck it up.

    So what they are saying is "We want to force our credit-card using customers to use unsecured, outdated, and fraudulent-prone systems because we don't want to pay for new ones but we don't want to be responsible if fraud occurs" - whereas the credit card companies are saying "we want to reduce fraud and increase security for the users of our products".

    Who has the better tagline?

  21. Re:In the UK, we've had chip and pin for years! by PrimaryConsult · · Score: 1

    A lot of diners and some chains (i.e. Denny's, IHOP) are set up such that you just bring your receipt to the hostess and they cash you out there. So, more places could move to that model.

    Honestly waiting for the waitress to come pick up our cards, then bring them back with a pen is a pointless waste of everyone's time. "Just bring up your receipt when ready" works so much better...

  22. Re:In the UK, we've had chip and pin for years! by Larry+Lightbulb · · Score: 1

    3 or 4 years ago I used a chipless card in Sheffield, the machine read it OK but the staff didn't know what to do with the slip of paper which printed. A year before I tried the same card in Amsterdam, that required blowing the dust off the only mag stripe reader they had and getting the one person who knew how to operate it.

  23. Did they scream like this ... by PPH · · Score: 1

    ... when the credit card companies moved from carbon paper card impressions to magnetic stripes? Technology moves on and so must you.

    Not a small business operator, but I was under the impression that mag stripe readers and yes, even carbon paper imprints are still acceptable. You've just got to pay additional per transaction fees applicable to each non preferred method. To cover added processing costs and risk.

    --
    Have gnu, will travel.
  24. magnetic strip works by Anonymous Coward · · Score: 0

    I guess it is like x86. The banks have become decent at spotting small scale credit card fraud, after all those years of investing in trying to spot weird transactions. It is mostly transparent to the consumer. And, technology keeps on changing, so why try to change as soon as possible, especially if it requires a giant investment to put it into place.

  25. Cloning vs. theft vs. frustration by tepples · · Score: 1

    It depends on the attack model.

    Against card cloning A chip is much harder to clone than a magnetic stripe. Against physical theft of a card The chip changes nothing. Against account cancellation out of cardholder frustration with too many changes to the payment method at once A delay of a few years between instituting chip and instituting PIN is less jarring than instituting both at once.
  26. Love and hate the tap by phorm · · Score: 1

    I used to hate the tap because really, it seems like a step backward in security. Nice to know it uses rolling codes, but it still kinda sucks if you have your card stolen.

    On the other hand, tap is pretty nice when you're grabbing a quick coffee etc, and the theft thing isn't too bad if you set a low purchase limit. Still seems like a terrible idea for debit though.

  27. Chip & Pin only works in Europe by rsilvergun · · Score: 1

    because their laws allow them to shift liability onto the consumer when your pin gets compromised. It's sorta like if someone breaks into a bank they get to take your money instead of the banks.

    In the United States every single credit card swipe is a loan. And you can't enter into a loan without consent. That's why it's so easy to dispute things. But it's also the only way Americans would swallow credit cards. Chip & Pin wasn't worth the extra effort because you don't get a full liability shift to the consumer here.

    --
    Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
  28. America... by YukariHirai · · Score: 1

    There is no country on Earth more stubbornly refusing to modernise than the US.

  29. Really - Flea Market has them by Anonymous Coward · · Score: 0

    I bought a rug at the flea market the other day, the merchant had a chip reader hooked to a phone.
    It may not be built into the cash register and its accounting software, but the chip reader itself is cheap.
    The problem is the accounting "SYSTEM" provider jacking up the price of the chip reader and its integration.

  30. Merchants shouldn't verify identity by Anonymous Coward · · Score: 0

    The cryptocurrency guys hate any degree of centralization, and the rest of the world doesn't want weird new technology, but the eeeeevil "banksters" who are testing blockchain technology are actually right.

    What we need is the best of both worlds - theft insurance for your bank-issued hardware wallet so the merchant can be sure they're getting irreversible money for their irreversible goods, no need to trust merchants with sensitive information or risk card/pin skimmers, and if YOU lose your keys your insurance rates go up but you're not ruined financially. Enough of these earning miles and cashback rewards workarounds; what they're trying to solve is ultimately an adverse selection problem. We're expecting merchants to do identify verification constantly when having specialists do it once would be far more economical.

    There's a reason merchants prefer cash, and the consumer's problems with cash are now solvable. Forget the macroeconomics... If you're worried about Fed conspiracies you can still use Bitcoin, and if you don't care (like most people) you can use a private blockchain denominated in USD. What matters first are the microeconomic solutions that are now light years ahead of cards.

  31. Why does everything in the USA come with a lawsuit by Computershack · · Score: 1

    When we switched over to chip and pin from swipe here in the UK a deadline was set and that was that. Everyone just got on with it without feeling like they were being badly done to, let alone launch a lawsuit.

    --
    I only please one person per day. Today is not your day. Tomorrow isn't looking good either. - Scott Adams
  32. Meanwhile in Mexico... by Anonymous Coward · · Score: 0

    In Mexico --yes, that Mexico that MopHair Trump despises so much-- ALL CCs are chipped, ALL terminals are chip-enabled and ALL transactions are chip-protected. Been that way for over a year. And nobody is whining and wringing their panties in a bunch.

    Doesn't mean that all of a sudden this became Happy-Happy Land and fraudulent transactions disappeared. Identities still get stolen as do credit cards, but fraud dropped off enormeously.

  33. A lot of stupid people by whitroth · · Score: 1

    1. As of the beginning of this year, the PCI - the organization of credit card vendors section that deals with security, announced, over a year ago, that not having chip readers enabled meant that the store is liable for fraud.. The chip is a *lot* more trouble to clone or steal.
    2. What's the big deal? Time them printing out the chit, you signing it, or inputting crap on the screen, then having to sign (I *loathe* "signing" with my fingertip) - as if anyone could read half your signatures - as opposed to shoving the card in and waiting a minute for it to beep.

    It's about them not wanting to loose a *lot* of money because users don't care about people stealing their data, or watching you punch in your PIN, or....

                mark

  34. Re:In the UK, we've had chip and pin for years! by david_thornley · · Score: 1

    With the waitress handling the card, I can sit at the table uninterrupted and then get up and walk out when I please. There's usually delays when I have to pay at a register, and the chip implementation in the US will only make that worse.

    --
    "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
  35. Re:In the UK, we've had chip and pin for years! by DarkVader · · Score: 1

    It's something you can do while you're chatting with your dining companions instead of standing in line to leave the restaurant.

    Denny's and I-SLOP do that because they're crappy restaurants. Nice places take care of all of it at the table, with very minimal intrusiveness.

  36. Re:In the UK, we've had chip and pin for years! by Anonymous Coward · · Score: 0

    If you haven't seen wireless terminals, then you have no idea what convenience is. Heck, last time I ate out with a group the waitress brought 2 terminals over to the table and the group was settling their bills in parallel 2 at a time.

  37. Rather surprised to see this.. by Rexdude · · Score: 1

    In India we've had chipped credit/debit cards for at least 3-4 years now. Every shop and restaurant has a card reader that works with both chip and magstripe, and they give you the machine to enter your pin. Some of them are attached to the cashiers' desk on account of a landline, but many of them use mobile SIM cards, so they just bring the reader over to your table or hand it to you to enter the pin.. On some of them there's a shield over the keypad to conceal your fingers when typing the pin. And for online transactions, Mastercard & VISA both enforce an extra layer of security, either by an OTP sent to your phone (which you presumably have with you while making the online purchase) or by another password known only to you.

    --
    "..One hosts to look them up, one DNS to find them, and in the darkness BIND them."