Chip and Sin

Over the Kitchen, DK not only refrains from his usual line in invective but relates a rather disturbing story about the use of Chip and Pin cards which resulted in this statement being made by a senior member of staff in HBOS’s retail banking division…

Up to 40 minutes after any Chip & PIN card transaction, the retailer may access your confidential details [this includes your card number and your PIN number] and submit any number of further transactions without your presence or consent. This is perfectly legal practice. The onus is then on the customer to challenge these subsequent transactions with their bank, once the customer actually becomes aware of them.

I beg your pardon?

DK has the full backstory to this, which started out innocently enough with a cock-up at a petrol station but which goes on to raise some fairly serious question marks about whether the Chip and Pin system is quite so secure as the public have been led to think.

One thing that isn’t clear from DK’s article, as I suspect the explicit question wasn’t asked, is quite what HBOS means when it states that ‘the retailer may access your confidential details [this includes your card number and you PIN number]‘.

Do they mean access in the sense of being able to pull up a transaction screen in which this information is already inserted in the relevant place, albeit obfuscated by lines of asterisks – as is common practice when web browsers pull a password out of cookie to save you the bother of typing in [and remembering] your password for loggin in to something like Gmail or Hotmail – or are they actually saying that this information is revealed to the retailer in a transcribable form which could be written down and used at a later date?

One would certainly hope that we’re talking about the former, but can one really be sure?

Second, there this whole business of the retailer being in position submit further transactions using your card details, for up to forty minutes, and without you either being present or even knowing what the hell they’re up to. The potential for fraud in this should be fairly obvious to anyone and it does rather make a mockery of the whole claim that Chip and Pin transactions are much more secure than the old-style swipe and sign way of paying for your shopping.

Third, given that retailers have this kind of access, and that your card details are either stored or still accessible, locally, for forty minute after your original transaction one has to wonder exactly how secure the equipment is in terms of the potential for tampering. Is it possible, yet, for an electronic reader to be attached to a Chip and Pin terminal in such a way as the stored/accessible card information might be downloaded from the system to enternal storage device.

If this hasn’t already been done, then you can bet that it will be in the not too distant future, as from long experience it should be obvious that no matter how secure you think a particular system is, someone, somewhere, will eventually crack it – and in the case of Chip and Pin, and with the increasing use by Supermarkets of ‘self-service’ checkouts, the incentives to develop such a system to enable Chip and Pin cards to be easily cloned is going to be pretty high.

Finally, and as aside, one would presume that the rationale for premitting retailers this kind of access to the system is to allow for corrections to be made when the retailer realises that the customer has been either overcharged (yeah, sure) or undercharged for their purchase but has left the premises before the error has been spotted.

Thinking about that, one cannot help but think of all the shops one has used, especially newsagents (for some reason) where one finds displayed prominantly behind the counter, a sign bearing a legend to the effect that, in the view of the retailer, its the customer’s reposnsibility to check their change before leaving the counter, after which point the transaction is concluded and any mistakes cannot be corrected.

Quite how this sits, legally speaking, I’ve never got around to checking as its generally the kind of thing that one accepts as being a game of swings and roundabouts – sometimes you get given too little change and you lose out, other times you get given too, and if you can make it out the shop without the retailer cottoning on to their mistake then the money’s yours by dint of all the times you’ve lost out the other way. One way or another, the assumption is that, all things being equally, these things will break even over time, so you take the occasional loss philosophically as long its a matter of loose change and note something like a fiver ot tenner.

Obviously, if retailers can alter or transactions after the fact without your knowledge then that alters the nature of the game and, in turn, make the question of the legality of the ‘please check you change’ sign a mater worth pursuing.

One way or another, the lesson here has to be not to assume that Chip and Pin is in anyway foolproof, while at the same time, the question has to be asked as to why the banks have neglected to mention any of this up to now?

Any blogging Parliamentarians about who’d care to do the asking?

2 Comments
The Administration of Things

Aside from being a day for dissecting the latest set of gushings from dear old Polly Pot, Friday is also Home Office press release day (particularly when there are unpromising statistics that need burying).

And so, on the Labour Party website, we find that Dr Demento doing his level best to polish up his shiny, patent leather, jackboots by administering a good kicking- Continue Reading...

3 Comments
Doing Semantics

On the back of the release of the report ‘Doing God: A future for faith in the public square‘ by the Theos ‘think-tank’, AC Grayling not only describes the report as ‘confused’ – discursive, meandering, sophistic, would all have been equally valid adjectives – but also gives the authors a well-deserved lesson in semantics.

Needless to say, this is required reading.… - Continue Reading...

No Comments
Oops…

Not sure how this will go down with the PLP, but while mooching through some of the search terms that have brought people here when they were obviously looking for something else entire, I’ve just discovered that on Yahoo UK search, I’m now the top result for ‘Labour Ministry UK’, beating the official Labour Party website (and a page on it about the Ministry of… - Continue Reading...

One Comment
Polly Plotless (as usual).

It’s Friday and Polly Pot is in full flow – and remember the Graun have coughed up around £1,400 for what follows.

Labour needs a woman at the top to win female votes back from Cameron

It is amazing that Labour has lost the backing of those who have gained most. But there is a way to reclaim their support

The back story here… - Continue Reading...

No Comments
Archives
Recent Comments
Recommended
Science/Skepticism
Politics
Ministry of Truth RSS 2.0
Ministry of Truth - Twitter
  • If New Labour is dead – what replaces it? September 2, 2010
    Sunder and Left Futures do a good job of rebutting Blair’s claim that Labour lost the election because it was insufficiently New Labour. But there’s something to add. […]
    Chris Dillow
  • In 2010, Tony Blair was so unpopular that… September 2, 2010
    […]
    Don Paskini
  • Will the web always be a hive for conspiracy theories? September 2, 2010
    On Sunday, Demos released a report, The Power of Unreason. We looked at the role conspiracy theories play in extremism, violence, and terrorism. Extremist groups use conspiracy theories to recruit, to justify violent acts and to maintain an ideology that sees violence as the answer to the world they find themselves within. Conspiracy theories can therefore b […]
    Guest
  • Theories: Splitting Linguistic Hairs and the Work of Anne Elk (Miss) August 29, 2010
    The work of Anne Elk (Miss), undoubtedly one of the overlooked intellectual giants of our age, serves to remind us of the importance of theories. And indeed, how anyone can hold one … ahem! I cannot gainsay Miss Elk’s evident expertise in the area of paleantology since I know nothing of Brontosauruses. But I was fascinated to hear the ‘T’ word occur […]
    Jourdemayne
  • Middle Age Spread August 29, 2010
    Once again, there are stories in the press about the rise of Sexually Transmitted Infections (STIs) in young people (under 24), with half a million new cases in the UK in the last year, a rise of 3% from the 2008 figures. There's an excellent analysis of the data and the media response by Dr Petra Boynton who also deals adeptly with an ill-informed resp […]
    Tessera
  • Amateaur astronomers discovery rotating pulsar using Arecibo August 25, 2010
    [2:07 begins the commentary by the discoverers] READ MORE read more […]
    Casey