Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The chips are most likely for EMV[1], which essentially puts some intelligence on the card in the form of an IC chip, and allows the card to make approve/deny decisions based on rules of the issuing bank. With EMV cards, the transaction is more like a negotiation, and the card may reject at any point.

Of course, like anything, there will be vulnerabilities, and in the interests of usability, some issuing banks will relax restrictions.

Because of the crypto involved in the back and forth communication between hardware and card, EMV transactions piss off a lot of customers, it can easily take 2-3 times more time to process a transaction when compared to a mag-swipe.

Though it does reduce the chance of your card getting skimmed. (Skimming is where your details are captured during the swipe. Yes, a swipe through the appropriate device reveals all the information required to completely duplicate the card.)

[1] http://en.wikipedia.org/wiki/EMV



Actually, in Norway there are some banks that use the credit card chip for two factor authentication (the same which is used for EMV). You put the card into a small "reader" with a display, and out pops a number that you use when logging into the online bank. Most banks however use a dedicated device with a time-based one time password.

I'm not sure why, but I've seldom seen EMV transactions take longer than a regular swipe, but this might be because both 1 second * 3 is still not that big of a deal. (Or for all I know, it might be because they are only validating the credit card number..)

The interesting thing is that skimming is still possible, at least in Norway. It still happens that there is some kind of communication problem with the EMV system, and swiping the card is the fallback option. I guess this option will be turned off as soon as it works "all the time" and they can remove the magnetic stripe.


> there will be vulnerabilities

Correct, in fact there already are. Most of those will require at a minimum a hardware hack or access to transactions 'in progress' (modified terminals) and will usually only gain access to the data that is stored on the magnetic stripe, not to the other data stored on the chip (the chip contains a duplicate of the stripe data and some other data only available on the chip and not sent out over the wire used in challenge/response fashion).

The system is not 100% secure but is a bit better than just having a password and the fact that it requires access to the original card makes it a lot harder still (those cards can be stolen though, and combined with a bit of hardware and a 'yes' card (a card that always responds 'transaction authorized') you could fool online payment terminals).

But that's still a step removed from gaining complete control of a bank account using web based banking and a password.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: