The EMV Chip Isn’t as Secure as We Thought

The EMV Chip Isn't as Secure as We Thought

The transition to the EMV chip has not been an easy one. I don’t know about you but I face major anxiety when I find myself at the register not knowing if I should swipe my card or insert it. God bless those who put a sign on their transaction machines indicating which route to take.

But all the fuss is justified when you think about all the security benefits that come from the EMV chip, right? Turns out they aren’t as secure as we once thought.

Computer security researchers at the payment technology company, NCR, demonstrated how credit card thieves can rewrite the magnetic strip code to make it appear like a chipless card again. This allows them to keep counterfeiting, just like they did before the chips were installed in the cards.

This glaring hole in the EMV chip system is possible because of the way many retailers are upgrading their payment machines. They are not encrypting the transaction.

NCR presented their findings at the Black Hat computer security conference on Wednesday, August 4, and showed that EMV doesn’t solve everything. The discovery of this flaw bolsters the retail industry’s complaints against the upgrade, which was forced upon them by banks. Retailers could spend millions of dollars upgrading to EMV and still not protect their customers from massive credit card theft.

To make the situation even worse, payment terminal makers keep producing machines that don’t have the encryption by default. Vendors who sell and install these machines at shops don’t simply flip the switch to encrypt; they have to buy into the extra security.

The NCR advices shops to “encrypt everything” in a transaction and asks customers to use the payment apps on their phones instead of physical cards whenever they can.

About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

New Products

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.