Hacker News new | ask | show | jobs
by pfranz 849 days ago
They're not copying or spoofing the chip on the card, they're skimming the mag stripe and getting the fixed credit card number, right? Then stealing your pin (second factor). I'm not 100% sure what methods they use for purchasing after collecting this info.

Couldn't we stop this today by rejecting transactions that use a mag stripe? Or just severely restricting them? My understanding is less secure transaction types have higher fees specifically because of fraud.

Mandating tap-to-pay (which has been in wide use for something like over 20 years now) eliminates this capture vector. I would love to opt-in to totp as a pin...while its used widely in tech I can see concerns with mandating it widely.

I feel like making this way more secure can be done with the tech already out there. It's the incentives that are preventing that from happening; i.e. the user is on the hook or it's "cheaper" to let the money get stolen.

1 comments

I need to look more at how tap-to-pay works, because unless it's doing something very clever I'm unclear how that prevents skimmers or other MITM attacks from still working.