Comment Chip-based credit cards is step in right direction (Score 1) 317
I completely disagree with the arguments prematurely concluding chip-based credit cards are insecure. For that matter any system is insecure if you consider a super strong adversary, there will be security problems in any system. Magnetic strip based credits cards should have been replaced long time ago!
And, the chip-based cards are better and step in the right direction even without a user supplied pin. Why?
1. To the best of my knowledge, the chips themselves are tamper proof and its internal logic cannot be replicated easily -- very much so compared to magenetic strips. So you can't steal a card without "actually" and physically stealing the only card. This is much better as it is not hard for one to notice a lost card and immediately report it, making the stolen card invalid and useless. Note that it does not have any information to replicate or steal any identifiable information.
2. Chip's OTP based token transactions are much better than communicating the account number and password. Much of the burden on the POS system being secure is lifted any stored transaction information (which could potentially be stolen) is useless as the information can be used only for one-time use.
And, the reference to Target breach seems to be inaccurate. It is true that a flaw in the backend enabled installing a malware on the POS systems, but the attack did rely on magnetic strip based credit cards and the POS systems had access to all the necessary account credentials for a future cardless transaction.