The EMV Chip Isn’t as Secure as We Thought

The EMV Chip Isn't as Secure as We Thought

The transition to the EMV chip has not been an easy one. I don’t know about you but I face major anxiety when I find myself at the register not knowing if I should swipe my card or insert it. God bless those who put a sign on their transaction machines indicating which route to take.

But all the fuss is justified when you think about all the security benefits that come from the EMV chip, right? Turns out they aren’t as secure as we once thought.

Computer security researchers at the payment technology company, NCR, demonstrated how credit card thieves can rewrite the magnetic strip code to make it appear like a chipless card again. This allows them to keep counterfeiting, just like they did before the chips were installed in the cards.

This glaring hole in the EMV chip system is possible because of the way many retailers are upgrading their payment machines. They are not encrypting the transaction.

NCR presented their findings at the Black Hat computer security conference on Wednesday, August 4, and showed that EMV doesn’t solve everything. The discovery of this flaw bolsters the retail industry’s complaints against the upgrade, which was forced upon them by banks. Retailers could spend millions of dollars upgrading to EMV and still not protect their customers from massive credit card theft.

To make the situation even worse, payment terminal makers keep producing machines that don’t have the encryption by default. Vendors who sell and install these machines at shops don’t simply flip the switch to encrypt; they have to buy into the extra security.

The NCR advices shops to “encrypt everything” in a transaction and asks customers to use the payment apps on their phones instead of physical cards whenever they can.

About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

New Products

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.