The EMV Chip Isn’t as Secure as We Thought

The EMV Chip Isn't as Secure as We Thought

The transition to the EMV chip has not been an easy one. I don’t know about you but I face major anxiety when I find myself at the register not knowing if I should swipe my card or insert it. God bless those who put a sign on their transaction machines indicating which route to take.

But all the fuss is justified when you think about all the security benefits that come from the EMV chip, right? Turns out they aren’t as secure as we once thought.

Computer security researchers at the payment technology company, NCR, demonstrated how credit card thieves can rewrite the magnetic strip code to make it appear like a chipless card again. This allows them to keep counterfeiting, just like they did before the chips were installed in the cards.

This glaring hole in the EMV chip system is possible because of the way many retailers are upgrading their payment machines. They are not encrypting the transaction.

NCR presented their findings at the Black Hat computer security conference on Wednesday, August 4, and showed that EMV doesn’t solve everything. The discovery of this flaw bolsters the retail industry’s complaints against the upgrade, which was forced upon them by banks. Retailers could spend millions of dollars upgrading to EMV and still not protect their customers from massive credit card theft.

To make the situation even worse, payment terminal makers keep producing machines that don’t have the encryption by default. Vendors who sell and install these machines at shops don’t simply flip the switch to encrypt; they have to buy into the extra security.

The NCR advices shops to “encrypt everything” in a transaction and asks customers to use the payment apps on their phones instead of physical cards whenever they can.

About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

New Products

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.