{"id":238,"date":"2006-05-10T09:39:52","date_gmt":"2006-05-10T09:39:52","guid":{"rendered":"http:\/\/irdial.com\/blogdial\/?p=238"},"modified":"2006-05-10T09:48:53","modified_gmt":"2006-05-10T09:48:53","slug":"do-not-use-chip-pin-at-tesco","status":"publish","type":"post","link":"https:\/\/irdial.com\/blogdial\/?p=238","title":{"rendered":"Do not use Chip &#038; Pin at Tesco"},"content":{"rendered":"<blockquote><p>>> When I use a shop with the &#8220;swipe and dock&#8221; design card readers (such<br \/>\n>> > > as Tesco) that read your magstripe, chip and ask for a PIN, I despair<br \/>\n>> > > that so many consumers are being taught to accept having their cards<br \/>\n>> > > skimmed in this way.<br \/>\n>> > ><br \/>\n>> > ><br \/>\n> > The PIN is encrypted in the keypad. So do the reports say how it has<br \/>\n> > been recovered?<\/p>\n<p>It is not encrypted in the keypad under the SDA system used in the UK. (There is a more expensive DDA system in which it is encrypted, using the card&#8217;s public key, but UK banks prefer not to pay an extra dollar for cards that are capable of public key crypto.)<\/p>\n<p>The effect is that the PIN travels in the clear from the Tesco PIN pad to the swipe-and-dock reader on the side of the checkout girl&#8217;s PC. So it can be captured by the PC software, along with the transaction data (which even in the case of a chip[ transaction contains all the information you need to clone a mag stripe card). In consequence I will not use a card at Tesco.<\/p>\n<p>It&#8217;s not even necessary to Trojan the keypad (and the Shell terminals were Linux-based, so might have been reflashed rather than had their hardware hacked &#8211; we&#8217;ll have to wait for the trial to find out).<\/p>\n<p>The first such scam I came across was in Holland where a petrol station attendant got PINs by eyeball and for the card data from a network sniffer. That was in 1994. The same technology will still work fine today.<\/p>\n<p>And I recall that when I predicted all this, a year or two ago, the APACS lady said I was speaking &#8216;tosh&#8217;&#8230;<\/p>\n<p>You know, maybe someone should make a formal complaint to the police against APACS for fraud. Fraud is misrepresentation leading to prejudice, and 15 years of persistent lying about ATM system security &#8211; to enable their member banks to deny genuine claims from customers who have been the victims of crimes resulting from the banks&#8217; own negligence &#8211; must surely fall within that definition.<\/p>\n<p>Ross<br \/>\n[&#8230;]<\/p><\/blockquote>\n<p>This is <em>yet another<\/em> reason to not shop at Tesco.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>>> When I use a shop with the &#8220;swipe and dock&#8221; design card readers (such >> > > as Tesco) that read your magstripe, chip and ask for a PIN, I despair >> > > that so many consumers are being taught to accept having their cards >> > > skimmed in this way. >> [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1,29,28],"tags":[],"_links":{"self":[{"href":"https:\/\/irdial.com\/blogdial\/index.php?rest_route=\/wp\/v2\/posts\/238"}],"collection":[{"href":"https:\/\/irdial.com\/blogdial\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/irdial.com\/blogdial\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/irdial.com\/blogdial\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/irdial.com\/blogdial\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=238"}],"version-history":[{"count":0,"href":"https:\/\/irdial.com\/blogdial\/index.php?rest_route=\/wp\/v2\/posts\/238\/revisions"}],"wp:attachment":[{"href":"https:\/\/irdial.com\/blogdial\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=238"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/irdial.com\/blogdial\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=238"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/irdial.com\/blogdial\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=238"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}