Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"In america, credit cards were 'good enough' compared to what was in china"

I disagree. CC fraud was unknown to me until I moved to the USA. The security chip was not used for a very long time in the USA and just started to be a thing. First version of chip enabled CCs had no pin. I am not sure about good enough.



The chip doesn't add any additional security to the card compared to what was available previously; US credit card companies have only added it to avoid additional legislation from Congress.

Also, the whole reason Europe had the chip and the US didn't was because phone lines in the US were better than ones in Europe, so it was vastly easier to do a quick authorization check in the US. The phone lines were not "good enough" in Europe, so the chip and pin system was created as a way to authenticate locally.


Actually, the data on the magnetic stripe was in plaintext. The chip has a digitally signed copy of that data. This allows the bank to authenticate the card as valid and eliminates attacks where a fake card is made with stolen data put onto the stripe.

This does nothing for online payments but very effectively curbs fraudulent card present transactions.


It goes beyond that, unless the US implementation is different to the one i am (somewhat) familiar with.

The chip is an active participant in the authentication.

it will receive digital signatures from the bank and the terminal, and if said signatures are found valid, release the payment info stored.


I do know the US implementation is different, but I do not know if it is different in regards to this highly relevant information.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: