Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Your PIN is actually checked locally by the card before it signs the transaction. Sure, you're vulnerable to a POS system stealing your PIN, but they can't really do anything with it unless they also have your card's private key, which is pretty much impossible to get off the card without destroying it. This is a huge improvement over what it was before, where you only had to copy the mag stripe info to clone the card.


Someone can take that PIN and the magstripe data obtained from the card and use it to withdraw your money from ATMs that don't support Chip and PIN.


Which is why we need to get this adoption completed ASAP so we can eliminate the magstripes on our cards.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: