Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah, I realized that recently as well. Apparently when they first rolled out the chip readers, people complained that the authentication took too long (5-15 seconds), so now all you have to do is stick the card in the chip reader, no PIN required (in most stores at least). Brilliant! Consumer behavior effectively turned the chip back into the old mag-stripe system.


Chips are better than magstripes. PINs versus signatures is orthogonal. From the original article:

"Even ancient magstripe credit cards share most of these advantages. Their main weakness is that a physical attacker can clone rather than steal your card, which is much harder to detect. That's the only real advantage of chip cards: they can't be trivially copied."

When you think about it, having to physically possess a card (and being able to disable a card when you realize you've lost it) provides 99% of the security benefit.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: