Card Companies Insecure About Security

creditcards195.jpg

My opinion

I’m not a security expert but I’ve always suspected that RFID (think Chip and PIN credit cards) could be compromised. If it can be read by a legitimate reader then it can be read. If you can read it, you can do bad things with it. The information may be encrypted but it can still be read. You simply use the encrypted format. You don’t really need to know what it says to make a purchase with it.

That’s a bit simplified of course, but the point is that there are holes.

Opinion confirmed?

The other day, one of our members found this and posted it to the alert list. It sums it all up nicely. Do I believe everything in YouTube? No, of course not. But these and those related are pretty convincing.

Check out this YouTube video

And in case you think that the credit card companies don’t know about this, watch this response when Adam Savage of Mythbusters is asked about RFID at the HOPE conference (Hackers On Planet Earth)

And remember that this is the same RFID that the Government wants to use for national security.

Update

On September 4th SlashDot reported that, according to TI, only one lawyer was present and that most of the people on the call were product managers from the Smart Card Alliance. Savage also reaffirmed that he was not on the call himself and that the decision was made by the production company.

Bottom line

It is pretty clear to me that Chip and PIN is about as safe as any credit card. Read that any way you like.

Similar Posts:

Bookmark and Share

About Tom

Tom Mahoney is the Founder and Director of Merchant911, a site dedicated to helping e-commerce merchants.
This entry was posted in credit card fraud, fraud, fraud trends and tagged , , . Bookmark the permalink.

2 Responses to Card Companies Insecure About Security

  1. Scott says:

    Done my part to forward this link on to all family and friends….need to make everyone we know aware of how bad this really is. :)

  2. Pingback: United States - Credit Card Fraud is about to increase | Merchant911 - Fraud Prevention for Merchants

Leave a Reply

Your email address will not be published.

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>