Comment Re:sigh, lamestream press strikes again (Score 2) 213
Point of Sale terminals keep their 3DES encryption keys in firmware within a tamper-resistant module. Even with advanced technology like plasma ablation and electron microscopy, it is believed to be impractical to extract the key. The keys are loaded by a courier who swipes special cards while the device is in maintenance mode.
This permits the POS stations to be used over an insecure line to the payment processor, and cleartext is never present anywhere outside the sealed module, from which the key cannot be recovered.
So unless you tap the keypad, you cannot have access to the unencrypted PIN. Stealing data is insufficient to obtain the information necessary to use the card.
That having been said, if there is any way you can do a trial of a large number of PINs, it is trivial to try all 10,000 possibilities, and see which one works, no matter how strong the encryption is.