Hacker News new | ask | show | jobs
by Nursie 4336 days ago
Depends on the card, which therefore depends on the risk profile that the issuing bank is willing to undertake.

There's a list of acceptable verification methods in the card, and a list of methods the device is can perform is contained in the terminal software. The intersection of these is what's usually performed.

(background - I wrote my first EMV processing kernel in 2001 and am currently working on a bluetooth-enabled card-reader and PIN entry device that looks like it will directly compete with the square device)