It's much better than MSRs because online transactions aren't vulnerable to skimming / replay. This eliminates the ability to clone cards using an ATM skimmer or over-the-wire stolen track data, which by my understanding is one of the primary identity theft attacks against US cards.
This "yes-card" attack relied on having physically stolen the original card (not skimmed) and only worked against offline transactions using SDA, which, as far as I know, aren't supposed to happen in the US.
As long as merchants continue to accept magstripes the security benefit isn't really there, but, in the ideal world where they accept only chip-and-sig, it's still much more secure than MSR even without the added protection of a PIN.
It worked against transactions that use offline PIN verification, which happen to be a lot more common than offline transactions. Some security researchers in the UK demonstrated the same attack using online transactions with offline PIN verification, which was standard for everything except ATM transactions at the time.
It's possible to encode a card with a specific number, so as long as you know the number and cvv, you could conceivably create your own card, since you are bypassing the chip-and-pin system anyway.
Comments
It's much better than MSRs because online transactions aren't vulnerable to skimming / replay. This eliminates the ability to clone cards using an ATM skimmer or over-the-wire stolen track data, which by my understanding is one of the primary identity theft attacks against US cards.
This "yes-card" attack relied on having physically stolen the original card (not skimmed) and only worked against offline transactions using SDA, which, as far as I know, aren't supposed to happen in the US.
As long as merchants continue to accept magstripes the security benefit isn't really there, but, in the ideal world where they accept only chip-and-sig, it's still much more secure than MSR even without the added protection of a PIN.
It worked against transactions that use offline PIN verification, which happen to be a lot more common than offline transactions. Some security researchers in the UK demonstrated the same attack using online transactions with offline PIN verification, which was standard for everything except ATM transactions at the time.
It's possible to encode a card with a specific number, so as long as you know the number and cvv, you could conceivably create your own card, since you are bypassing the chip-and-pin system anyway.