Slashdot Mirror


The Long, Slow Demise of Credit Card Signatures Starts Today (cnet.com)

Last year, all four major U.S. payment providers -- Mastercard, Visa, American Express and Discover -- announced plans to remove the requirement that merchants collect signatures for card transactions. Those plans officially go into effect today, or Saturday in the case of Visa. CNET reports: [D]on't despair if you actually like writing your signature at retail stores, because their ultimate demise will likely take a while. The change is only optional, with merchants, not customers, given the new power to decide whether to get rid of signatures. So, if asked to sign, please don't insist to your next cashier that you no longer need to -- it won't work. Also, plenty of retailers will likely want to keep signatures, particularly if their workers are paid based on a lot of tips, or they sell pricey items. Still, the change marks a clear awareness from payment providers that the signature doesn't really work as a strong protector against fraud.

The change is being handled a little differently by each payment provider. For instance, Mastercard, Discover and American Express said they'll let retailers make every kind of card payment optional for a signature, regardless of whether you've got a new chip card or you still swipe. Visa, meanwhile, isn't changing its requirements for payments using a swipe card, but it did relax its policy for chip card and contactless payments like Apple Pay. Visa noted that over 75 percent of face-to-face transactions using its cards in North America already don't require a signature, thanks to lower-value transactions.

114 comments

  1. Hey USians! by JoeDuncan · · Score: 3, Informative

    ... welcome to the year 2000!

    By the time the rest of us are authorizing credit purchases with telepathy, you'll probably *JUST* be introducing the "tap & go" LOL what a fucking backwater...

    1. Re:Hey USians! by AlanBDee · · Score: 2

      You're just wrong. We have the best internet, highest quality healthcare (and cheapest), and the best educational system ever.

      Some people are so stupid they just don't know it.

    2. Re:Hey USians! by aaarrrgggh · · Score: 1

      Yes, but we effectively have zero consumer liability for fraud. Pick your poison; not sure I want EU-styled consumer liability based on a PIN code alone.

    3. Re:Hey USians! by Anonymous Coward · · Score: 0

      It wasn't that way until about a year ago. Then everything suddenly got way, way, way better. Bigly.

    4. Re:Hey USians! by Anonymous Coward · · Score: 0

      Considering you're posting from the US. Yes, we can tell.

    5. Re:Hey USians! by Anonymous Coward · · Score: 0

      The correct terminology is "shithole".

    6. Re:Hey USians! by jrumney · · Score: 1

      Hey Europeans, welcome to the year 1985, when EFT pinpads were first introduced in your far flung colonies. Signatures are from the distant era of carbon paper imprints.

    7. Re:Hey USians! by jrumney · · Score: 1

      You name doesn't seem very Korean to me...but plastic surgery isn't all there is to healthcare.

    8. Re: Hey USians! by Anonymous Coward · · Score: 0

      You have zero fraud liability in Europe as well. That have excactly nothing to do with pin vs signature.

    9. Re:Hey USians! by ShanghaiBill · · Score: 2

      Yes, but we effectively have zero consumer liability for fraud.

      That means little in reality. Plenty of fraud is for small amounts that slip by without the consumer bothering to inquiry about an $8 charge on their card. For big charges involving identity theft, the burden is on YOU to prove the transactions were fraudulent, and even if you are successful, you may spend hundreds of hours, and have your credit ruined for years.

      Pick your poison; not sure I want EU-styled consumer liability based on a PIN code alone.

      So here are the choices:
      1. Security based on a PIN that is under my full control, and can be changed if compromised.
      2. The American way: Security based on my SSN and DOB, which are unchangeable, and have already been compromised a dozen times.

      Golly, that is a tough decision.

    10. Re:Hey USians! by grim4593 · · Score: 1

      I've had fraudulent activity on my card twice. I hit a button on the credit card app to turn the card off, press another button to call to report fraud, and my new card was in the mail that day. No follow up activity was needed.

    11. Re:Hey USians! by DNS-and-BIND · · Score: 1

      That's why it's so wrong that we meddle so often in other countries' military affairs and have this gigantic trading empire. We need to stop these ridiculous outdated projects like NATO and withdraw our troops home, so that we can pay for these badly needed improvements to our society. Being considered a backwater by the rest of the world stings badly, and there's a lot of things we need to stop doing. If we cut the US Navy down to half the number of ships, we can afford to improve ourselves. Other countries will of course support this, as who wants to be the ally of a backwater shithole like the USA?

      --
      Shutting down free speech with violence isn't fighting fascism. It IS fascism!
    12. Re:Hey USians! by Anonymous Coward · · Score: 0

      I had the same thought today, but in another context.

      Some highly technical guys were commenting about data transfer rates and how sensitive is USB 3.0 to distance. Some commented about it not working on a mere 100 inch (to a reach a printer IIRC).

      I then thought people in the US are like in an island, because if someone leaves for another country he/she/they would be illiterate regarding most units, with the exception of time.

      Not a big deal, perhaps, after some time everyone gets used, but the initial confusion must be like when we read articles with feet, miles, pounds, ounces...

    13. Re:Hey USians! by Computershack · · Score: 2

      ; not sure I want EU-styled consumer liability based on a PIN code alone.

      It would have been easier to say "I get my information about the EU from Fox News."

      --
      I only please one person per day. Today is not your day. Tomorrow isn't looking good either. - Scott Adams
    14. Re: Hey USians! by Anonymous Coward · · Score: 0

      My experience in EU regarding credit card fraud was pretty easy: the bank called me up and asked if I had ordered luxury clothes online in the US without using verified by visa authentication. A simple "no" and they blocked the card, sent out a new one and refunded me $50k and issued a chargeback to the US companies that didn't implement any of the usual (in EU) security checks for buying goods online (I was told not even the CVV was provided so it might have been a phone order; we can't make these purchases anymore).

    15. Re:Hey USians! by quenda · · Score: 1

      You think signatures are bad?
      Americans still use cheques - sorry, checks, and they actually get physically moved around between banks, and eventually returned to the writer.

      Another thing: Americans still have pennies in circulation. Worth less than a Euro-cent! Its insane.
      Something costs 99c, you hand over a dollar (in paper money I tell you! not a coin), the clerk then says you need another ten cents because the 99c did not include tax, so you find a dime (almost worthless) and then get a penny in change. Which you drop in a tray. The country's payment system is incomprehensible.

      On the plus side, because their banking system is so awful, they did invent the credit card. And sometimes the countries who invent things get stuck with a bad beta version, like NTSC colour TV.

    16. Re:Hey USians! by Jahta · · Score: 1

      Yes, but we effectively have zero consumer liability for fraud.

      That means little in reality. Plenty of fraud is for small amounts that slip by without the consumer bothering to inquiry about an $8 charge on their card. For big charges involving identity theft, the burden is on YOU to prove the transactions were fraudulent, and even if you are successful, you may spend hundreds of hours, and have your credit ruined for years.

      Pick your poison; not sure I want EU-styled consumer liability based on a PIN code alone.

      So here are the choices: 1. Security based on a PIN that is under my full control, and can be changed if compromised. 2. The American way: Security based on my SSN and DOB, which are unchangeable, and have already been compromised a dozen times.

      Golly, that is a tough decision.

      And in Europe all cards are Chip-and-PIN, and therefore cannot be skimmed. So a fraudster would have to have your actual card as well as your PIN.

    17. Re:Hey USians! by TheRaven64 · · Score: 1

      Chip and pin systems were introduced in France at around that time, but the system was patented. Most of non-French banks didn't want to license the patent and so waited until it expired before rolling it out across the continent. I guess your country either didn't sign the relevant IP treaties or was happy paying royalties to France for every transaction.

      --
      I am TheRaven on Soylent News
    18. Re:Hey USians! by Megane · · Score: 1

      Americans still use cheques - sorry, checks, and they actually get physically moved around between banks, and eventually returned to the writer.

      That hasn't been true for over 15 years. Once it was allowed to pass around just the image of the check (back in 2001 or so), they got scanned and shredded early in the clearing process, and the monthly statement includes a few pages of the images of the front of the checks. The rear side (signatures and a lot of rubber stamping) is no longer available to mortals.

      --
      #naabhaprzrag, #sverubfr-000, #agi-fcbafberq, negvpyr[pynff*=' negvpyr-ary-'] { qvfcynl: abar !vzcbegnag; }
    19. Re: Hey USians! by Anonymous Coward · · Score: 0

      Dumbass, if it weren't for the large US military, you Euros would have to actually spend the money to defend yourselves and keep the world's shipping lanes safe. Instead, you let Daddy pay for it so you can spend your money on wants instead of needs. FREELOADER.

    20. Re: Hey USians! by Anonymous Coward · · Score: 0

      Reread your comment. Revise my post to not call you a Euro, but the same argument applies: someone has to keep the peace, and it costs money to do so.

    21. Re:Hey USians! by MoarSauce123 · · Score: 1

      I am still waiting for a large number of merchants got get chip readers ...yea, chip only, not chip and pin. Makes the chip only marginally more difficult to intercept. If the chip reader rollout is any indication, the no signature rollout will take until 2178....still 10 years before the new airport in Berlin opens.

    22. Re:Hey USians! by Anonymous Coward · · Score: 0

      Also paying to receive a fucking phone call. Seriously, what the fuck is up with that?

      Or America's relentless fascination with plain jane SMS. The whole world moved on, America still texts 160 characters at a time, 153 if it's a multipart message. Hell, even Twitter went to 280.

      Or, because someone's boss doesn't pay them enough to live comfortably, it's somehow on me to pay 20% or so more on my bill so Johnny Servant can afford rent. Fuck no. Find a job that pays enough for you to live on, I have my own finances to deal with, thank you very much. I'll tip if I get exceptional service, not when Johnny Servant begrudgingly tosses my plates in front of me with a grunt.

    23. Re: Hey USians! by Anonymous Coward · · Score: 0

      I also hear that they started making these new âoedefense riflesâ that donâ(TM)t even have triggers. You just point and itâ(TM)s advanced AI decides if it shoots or not. Boy oh boy I love being white! ;)

    24. Re:Hey USians! by Anonymous Coward · · Score: 0

      Err what the fuck are you talking about. Lived in EU for 10 years. My CC if lost or even used with payway was NEVER more than $50. If i notify visa before it is used it was zero! ZERO.

    25. Re:Hey USians! by jrumney · · Score: 1

      The 1980s cards were magstripe and PIN, chips came later.

    26. Re: Hey USians! by Anonymous Coward · · Score: 0

      Haha! Daddy...

      Now back to bed Junior. Before the Red Menace gets you.

    27. Re:Hey USians! by torkus · · Score: 2

      My bad, i thought this was /. where people knew at least a tiny bit about the tech...

      It's harder, but by no means impossible, to read and duplicate a chip card. You do also need the PIN but there are plenty of examples of that being compromised with cameras primarily but also with hacked keypads and other means.

      It's significantly harder to skim a chip-and-pin vs mag stripe(mag stripes were never secure, only slightly obscure ... for a while) but it can, has, and will still be done fairly regularly.

      --
      You can get rich if you own a politician, but you have to be rich to buy one in the first place.
  2. Ta hell with all four ... by b0s0z0ku · · Score: 1

    I prefer cash without the gov't/corporate tracking. And no signature required, just basic math skills.

  3. I've never written my name on any card I've ever o by Anonymous Coward · · Score: 0

    wned. Nobody has asked me about it either.

  4. Ye by Anonymous Coward · · Score: 0

    Just doing their part in making sure the fraud prevention duties get transferred exclusively to the retailers, I guess.

  5. Who signs their real name? by Snotnose · · Score: 3, Interesting

    These signing terminals have been a thing for a good 15-20 years now, yet I've never signed one. I sign either Foo Bar or Mickey Mouse, depending on my mood. All have gone through with 0 hassle.

    In fact, I bought groceries from Von's today, signed Foo Bar with no issues

    Then again, their Just 4 U program ties my phone # to my credit card so there's that.

    1. Re:Who signs their real name? by glenebob · · Score: 1

      These signing terminals have been a thing for a good 15-20 years now, yet I've never signed one. I sign either Foo Bar or Mickey Mouse, depending on my mood. All have gone through with 0 hassle.

      There's one store near me that rejected my actual signature on two occasions (many years ago). In both instances, a block printed "BOB" fixed the issue.

    2. Re:Who signs their real name? by Art+Challenor · · Score: 1

      Getting a little more creative.... https://www.reddit.com/r/funny...

    3. Re:Who signs their real name? by torkus · · Score: 1

      Macys was doing this at one point about two years ago. I ran into it while christmas shopping. Unless the first letter of my signature was comprehensible as the first letter of my name it would reject the signature. I made several purchases one day there and kind of ... got to play with it. A block letter followed by a squiggle was fine. Anything that resembled my actual signature not so much.

      --
      You can get rich if you own a politician, but you have to be rich to buy one in the first place.
  6. partial security / insecurity -- what's the point by supernova87a · · Score: 5, Interesting

    It was silly for the card networks and banks to chicken out on implementing Chip + PIN. People will have to face the (relatively small) pain of learning how to use it at some time, and better to just rip the bandaid off all at once.

    All of Europe, rest of world can deal with using a PIN. What's so special about the US? Just do it, save us all from having to subsidize fraud.

  7. Re:partial security / insecurity -- what's the poi by Anonymous Coward · · Score: 0

    Chip + PIN. People will have to face the (relatively small) pain of learning how to use it at some time

    I disagree. Americans will never learn a PIN number, and they'll be forced to just deal with the identify theft that occurs because of it. The credit card companies will say there's nothing they can do about it because it's the criminals' fault, and we need to be tougher on crime!

  8. Re:partial security / insecurity -- what's the poi by AlanBDee · · Score: 1

    All of my recent debit cards have chips. Merchants don't want to buy new machines and the credit card companies don't care because they pass most the cost of fraud to the merchants. It's seriously sickening how these payment providers make money on both ends without that much liability.

  9. Re:partial security / insecurity -- what's the poi by aaarrrgggh · · Score: 1

    Then explain the merchants with the chip/contactless compatible terminals with signs saying “swipe only”. Card issuers are interested in limiting fraud... Chase called my wife today about fraudulent MSFT/XBox charges. They want to keep the consumers happy and feeling secure, and... not sure what they want to do with the merchants.

  10. Cursed writing by minstrelmike · · Score: 0

    So can we stop teaching cursive in elementary school now? I hated writing the same-sized letters in the notebook with all the lines.

    1. Re:Cursed writing by Anonymous Coward · · Score: 0

      Ugh, why is this ignorance being upmodded?

      Cursive has nothing to do with legal signatures. People use cursive for signatures because it's the easiest way of generating an identifiable scrawl for use as a signature. And if you see lots of signatures, you'll find that very few of them are actually in cursive.

      The reason why educated people know how to write in cursive is because it's a lot easier to write large amounts of text quickly and efficiently than with print or block writing. The shape of the letters makes it a lot easier to write quickly and it's not even close.

  11. Re:partial security / insecurity -- what's the poi by glenebob · · Score: 1

    I disagree. Americans will never learn a PIN number, and they'll be forced to just deal with the identify theft that occurs because of it.

    What identity theft? With modern chip cards that are essentially impossible to clone will solve that issue almost entirely - fraud is already down dramatically because of chip cards, and many of them still support the old insecure mag stripe mode.

  12. Re:partial security / insecurity -- what's the poi by misexistentialist · · Score: 1

    Europe has lower card usage, PIN adds more inconvenience than security. You have a couple of people looking at you type it in and who knows how many cameras, what is the point?

  13. Re:partial security / insecurity -- what's the poi by glenebob · · Score: 1

    Then explain the merchants with the chip/contactless compatible terminals with signs saying “swipe only”

    I'm not sure about this, but that could be due to older POS software that doesn't grok the new reader features.

  14. Re: partial security / insecurity -- what's the po by Anonymous Coward · · Score: 0

    We rejected PIN because the processors believe it is more powerful than it really is. Falling back on "you must have shared your pin" for unexplained cases is not acceptable here.

  15. Re:partial security / insecurity -- what's the poi by Anonymous Coward · · Score: 0

    I'm perfectly happy using chip-only and stopping the pointless signatures. But, I shall retain the right to view my statement and dispute a fraudulent charge. I refuse to use a PIN when the banks try to bundle that with a shift in liability and a presumption that their little toys are invulnerable to fraud.

    Also, I will never accept a system where I am forced to enter my supposedly sensitive, never-share-with-anyone PIN into random devices maintained by shopkeepers. A proper end-to-end secure transaction should consider the point of sale device to be adversarial.

  16. Re:partial security / insecurity -- what's the poi by Anonymous Coward · · Score: 0

    With modern chip cards that are essentially impossible to clone will solve that issue almost entirely

    Spoken like a true American! We don't need no PIN numbers, it's good enough without them!!

    (Sarcasm.)

  17. India has moved ahead..mobile payment by Anonymous Coward · · Score: 0

    Since 2017 all cards issued/replaced are chip&pin cards as govt mandated. But majority people, skipped the card-phase, have gone to mobile payment using govt supported UPI(uniform Payment Interface) implementated by various apps. UPI does not require a merchant machine, just a phone QR code paper printout stuck at counter, which a road side hawkers have it now a days on thier push carts and cabs. I routinely make UPI payments to sellers whose turnover is less than 50$ per day.

    1. Re:India has moved ahead..mobile payment by PPH · · Score: 2

      just a phone QR code paper printout stuck at counter

      I don't understand how this works. The shop has the QR code. The customer scans it with his phone. 'Beep', the payment has been made. What stops someone from writing a 'Beep' app?

      --
      Have gnu, will travel.
    2. Re:India has moved ahead..mobile payment by TheRaven64 · · Score: 1

      There was a paper published last week showing a whole raft of trivial attacks on this system, and that's ignoring the fact that it runs on phones that are likely to have at least one remotely exploitable security vulnerability. It basically works because most of the users don't have enough money to be interesting targets for theft.

      --
      I am TheRaven on Soylent News
    3. Re:India has moved ahead..mobile payment by denbesten · · Score: 1

      Walmart pay does this. The trick is that the a unique QR code is displayed on the credit card reader for your transaction. When you scan the code with the Walmart app on your phone, it links you to the transaction and uses a stored credit card to make the payment. It also downloads a copy of the receipt into your walmart app.

      Apparently, they implemented it to avoid fees charged by Apple, Google, Samsung and other mobile payment services.

  18. Re: partial security / insecurity -- what's the po by Anonymous Coward · · Score: 1

    Except of course that cards are used so frequently in Europe that people are talking about a cash less future...

  19. Just skip it by Anonymous Coward · · Score: 0

    We should just skip the whole chip card thing, which Europe has been doing for like the last 20 something years, and move to contactless payments. Granted not everyone will have a smartphone capable of NFC payments, but surely we could figure out SOMETHING. Japan was letting people pay at vending machines back before there was such a thing as a smartphone. It can be done.

  20. Re:partial security / insecurity -- what's the poi by Anonymous Coward · · Score: 0

    Why on earth is it okay to share the chip with the card reader, but not the PIN?

  21. Why not chip-and-pin? by jonwil · · Score: 3, Interesting

    Australia has been using chip-and-pin credit cards for years now, as has Europe and many other places. What is it about the US that makes card companies (Visa, MasterCard etc), banks and merchants so reluctant to introduce chip-and-pin in the US?

    1. Re:Why not chip-and-pin? by Anonymous Coward · · Score: 0

      We haven't been permitted to sign for credit card purchases for at least 4 years - PIN is required. Contactless cards have been a thing for longer, chip and pin predates that again (and is largely obsolete).

    2. Re:Why not chip-and-pin? by Anonymous Coward · · Score: 0

      What is they are still using Imperial measurements while the whole world has switched to the metric system long ago. Even Britain is using mostly metric nowadays.

    3. Re:Why not chip-and-pin? by thegarbz · · Score: 1

      You missed a far more interesting part of that: Australia has *mandated* pin for all transactions on Australian cards for the past 4 years. When you swipe a card in an Australian terminal it will identify Australian credit and debit cards and force a chip+PIN authorisation.

    4. Re: Why not chip-and-pin? by DNS-and-BIND · · Score: 1

      It costs money to change over. You think bankers got rich by spending money? Hell no. We must all suffer so they can make a few more coppers. That's how sociopaths work.

      --
      Shutting down free speech with violence isn't fighting fascism. It IS fascism!
    5. Re:Why not chip-and-pin? by Anonymous Coward · · Score: 0

      [...] What is it about the US that makes card companies (Visa, MasterCard etc), banks and merchants so reluctant to introduce chip-and-pin in the US?

      I'll give you a hint: They have breasts,

    6. Re:Why not chip-and-pin? by Local+ID10T · · Score: 1

      We have chip-and-pin.

      Every merchant supports it for debit transactions. It uses the same piece of hardware (card reader) whether you use pin or signature. It makes no difference to the merchant whether you punch in a pin, or scribble on the receipt, or wave your phone at the reader -we just want to get paid.

      So, why don't we use chip-and-pin for credit transactions?

      Because the card issuers/payment processors don't want us to.

      --
      "You want to know how to help your kids? Leave them the fuck alone." -George Carlin
    7. Re:Why not chip-and-pin? by Anonymous Coward · · Score: 0

      One simple answer : Patents

      Smart Cards Patents are orginally from France, where we were early adopters.
      For ~20 years, ""US"" decide that the chip+pin was no more secure than the magnetic strip.
      The by different means, the patents became ""US"" bits by bits (including spying/stealing, hostile stocks takeover, purchase influence inside the key player or the whole key palyer itself).
      When the ""US"" has got the patents, Magnetic Strip was denouced as poor security, and chip + pin was the way to go.

      So in the end they waited before paying the patent licences.

  22. Re:partial security / insecurity -- what's the poi by Anonymous Coward · · Score: 0

    All of Europe, rest of world can deal with using a PIN. What's so special about the US? Just do it, save us all from having to subsidize fraud.

    1. The fraud will happen anyway.

    2. Better to have them steal an identifier than an authentication secret.

    The signature is meaningless. It's just an identifier. You can literally put a big X on the pad and it, plus the cashier in most places, will happily take it.

    The PIN on the other hand is also used as an authentication secret to gain access to the cardholder's bank account. Most people in the US will have a card tied to their bank account that can also be used as a credit card, because that's what the banks in the US are selling you. A credit line.

    Ever notice how somehow despite it being a "bank" account, you can somehow have it wind up in the negative digits? Most of these scams are called "over-draft protection" or "courtesy pay" by the banks. These schemes allow the bank to charge you to pay more than you have in your account to someone. Instead of failing and returning "insufficient funds" when the transaction was made. Depending on the bank, this may also allow them to hide screwing around with the order of your transactions in an attempt to hit you with more fees. Particularity, if you don't keep a close eye on the account statements.

    Knowing that PIN could easily cause some people to drop into the red simply due to someone else using it. Worse, some banks also use the PIN for customer service and online services, amongst other things.

    Wanna know how easy it can be to hack the reader to send out the PIN to a phone somewhere? Or how about the old camera above the keypad trick? The US is about to find out.

  23. Re:partial security / insecurity -- what's the poi by jrumney · · Score: 1

    Are you suggesting that Americans will continue to use the signature strip on the back of their card the same way they have always used it -put a copy of the thing that authorizes them as the valid user of that card there for all to see?

  24. Re:partial security / insecurity -- what's the poi by SvnLyrBrto · · Score: 4, Insightful

    The truly obnoxious thing is that without the PIN, the chip itself is worthless, but was forced on us anyway. So we got the slowdown at the registers for no reason. With a PIN, at least if I lose my card or my wallet is stolen, the card would be useless to the thief barring unbelievable luck in guessing. But with only the chip in play, the only place a thief couldn't use my card is the gas station, which was already the case with the stripe.

    Pointless. Security. Theater.

    --
    Imagine all the people...
  25. Re:partial security / insecurity -- what's the poi by Anonymous Coward · · Score: 1

    The chip signs a transaction to report "card present". The device does not get a copy of the keys held inside the chip.

    The PIN is purported to indicate "user is present and accepts transaction". But a rogue device could capture it and then reuse it later if they happen to acquire the card again. That defeats the purpose of having a supposed second factor.

    Once you recognize that large merchant chains have been hacked and will be hacked again, you should assume that there is a malicious network of point of sale devices out there, waiting for victims. A malicious device could generate fraudulent charges while my card is present. And I can dispute them with the current rules here in the US for a chip-only transaction. The PIN does not guarantee that I am approving this particular transaction, when it might be a replay attack using a stored PIN value obtained on a previous encounter with my card. It doesn't add security, and we shouldn't entertain the security theater nor allow the finance companies to shift liability to users when this useless extra ceremony is performed.

  26. Re: partial security / insecurity -- what's the po by b0s0z0ku · · Score: 1

    Only in a handful of countries. Southern Europe, Germany, and Eastern/Central Europe are basically cash economies.

  27. Wait, let me get this straight. by CptLoRes · · Score: 1

    you have a direct link to your bank account in your wallet, that if lost or stolen anybody can use? No pin, no nothing. Man.. I guess you really are the land of the brave..

    1. Re:Wait, let me get this straight. by iggymanz · · Score: 1

      actually, no, there are limits on liability.

      so not brave, just insured

    2. Re:Wait, let me get this straight. by PPH · · Score: 1

      direct link to your bank account

      Credit card. Issued by an entirely different bank.

      But yeah. Why no PIN? Merchants around the rest of the world love PINs. Less deniability over credit charges.

      --
      Have gnu, will travel.
  28. Re:partial security / insecurity -- what's the poi by pete6677 · · Score: 1

    Pointless. Security. Theater.

    Otherwise known as the American Way.

  29. It had less to do with learning to do it by rsilvergun · · Score: 1

    and more to do with getting businesses to buy all the hardware and software needed to do it. Chip + Sig was cheaper and easier to implement. As for what's different about America, we are positively _loath_ to spend on infrastructure of any kind (except private airports for the ultra rich, but I digress).

    --
    Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
    1. Re:It had less to do with learning to do it by PPH · · Score: 1

      getting businesses to buy all the hardware and software needed to do it

      The chip hardware is here already. Adding a PIN just uses the (included) keyboard and some more software (which has a development cost but zero marginal cost to distribute).

      --
      Have gnu, will travel.
    2. Re:It had less to do with learning to do it by thegarbz · · Score: 1

      You think that a chip+pin terminal was more expensive than the over sized complex terminals with large displays and touch / stylus which were implemented for chip+signature?

      That is truly incredible.

    3. Re: It had less to do with learning to do it by Anonymous Coward · · Score: 0

      I got the sense that the main pushback came from restaurants where in the US the usual routine is for the card transaction to happen out of sight, away from the table.

      In Europe and Canada there are portable devices for executing the transaction, but US restaurants don't have these already (so would need to buy them) and it turns an async process (bring paper to customer and walk away, customer signs and leaves, collect paper when convenient) into a sync one (bring device and wait while the customer fusses with it for a minute or more).

  30. Re:partial security / insecurity -- what's the poi by Anonymous Coward · · Score: 0

    The point is that the ones who see you type in the pin don't have the chip and the guy that steals your chip hasn't seen you put in the pin.

  31. signatures served no purpose by iggymanz · · Score: 2

    I can't write anything that looks like my signature on those silly tablets anyway, and a lot of people just make a wavy line..... how about some actual security instead? a pin? connect the dots on a grid in a pattern?

    signatures always were silly, a thief can practice the one they make you put the the back of your card

    1. Re:signatures served no purpose by Anonymous Coward · · Score: 0

      signatures always were silly, a thief can practice the one they make you put the the back of your card

      I used to work as a cashier in the US at a drive through, before they had those self-serve terminals rolled out, and well over half of the cards that I checked were unsigned on the back. Thank goodness at least one of the banks had the sense to include a tiny photograph of the card holder on the front.
      In fact now that the majority of terminals are self-serve, there's nobody who's going to check the signatures on the back of the cards or the photograph on the front if there even is on, so they largely serve no purpose for day-to-day transactions.

  32. Re:partial security / insecurity -- what's the poi by Bobberly · · Score: 1

    Also, I will never accept a system where I am forced to enter my supposedly sensitive, never-share-with-anyone PIN into random devices maintained by shopkeepers. A proper end-to-end secure transaction should consider the point of sale device to be adversarial.

    Why? The PIN is useless without the attached card. As long as you can retain possession of the card immediately after you enter the PIN there is no possibility of fraud. You'll see the authorized amounts on the device.

    You DO keep your receipts so you can correlate with what your issuer said happened right?

    As many others have said, works for Europe just fine...

  33. Re:partial security / insecurity -- what's the poi by PPH · · Score: 1

    when it might be a replay attack using a stored PIN value obtained on a previous encounter with my card

    Except your card is no longer present for that replay attack to work. It is my understanding that there is some sort of handshake between the card company and the chip to authenticate. There isn't a simple mag stripe account number that they can save and replay with your PIN.

    nor allow the finance companies to shift liability to users when this useless extra ceremony is performed.

    This is the root of the problem. Consumers have become too accustomed to the ease of reversing fraudulent charges, based on the ease of signature forgery. Losing a PIN implies some carelessness on the part of the consumer, so they end up accepting more liability.

    I'd like to see a system where the banks issue two types of card accounts. One with a chip only and one with a chip and pin. The fees charged against each type of card to cover fraud losses would be spread among the holders of each type. Let the free market decide.

    --
    Have gnu, will travel.
  34. Today?? by Anonymous Coward · · Score: 0

    Canada has been doing this for more than 25 years...today? Are you joking??

  35. Re:partial security / insecurity -- what's the poi by squiggleslash · · Score: 3, Informative

    Most credit card fraud is based upon writing bogus data (data for the victim's card) to the magnetic strip, so the chip does at least provide security against someone getting hold of your number and creating a fake credit card using it.

    But yes, it does nothing for you without a PIN if the card leaves your possession.

    --
    You are not alone. This is not normal. None of this is normal.
  36. Anecdote regarding signatures by Anonymous Coward · · Score: 0

    Posting as AC because it's somewhat embarrassing.

    Nearly 30 years ago I let a woman use my credit card and of course she abused it and the stated agreement between us was that she would pay me back.

    You can guess how that turned out. Capital One ended up reversing every charge that didn't have a signature which was mostly to fill her gas tank but didn't cover most of the other purchases.

    Of course her name didn't match the credit card at all but apparently no one challenged her on it. Lesson learned. I sued in small claims court and won, but of course it was a judgement I could never collect on. ....

    Nowadays I merely "make my mark" rather than signing my name. Like many people, I just scribble as little as possible and it has no resemblance to what my signature would look like on a document I considered important like my mortgage.

    1. Re: Anecdote regarding signatures by Anonymous Coward · · Score: 0

      We've all been ripped off by women, in different ways.

    2. Re: Anecdote regarding signatures by dave420 · · Score: 1

      We've all been ripped off by people, in different ways.

  37. Re:partial security / insecurity -- what's the poi by Jarik+C-Bol · · Score: 2

    Was it not just last week we had reports of new chip cards being intercepted in the mail, having their chip pulled off and replaced with the chip from a dummy card, the real chip put onto the dummy card, and then the modified card placed back in the mail, so that the customer receives their card and activates it, thus enabling the thieves to use their dummy card with the real chip on it, leaving the customer up a creek with their useless card, and charges they did not make?

    --
    I've decided to Diversify my Holdings. I've divided my cash between my left and right pockets, instead of all in one.
  38. Pretty useless anyway. by bjwest · · Score: 1

    I don't know when the last time I signed my name in one of those esig boxes. I random scribble something and the cashier just pushes a button, my receipt's printed, and out the store I go with my goods. And people wonder why it's so easy for someone to use someone else's credit card.

    --

    --- Keep the choice with the user..
    1. Re:Pretty useless anyway. by Anonymous Coward · · Score: 0

      It's easy because there is a video of you making the squiggly line. So if you make someone elses squiggly line and steal their stuff, there is a pretty good chance you will be caught.

    2. Re:Pretty useless anyway. by stooo · · Score: 1

      Caught by a video ?
      Tht will not happen.
      You cannot be identified among 270 million other people (or 7 billion).

      --
      aaaaaaa
    3. Re:Pretty useless anyway. by bjwest · · Score: 1

      You mean that video usually shot from the ceiling that's easily foiled by a simple baseball cap?

      --

      --- Keep the choice with the user..
  39. Re: partial security / insecurity -- what's the po by Computershack · · Score: 1

    More transactions were done on card than in cash in the UK. A lot of people in the UK, myself included, go months without touching cash.

    --
    I only please one person per day. Today is not your day. Tomorrow isn't looking good either. - Scott Adams
  40. Re:partial security / insecurity -- what's the poi by Anonymous Coward · · Score: 0

    The PIN doesn’t give access to your bank account. It is used to authenticate you to the card, which signs the transaction. It is useless without the card and the card is useless without the PIN. You need both to complete the transaction that is displayed on the screen. Replay wouldn’t work either since the transaction challenge contains a pseudo random number that is signed by the card along with payment information. The number is different for each transaction.

  41. USA is 20 years behind on tech by stooo · · Score: 1

    >> It was silly for the card networks and banks to chicken out on implementing Chip + PIN.
    This. The USA is only 20 years behind on tech

    --
    aaaaaaa
  42. Re:partial security / insecurity -- what's the poi by stooo · · Score: 1

    >> ....having their chip pulled off and replaced with the chip from a dummy card, ....., so that the customer receives their card and activates it
    That happens only in the broken US system.
    In EU you typically can only activate your card with the right PIN, and only on an TM which checks the chip.

    --
    aaaaaaa
  43. Re: partial security / insecurity -- what's the po by Anonymous Coward · · Score: 0

    Over here in Europe I get sent the PIN by registered mail or (now nore common) electric secure mail (RSA dongle required). And activating the card requires to go to the bank's ATM and enter the PIN. Until then the card is blocked from any purchase...

  44. Whither Chase? by TechyImmigrant · · Score: 1

    Chase has not provided me with a pin for my Chase Sapphire Preferred credit card. I have to sign.

    There really isn't an excuse for not requiring pin authentication for a card present PoS credit card transaction.

    --
    I should use this sig to advertise my book ISBN-13 : 978-1501515132.
  45. Re:partial security / insecurity -- what's the poi by TheRaven64 · · Score: 1

    It is my understanding that there is some sort of handshake between the card company and the chip to authenticate

    This is half true. The EMV protocol allows the bank to authenticate the card, but doesn't allow the card to authenticate the bank. This makes some forms of attack possible if you MITM the connection.

    --
    I am TheRaven on Soylent News
  46. Re:partial security / insecurity -- what's the poi by TheRaven64 · · Score: 1

    I'm perfectly happy using chip-only and stopping the pointless signatures. But, I shall retain the right to view my statement and dispute a fraudulent charge. I refuse to use a PIN when the banks try to bundle that with a shift in liability and a presumption that their little toys are invulnerable to fraud.

    That's not how the liability shift worked, in the UK at least. If you use a contactless payment (which is limited in amount) or if you use a PIN, it's the bank's liability if it's fraudulent. If you use a signature, it's the merchant's liability. It's never the cardholder's liability (at least on paper - there have been a couple of cases where banks have tried to pretend it's impossible for the fraud to take place. Fortunately, those of my colleagues involved in demonstrating weaknesses in the EMV protocol were happy to turn up as expert witnesses and inform the court that the banks were full of shit).

    --
    I am TheRaven on Soylent News
  47. Re:partial security / insecurity -- what's the poi by TheRaven64 · · Score: 1

    Replay wouldn’t work either since the transaction challenge contains a pseudo random number that is signed by the card along with payment information. The number is different for each transaction.

    The second half of that is true. The first half is what the spec says, but a significant number of uses use an incrementing counter, so if you do two transactions in a shop you can predict the value. Oh, and I seem to remember that it's only a 16-bit value, so if you can trick the card into doing a bunch of retries (which isn't too difficult, because the protocol doesn't allow the card to authenticate the bank, only the bank to authenticate the card) then you can just get the card to generate all possible signatures for a transaction and present the on that the bank asks for.

    Note that although most of the EMV attacks were demonstrated several years ago, we've not seen any evidence that they are in widespread use, because the equipment required to do them is fairly complex. If you're going to that much effort, then there are ways of stealing much more money with the same probability of being caught.

    --
    I am TheRaven on Soylent News
  48. Re:partial security / insecurity -- what's the poi by radarskiy · · Score: 1

    "Americans will never learn a PIN number"

    Americans use PINs for debit cards reasonably well.

  49. Re: partial security / insecurity -- what's the po by Anonymous Coward · · Score: 0

    My most recent card doesn't have that at all. But, in general that box is about agreeing to the cc terms and nothing else.

    It's a target card, so it might just be because it's not on the usual network.

  50. Bad news by Anonymous Coward · · Score: 0

    If you don't have to sign your name much anymore as it has become with me, your signature will become little more than a scribble (like mine). Writing is kind of like being fitted with braces. You have to wear a retainer at night the rest of your life or your teeth will revert to crooked again.

  51. Re:partial security / insecurity -- what's the poi by Anonymous Coward · · Score: 0

    It was silly for the card networks and banks to chicken out on implementing Chip + PIN.

    All of Europe, rest of world can deal with using a PIN. What's so special about the US? .

    The US is a scammer's safe-haven, moreso than Nigeria.

  52. Chip and pin was broken in 2007 by davecb · · Score: 1

    Requiring a signature was insisted upon by customers, noit vendors. People require a way to prove that they didn't authorize a charge, especially in the UK where the card vendors claimed that a PIN was "unbreakable" and there was no fraud. The courts eventually caught on, and now require the vendors to prove that the customer authorized the charge.

    --
    davecb@spamcop.net
  53. Re:partial security / insecurity -- what's the poi by Anonymous Coward · · Score: 0

    When it was proposed in the US years ago, the tone was very much "this is unbreakable" and the cardholder would be on the hook (based on a presumption that they shared their PIN if a transaction went through). There was massive backlash against this and I think that left us where we are and also poisoned the well for future changes. Maybe they will try again when all the older folks die out and the memory fades.

    Historically, many cardholders in the US experienced this sort of bias for debit/ATM cards versus credit cards. We can contest a credit charge without paying it. Debit would go through and it was a much harder uphill battle to ever get payments reversed. For folks with those memories, a PIN goes with a debit card and we are much less promiscuous about where we will use those cards. To this day, I consider my debit card as just my ATM card. I would never use it with a merchant as I would never type my PIN into anything other than my own bank's teller machines.

    I don't think US cardholders see any upside to adopting PINs for credit card transactions. The card-only transaction will be quicker, the current liability protections are what we expect, and we don't care about the effects on merchants or processors. We know (cynically) that any potential reduction in fraud rates will line the pockets of bankers, not us.

    I wish there would be a card-reader option for web browsers so we could have card-present transactions for online purchases and stop the frequent sharing of card numbers and CV codes. I'd be happy for it to be impossible for merchants to perform recurring charges after one encounter with a card, as well as stopping all the fraud that can happen when card numbers are stolen out of merchant systems.

  54. Re:partial security / insecurity -- what's the poi by TheRaven64 · · Score: 1

    I wish there would be a card-reader option for web browsers so we could have card-present transactions for online purchases and stop the frequent sharing of card numbers and CV codes. I'd be happy for it to be impossible for merchants to perform recurring charges after one encounter with a card, as well as stopping all the fraud that can happen when card numbers are stolen out of merchant systems.

    About seven or eight years ago, a company produced credit cards that had a button on them that would generate a one-time code displayed on a small LCD on the card. The battery was good for a couple of years of normal use and the code could be used as the CVV for CNP payments - each generated code is good for one transaction and is then not generated again for at least a few hundred transactions. It was trialled in, as I recall, Singapore, but at the end of the trial banks decided that the more expensive cards would cost them more than just eating the fraud as part of the cost of doing business.

    The closest thing today for online payments is Apple Pay. When you buy something online using Apple Pay from an iOS device, it runs the full EMV protocol with your endpoint being a software implementation running in the Secure Element. The Secure Element is also responsible for verifying fingerprints, so the entire process can be locked using your fingerprint. In theory, no code running on the application processor (i.e. iOS and iOS processes) are unable able to interfere (other than to attempt to MITM the connection between the secure element and the remote site) and the private key never leaves the secure element. Some Android phones implement Google Pay using a similar mechanism with TrustZone protecting the EMV endpoint. It would have been nice if the TPM spec had included a mechanism for running an EMV endpoint for standard x86 machines.

    --
    I am TheRaven on Soylent News
  55. Re: partial security / insecurity -- what's the po by Jarik+C-Bol · · Score: 1

    Here in americastan you just dial a phone number thats on a sticker on the card, give the computer a few identifying pieces of information about yourself and your card, and it activates. PIN being optional because we're twits.

    --
    I've decided to Diversify my Holdings. I've divided my cash between my left and right pockets, instead of all in one.
  56. Re:partial security / insecurity -- what's the poi by Jarik+C-Bol · · Score: 1

    Yeah, our phone activation system is extremely convenient for both the customers and the thieves.

    --
    I've decided to Diversify my Holdings. I've divided my cash between my left and right pockets, instead of all in one.
  57. Re:partial security / insecurity -- what's the poi by Anonymous Coward · · Score: 0

    Chip on its own makes card cloning harder. WAY harder. it is down right trivial with mag stripe only.

  58. What about the rest of the world? by CaffeinatedBacon · · Score: 1

    If by long you mean short, and slow you mean fast. Also by today you mean many years ago.

  59. Chip cards by DrYak · · Score: 1

    Early 1980s already had chip cards, mostly used for phone booth (remember, back in the dinosaur era when your phone couldn't fit in your pocket and you needed to call from public ones).
    Wikipedia mentions in french the "Télécate" in France in 1983 as a first massive deployement beyond local tests .
    The patent itself dates back from 1974.

    The first chip payment system is the "Carte Bleure" in France, 1986 according to wikipedia (and by 1992 there were nothing else but chip cards)
    Germany also had GeldKarte as a local older chip payment system.

    But yeah, the EMV standard came much later, in the 1990s. So lots of payment system were still magstripe.
    But in 1980s there were already chips. Just not as widespread.

    --
    "Sufficiently advanced satire is indistinguishable from reality." - [Tips: 1DrYakQDKCQ6y52z6QbnkxHXAocMZJE61o ]
  60. What a strange world by rbpOne · · Score: 1

    that you USAsians live in.