Hacker News new | ask | show | jobs
by mntwiddler 4744 days ago
Definitely an issue. However if a card has been reported stolen wouldn't it just be deactivated and not work whether it was used at an at home swipe or swiped at a business?
1 comments

The physically possesses part is an important part of that equation. If I hack the users computer and steal the swipe info then I can retransmit the data and home swipe without physical possession of the card. Since the user never lost the card he is less likely to report it lost or stolen in a timely manner. A smart credit card would generate a known nonce making retransmited data worthless, and restore the likely physically has the card factor.