Hacker News new | ask | show | jobs
by WorldMaker 3113 days ago
The sad fact is the terminals are painfully slow because US banks don't think US customers want or are capable of using PINs.

When you use a PIN you get a nice two factor signature from the card chip: it signs the current timestamp and the PIN you knew, and can do both as quickly as chip's processing capability and the bandwidth between the chip and terminal allows.

US banks came up with a dumb compromise just like most of their websites use Wish-It-Were-Two-Factor auth and secondary "Security Question" passwords, the chip cards in the US are doing their own Wish-It-Were-Two-Factor: sign a timestamp, wait some amount of wall clock time, sign a different timestamp.

Most of the wait in a chip purchase in the US is artificial just to make sure that two timestamps are "sufficiently" different. US banks should just give people PINs and stop this silliness.

1 comments

> The sad fact is the terminals are painfully slow because US banks don't think US customers want or are capable of using PINs.

Is this conjecture, or do you have actual citations to back this up? Those same banks have been issuing debit cards with PINs for a couple decades.

It's a bit intentional hyperbole, but not by much.

Every chip card I've received to date from several different major US banks has included some variation of "Great news! You don't need to learn or use a PIN to use this card."

My personal reaction every time has been, "But what if I want to use a PIN?" and this far I've never seen a satisfactory answer in those same letters or on those banks' own websites.

Admittedly that is purely anecdotal, as far as citations go, but in my mind it seems pretty clear what these banks think about PINs for credit cards.