Chip & PIN Fraud Explained - Computerphile

TL;DR
Chip & PIN fraud works by exploiting transaction flows, compromised terminals, and data that is not properly cryptographically authenticated. Introduced in Britain from 2003 to 2005, the system made chip counterfeiting harder, yet criminals harvested card and PIN details, produced magnetic-stripe forgeries, and enabled no-PIN purchases with man-in-the-middle devices. Read on to understand each attack and why overall fraud increased.
Transcript
In the old days cards from the 1960's had a magnetic strip right so that when you did a transaction the terminal would read the data on the card's magnetic strip but from 2003 in the UK you started to get chips as well. So the information is kept in this semiconductor chip and that makes it significantly more difficult to counterfeit. . To counterf... Read More
Key Insights
- 💨 Chip & PIN cards were introduced to counter fraud, but criminals quickly adapted and found various ways to cheat the system.
- ❓ Intercepting transactions and manipulating transaction details have become common tactics used by criminals to carry out fraud.
- 🎴 Counterfeit cards and stolen card details are still a significant concern, even with the implementation of chip & PIN technology.
- 😮 Fraud rates initially dropped but then increased with the rise of online fraud and exploitation of chip & PIN devices.
- 🤪 Criminals have gone as far as compromising chip & PIN terminals during the manufacturing and distribution process.
- 🔒 The evolving fraud landscape requires continuous efforts to improve protocols and security measures.
- 🐿️ Awareness about the hazards of using chip & PIN cards in questionable establishments is crucial to prevent falling victim to fraud.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How does Chip & PIN fraud work?
Criminals exploit several parts of the payment process rather than directly counterfeiting the chip. They can compromise terminals to capture card and PIN details, use those details for magnetic-stripe forgeries, or place a man-in-the-middle device between a stolen card and the terminal to manipulate verification messages.
Q: Why are chip cards harder to counterfeit than magnetic-stripe cards?
A magnetic-stripe card can be counterfeited by copying its data onto another card. Extracting a chip’s keys requires lasers, probing stations, and other expensive equipment, and the process works only some of the time.
Q: When was Chip & PIN introduced in Britain?
Chip & PIN was introduced in Britain from 2003 to 2005. It had been designed in the late 1990s based on earlier experiments from the early 1990s.
Q: Did Chip & PIN reduce overall card fraud?
Fraud initially fell slightly in shops, and counterfeit-card fraud also decreased at first. Overall fraud rose because criminals moved online, while counterfeit-card fraud increased again after roughly six months as compromised Chip & PIN devices were used to harvest payment details.
Q: How were stolen Chip & PIN details used to create counterfeit cards?
Compromised terminals captured card details and PINs, which criminals used to make magnetic-stripe forgeries. Those forged cards could then be used at ATMs that still accepted magnetic-stripe transactions.
Q: What happened with the compromised Chip & PIN terminal in Girton?
A compromised terminal at a BP garage in Girton, Cambridgeshire, led to money being taken from the cash machines of a couple of hundred local people. The withdrawals occurred in Thailand.
Q: How can criminals capture card and PIN data from a payment terminal?
One method removes part of a terminal’s back, adds electronics, and accesses the serial link between the PIN pad and the card. That link carries card details in one direction and the PIN in the other, providing the information needed for magnetic-stripe forgeries.
Q: How does a man-in-the-middle device enable no-PIN fraud?
A device placed between a stolen card and the terminal changes the messages passing between them. It tells the terminal that the card accepted the correct PIN while telling the card that a signature verified the transaction, allowing a purchase without entering the PIN.
Summary & Key Takeaways
-
Chip & PIN cards were implemented in the UK in 2003 to combat fraud. The introduction of chips on cards made counterfeiting more difficult.
-
However, fraudsters quickly adapted, resorting to online fraud and using chip & PIN devices to harvest card details and create counterfeit mag stripe cards.
-
Criminals also found ways to cheat by manipulating transactions, using devices that disguise PIN verification as signature verification.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from Computerphile 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator