|
|
|
|
|
by CaptainZapp
1150 days ago
|
|
Funnily enough my card doesn't work contactless with PIN. I need to shove it into the chip reader to make it work. Which, thinking about it, is exactly how it should be. The closed circuit of chip reader and pin was always touted as super secure. Then suddenly, you could pay contactless with most cards regardless of the amount and enter the PIN. Too me this always seemed to subvert the "super secure" chip & PIN authentication. It's a small "hardship", really. On small amounts contactless works just dandy and having to present the physical card to the chip reader for larger amounts makes me actually feel better. |
|
Chip and Pin usually implies offline PIN. The terminal supplies the PIN, after a one-way transform of some sort IIRC* to the chip on the card, which then verifies it locally against a stored version of that same hash or whatever.
With contactless you're doing online PIN. The terminal applies a transform and some sort of asymmetric key encryption to the PIN, and this gets sent to your bank. There's nothing any less secure here.
(* I wrote an EMV 'kernel' a long, long time ago, in about 2002, and some more PIN block processing code about 8 years back. So it's been a while!)