{"id":10162,"date":"2016-08-06T11:51:14","date_gmt":"2016-08-06T11:51:14","guid":{"rendered":"http:\/\/www.biphoo.com\/bipnews\/?p=10162"},"modified":"2016-08-06T12:02:59","modified_gmt":"2016-08-06T12:02:59","slug":"security-flaw-in-credit-card-chip-revealed","status":"publish","type":"post","link":"https:\/\/www.biphoo.com\/bipnews\/technology\/security\/security-flaw-in-credit-card-chip-revealed.html","title":{"rendered":"Security Flaw in Credit Card Chip Revealed"},"content":{"rendered":"<h2 style=\"text-align: justify;\"><strong><span style=\"color: #000000; font-size: 18pt; font-family: Arial,Helvetica,sans-serif;\">Security Flaw in Credit Card Chip Revealed<\/span><\/strong><\/h2>\n<p style=\"text-align: justify;\"><span style=\"color: #000000; font-size: 12pt; font-family: Arial,Helvetica,sans-serif;\"><strong>Security Flaw in Credit Card Chip Revealed\u00a0<\/strong>: Computer researchers claim to have found yet another flaw in the upgrade to the chip-based credit cards in the United States.<\/span><\/p>\n<p><span style=\"color: #000000; font-size: 12pt; font-family: Arial,Helvetica,sans-serif;\">The chip on these credit cards have been praised for making them nearly impossible to counterfeit. While the cards also contain a magnetic strip, that strip is supposed to tell the payment machine to use the chip.<\/span><\/p>\n<p><span style=\"color: #000000; font-size: 12pt; font-family: Arial,Helvetica,sans-serif;\">But there&#8217;s a relatively easy way to knock down that safeguard.<\/span><\/p>\n<p><span style=\"color: #000000; font-size: 12pt; font-family: Arial,Helvetica,sans-serif;\">Computer security researchers at the payment technology company NCR demonstrated how credit card thieves can rewrite the magnetic stripe code to make it appear like a chipless card again. This allows them to keep counterfeiting &#8212; just like they did before the nationwide switch to chip cards.<\/span><\/p>\n<p><span style=\"color: #000000; font-size: 12pt; font-family: Arial,Helvetica,sans-serif;\">They presented their findings at the Black Hat computer security conference on Wednesday.<\/span><\/p>\n<p><span style=\"color: #000000; font-size: 12pt; font-family: Arial,Helvetica,sans-serif;\">This claim of a glaring hole in EMV, the chip-based system, is possible because of the way many retailers are upgrading their payment machines: They&#8217;re not encrypting the transaction. <\/span><\/p>\n<p><span style=\"color: #000000; font-size: 12pt; font-family: Arial,Helvetica,sans-serif;\">\u00a0&#8220;There&#8217;s a common misperception EMV solves everything. It doesn&#8217;t,&#8221; Patrick Watson, one of the researchers, told CNNMoney.<\/span><\/p>\n<p><span style=\"color: #000000; font-size: 12pt; font-family: Arial,Helvetica,sans-serif;\">On Thursday, a banking and retail industry group that monitors the EMV system cast doubt on the theory.<\/span><\/p>\n<p><span style=\"color: #000000; font-size: 12pt; font-family: Arial,Helvetica,sans-serif;\">&#8220;If the data on the magnetic stripe is altered it might fool the terminal,&#8221; said U.S. Payments Forum director Randy Vanderhoof. But on the back end, the system would &#8220;reject the transaction.&#8221;<\/span><\/p>\n<p><span style=\"color: #000000; font-size: 12pt; font-family: Arial,Helvetica,sans-serif;\">But the discovery of this possible flaw bolsters the retail industry&#8217;s complaints against the upgrade, which was forced upon shops by banks.<\/span><\/p>\n<p><span style=\"color: #000000; font-size: 12pt; font-family: Arial,Helvetica,sans-serif;\">The National Retail Federation has long complained about the upgrade, which is estimated to cost American retailers $25 billion. <\/span><\/p>\n<p><span style=\"color: #000000; font-size: 12pt; font-family: Arial,Helvetica,sans-serif;\">\u00a0This latest research shows that retailers could spend millions of dollars upgrading to EMV and still not protect their customers from a massive credit card theft like the Target and Home Depot hacks two years ago.<\/span><\/p>\n<p><span style=\"color: #000000; font-size: 12pt; font-family: Arial,Helvetica,sans-serif;\">Adding to the problem, payment terminal makers keep producing machines that don&#8217;t have the encryption by default.<\/span><\/p>\n<p><span style=\"color: #000000; font-size: 12pt; font-family: Arial,Helvetica,sans-serif;\">And vendors who sell and install these machines at shops don&#8217;t simply flip the switch and turn on encryption. Retailers have to pay extra for basic security. <\/span><\/p>\n<p><span style=\"color: #000000; font-size: 12pt; font-family: Arial,Helvetica,sans-serif;\">\u00a0The major machine makers, Verifone and Ingenico, both asserted they offer point-to-point encryption on retailer&#8217;s machines &#8212; but it&#8217;s up to retailers and their partners to turn it on.<\/span><\/p>\n<p><span style=\"color: #000000; font-size: 12pt; font-family: Arial,Helvetica,sans-serif;\">Currently, retailers focus on protecting the computer network that support their payment system. But that leaves the actual conversation between your credit card and the machine in plain text, readable to any hacker who breaks into the system.<\/span><\/p>\n<p><span style=\"color: #000000; font-size: 12pt; font-family: Arial,Helvetica,sans-serif;\">It&#8217;s a mistake, said Mike Weber, vice president at the IT auditing firm Coalfire.<\/span><\/p>\n<p><span style=\"color: #000000; font-size: 12pt; font-family: Arial,Helvetica,sans-serif;\">&#8220;They&#8217;re assuming the environment is okay,&#8221; he said. It&#8217;s not.<\/span><\/p>\n<p><span style=\"color: #000000; font-size: 12pt; font-family: Arial,Helvetica,sans-serif;\">During their presentation, the NCR researchers advised shops to &#8220;encrypt everything&#8221; in a transaction. They also said consumers should pay with special apps on their phones and watches whenever the high tech option is available. <\/span><\/p>\n<p style=\"text-align: justify;\"><span style=\"color: #000000; font-size: 8pt; font-family: Arial,Helvetica,sans-serif;\"><span style=\"font-size: 10pt;\"><strong><span style=\"color: #ff0000;\">Source <\/span><\/strong><\/span>: http:\/\/money.cnn.com\/2016\/08\/03\/technology\/credit-card-chips-flaw\/index.html<\/span><\/p>\n<div class=\"fb-background-color\">\n\t\t\t  <div \n\t\t\t  \tclass = \"fb-comments\" \n\t\t\t  \tdata-href = \"https:\/\/www.biphoo.com\/bipnews\/technology\/security\/security-flaw-in-credit-card-chip-revealed.html\"\n\t\t\t  \tdata-numposts = \"10\"\n\t\t\t  \tdata-lazy = \"true\"\n\t\t\t\tdata-colorscheme = \"light\"\n\t\t\t\tdata-order-by = \"social\"\n\t\t\t\tdata-mobile=true>\n\t\t\t  <\/div><\/div>\n\t\t  <style>\n\t\t    .fb-background-color {\n\t\t\t\tbackground: #ffffff !important;\n\t\t\t}\n\t\t\t.fb_iframe_widget_fluid_desktop iframe {\n\t\t\t    width: 630px !important;\n\t\t\t}\n\t\t  <\/style>\n\t\t  ","protected":false},"excerpt":{"rendered":"<p>Security Flaw in Credit Card Chip Revealed Security Flaw in Credit Card Chip Revealed\u00a0: Computer researchers claim to have found yet another flaw in the upgrade to the chip-based credit cards in the United States. The chip on these credit cards have been praised for making them nearly impossible to [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":10163,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[974],"tags":[5565,5563,5564,5562,5566,5561],"class_list":["post-10162","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-computer-security","tag-credit-card-chip-security","tag-credit-card-chips","tag-cyber-security","tag-hacking","tag-security-flaw-in-credit-card-chip-revealed"],"_links":{"self":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts\/10162","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/comments?post=10162"}],"version-history":[{"count":0,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts\/10162\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/media\/10163"}],"wp:attachment":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/media?parent=10162"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/categories?post=10162"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/tags?post=10162"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}