So its possible to remotely overwrite the Verifone software to capture PIN numbers. The local attacks aren't as terrifying, since it was already possible to replace them with modified devices to skim PINs. And what about all the HSM PIN-recovery attacks, on which the details are already available? And where are those <1mm thick ATM skimmers they warned us about?
Ultimately, stolen credit card numbers just aren't that monetizable (they're sold for pennies on the dollar, $2-$3 per) and not enough people use their pin numbers at POS terminals. It seems more fraudsters steal using Scareware/rogue AV (its less likely to be charged back, since the victim actively entered their details).
Well-funded organized crime seems more interested in targeting bank logins, or Medicare (losses in the billions, mixed with bonafide doctor-fraud), or maybe home loans and other forms of ID theft.
Sorry, suggesting that credit card fraud isn't a real threat to people is just completely out of touch.
From the first hit for 'credit card fraud' on google (the wikipedia page):
'The cost of card fraud in 2006 were 7 cents per 100 dollars worth of transactions (7 basis points).[2] Due to the high volume of transactions this translates to billions of dollars. In 2006, fraud in the United Kingdom alone was estimated at £535 million,[3] or US$750–830 million at prevailing 2006 exchange rates.[4]'
You can say what you like (the page does note that the incidence of fraud as compared to other types of fraud has gone down), but credit card fraud is extremely destructive and is here to stay for quite a while. Dealing with it is not cheap, or easy, or fast.
Credit card fraud is also an enormous threat to merchants due to the fact that chargebacks result in large fees and, eventually, merchant account termination. Merchants have to compensate by being extremely zealous about fraud and actively filtering out customers (legitimate or not) based on heuristics and data to try and avoid processing fraudulent payments - so for the 1% of your payments that are fraudulent, you probably have to throw out 2-5% of them, just to avoid processing the bad ones.
Comments
So its possible to remotely overwrite the Verifone software to capture PIN numbers. The local attacks aren't as terrifying, since it was already possible to replace them with modified devices to skim PINs. And what about all the HSM PIN-recovery attacks, on which the details are already available? And where are those <1mm thick ATM skimmers they warned us about?
Ultimately, stolen credit card numbers just aren't that monetizable (they're sold for pennies on the dollar, $2-$3 per) and not enough people use their pin numbers at POS terminals. It seems more fraudsters steal using Scareware/rogue AV (its less likely to be charged back, since the victim actively entered their details).
Well-funded organized crime seems more interested in targeting bank logins, or Medicare (losses in the billions, mixed with bonafide doctor-fraud), or maybe home loans and other forms of ID theft.
Sorry, suggesting that credit card fraud isn't a real threat to people is just completely out of touch.
From the first hit for 'credit card fraud' on google (the wikipedia page):
'The cost of card fraud in 2006 were 7 cents per 100 dollars worth of transactions (7 basis points).[2] Due to the high volume of transactions this translates to billions of dollars. In 2006, fraud in the United Kingdom alone was estimated at £535 million,[3] or US$750–830 million at prevailing 2006 exchange rates.[4]'
You can say what you like (the page does note that the incidence of fraud as compared to other types of fraud has gone down), but credit card fraud is extremely destructive and is here to stay for quite a while. Dealing with it is not cheap, or easy, or fast.
Credit card fraud is also an enormous threat to merchants due to the fact that chargebacks result in large fees and, eventually, merchant account termination. Merchants have to compensate by being extremely zealous about fraud and actively filtering out customers (legitimate or not) based on heuristics and data to try and avoid processing fraudulent payments - so for the 1% of your payments that are fraudulent, you probably have to throw out 2-5% of them, just to avoid processing the bad ones.