Hacker News new | ask | show | jobs
by snuxoll 3683 days ago
Comparing signatures to the back of the card is useless, most people do not sign their marks THAT consistently and it's entirely possible for someone committing fraud to make something "good enough" that would pass casual inspection from a depressed retail employee (my signature varies depending on how tired I am, how quickly I am trying to just get the hell out of the store, how much caffeine I have - or haven't - had that day, etc). Pretty much the only reason they are even ON your card is a place for you to accept the terms of your cardholder agreement (which is virtually useless since every card I've had since I started using credit/debit cards has me accept them during the card activation process or just applying for the card).

EMV PIN's are a crappy solution too, a four digit PIN is all banks in Europe need to consider a transaction "genuine" even though numerous attacks against EMV are already in the wild - makes for great fun trying to reverse fraudulent charges in many stories I've read online.

1 comments

Stories you've read online?

There is zero hassle reversing fraudulent charges, in many cases the bank itself will tell the person they think something is fraudulent, and a quick "Yeah that was me" or "Oh dear that wasn't me" is all it takes.

4 digits is enough security given it requires having the card itself, and locks out after a few incorrect attempts.

And security is about traceability not preventability.

> There is zero hassle reversing fraudulent charges,

For fraud where the pin is used? In the UK if the criminal uses your pin you're going to struggle to get the bank to repay you.

"banks / credit card companies always repay the victims of fraud" is a bit of a meme, and it's dangerous because it's often not the case. The repay in certain clearly limited cases, but not in others.

I've never had a UK bank refuse to reimburse fraudulent transactions for me. Usually you just have to report it promptly and sign a statement to say it wasn't you. The bottom line is for relatively small transactions (say a few grand or less), it's not worth their time to investigate.