Last edit by: philemer
Posts from 1/1/16 onward can be found here: http://www.flyertalk.com/forum/credit-card-programs/1739359-2016-onward-usa-emv-cards-availability-q-chip-pin-signature.html
EMV wikipost volunteers: kebosabi
What is EMV?
EMV is a defacto global standard of technology where there is a visible microchip on the front of the card. It looks like this:
Who issues them?
See Google Docs spreadsheet in Post #1
SFOAMS also has created a list of excellent webpage that shows US EMV cards in a more interactive interface
Another site, which lets you narrow the search for an EMV card by various parameters, is http://www.spotterswiki.com/emv/index.php.
Several credit unions issue some form of Chip-and-PIN credit cards or prepaid cards. Prepaid EMV cards however are not recommended due to junk fees. USAA (currently restricted to members of military) used to offer Chip-and-PIN cards, but as late has backtracked to Chip-and-Signature priority.
Hey that's a cool Google Docs list! I know others that aren't on that list. How can I help by adding them to the list?
My bad for not putting this into the wiki sooner. Right now, the Google Docs is locked out of editing and only in "read-only" view because there were instances in the past where people would just delete the rows not thinking that it affects others viewing the list.
If you promise not to delete any rows and input all the pertinent info (annual fee, rewards, FTF, etc.), I can provide you with edit access. Just shoot me a PM to kebosabi with your gmail address and I'll provide you edit access.
Thanks for helping out!
As of October 2014, no USA-based card issuer offers Chip-and-PIN priority cards except for BMO Harris (Diners Club) and UN Federal Credit Union. Other major USA-based banks such as BofA, Chase, Citi, as well as others issue Chip-and-Signature cards which may work at many automated kiosks. However, bear in mind the word may is used above is a context where there is no absolute certainty of success for certain environments such as automated kiosks due to different natures of offline and online transactions. It is highly recommended to read Post #3 which lists real life FTer examples on how Chip-and-Signature worked and did not work at various transaction environments.
Can I upgrade it right now?
If it's listed on that Google Docs spreadsheet or SFOAMS' Silk page, wouldn't hurt to call/twitter them for a free upgrade. If you get the response you don't like, hang up, try again.
What is the difference between Chip-and-Signature and Chip-and-PIN?
You insert the chipped card into the slot. The physical contact terminal will read the EMV chip and the terminal will automatically read the preferred cardholder verification methods (called CVM) for that card.
Chip-and-Signature means that the terminal will printout a receipt for you to sign. This is the most prevalent authentication for most US issued EMV cards. Chip-and-Signature helps in a way that it will get through to face-to-face merchant transactions where you and the merchant do not speak the same language.
Chip-and-PIN means that the terminal will prompt you to input a PIN for authentication. Some credit union issued credit cards will have this CVM as secondary if Chip-and-Signature cannot be done. Chip-and-PIN is the more prevalent method of authentication used outside the US, especially in transaction environments where no human interaction is needed (i.e. automated gas pumps, toll roads, train kiosks, etc.).
The Google Docs spreadsheet will list which CVM are used in the EMV cards listed. Some cards can only do Chip-and-Signature. Other cards can do both Chip-and-Signature and Chip-and-PIN. And others might have a third option called No CVM (no authentication needed) which is reserved for low value transactions.
One chip can hold a lot more data, therefore it is capable of doing multiple verification methods. That's one of the great things about EMV over the mag-stripe which can hold very little data.
I want to know for sure what my EMV chip does. Is there anyway I can test out my own EMV card to see what the CVM list is?
alexmt has written up a nice step-by-step procedure on Post #3615.
If most of the EMV cards in the US is the Chip-and-Signature type, doesn't that mean it's still useless abroad?
Depends if you see it as glass half empty or glass half full. See Post #3 for further details on how Chip-and-Signature has worked both successfully and unsuccessfully depending on the merchant transaction environment and use your best judgment whether which one is right for you.
Are there any places in the US that are accepting transactions via the EMV chip?
tmiw has created a dedicated Google maps webpage to show where EMV has been proven to work here: http://emvacceptedhere.com/ Per his Post #4240, feel free to add any places with active EMV terminals if you come across one.
As of 2014/05, the EMV terminals in most Walmarts and Sam's Clubs are being turned on. Hence, the best place to try them out would be your local Walmart or Sam's Club. For other merchants, it's slowly being phased in.
I hope people will post them in the Post your receipt of your 1st EMV based transaction in the US thread. cvarming has shown us an EMV transaction receipt from Brooklyn, NY in Post #2380. I myself had my first EMV based (Chip-and-Signature) transaction in two stores in the Los Angeles area, as shown in detail in Post #2705 (courtesy of WhatWhatTech for pointing these two stores out)
I don't want a chip in my card. I heard horror stories all over the media saying hackers can steal my credit card info from a mile away.
There are two types of chips. One is contactless and the other is contact. Cards can be either one or the other, or both.
In the Google Docs spreadsheet, the cards that are capable of contactless payments are listed seperately under the "RFID or NFC contactless chip" column. If it says yes, then that means it has the ability to do contactless payments. If it says no, it doesn't have that feature.
The one that the media has overhyped about hackers "stealing your information wirelessly" was the contactless type like this:
You are worried about this happening, right?
You don't have to worry. EMV is a chip standard that can have both contact and contactless interfaces. With the traditional contact interface, this means you actually have to physically insert the chip into a POS terminal for it to be authorized, like this:
With the contact interface, nothing is wireless. No data is sent out in a stand-alone contact type EMV chip. With the EMV contactless interface, data is sent wirelessly.
Furthermore, contactless chip cards are required to show a symbol (looks like Wi-Fi symbol) somewhere on the card that to denote it's capability as a contactless card. For example, here's an example of a Discover Card with contactless capability (in which Discover calls "Discover ZIP") showing the contactless symbol on the back of the card:
Don't believe everything that the media says. Besides, millions of people all over the world from London to Singapore, uses contactless payments daily in extremely crowded subways and mass transit with nary any problems. There are multiple layers of encrypted securities and keys that are needed to break the code.
Frankly, giving your physical card to a waiter/waitress who takes the card out of your view is much more susceptible to fraud than contactless payments.
Why should I care?
If you are an international traveler, you will want this because majority of the world has or in the process of converting to this payment format.
In fact, in 2012, even North Korea moved to the EMV format, leaving the US as one of the countries in the world that hasn't done so.
In addition, VISA, MC, AMEX, and Discover have all agreed to incentivize the USA shifting to EMV payments by 2015 by shifting liability for fraudulent transactions to merchants if they do not have EMV equipment and the cardholder has an EMV card. So if you travel internationally or would like to get one before the others, you might be interested in getting one.
BS! I had no problems using my card in [insert whereever country], [insert whatever point in time]
If you stick to the tourist path where they have lots of visitors from the US, you should have no problems using your mag-stripe only card in hotels and restaurants, at least for now. But as things can change as things go forward.
However, consider that once you start taking the off-beaten path, go to non-touristy places where they are not familiar with mag-stripes, rent a car and use toll roads, fill up gas, or try to buy train tickets you might end up into a trouble of the machine not recognizing your card because it lacks the chip. Furthermore, a lot of toll roads, gas pumps, and automated ticket machines lack any human assistance to help you when you need it the most.
But [insert credit card company] told me all merchants that display their logo must accept them! All I have to do is report them for violating their agreements, right?
There are several factors against this.
1. You can only speak English. The merchant representative, most likely a part-time clerk earning minimum wage, speaks in a different language, let's say French. If you have no French language skills, how are you going to get your point across? Are you going to whip out your cell phone at exorbitant int'l roaming charges and hope the customer service is going to translate it for you on the spot? Or maybe you might actually know French. But how about Swahili, Farsi, Balinese, or the multiple languages in mainland China?
2. Just like US, the rest of the world's businesses uses part-time minimum wage workers as cashiers to cut down on labor costs. Most of their SOP training manuals are written by MBA types to not to do anything they are not familiar with. Do not expect them to understand the intricate details of credit card mumbo jumbo. You don't expect Taco Bell employees to understand the minute details of Discover-JCB-Union Pay agreements, right? Same thing the other way around: be respectful as a guest in their country, prepare in advance in their ways, avoid being an "ugly American" stereotype.
3. You are a guest in their country. You are a minority. If 99.9% of their country's people and other tourists from around the world uses EMV, do you really think they are going to accomodate the 0.1% of American tourists who only have mag-stripes credit cards?
4. Again, you are a guest in their country. How would you, as an American standing in line, react if a Chinese tourist was clogging up the lines at a local Taco Bell because the clerk doesn't understand the Discover-Union Pay agreement and has trouble communicating between Mandarin spoken by the tourist and English spoken by the Taco Bell clerk? Same way the other way around. You do not want to clog up the lines for everyone. The less hassle, the better.
5. VISA and MC make tons of money from merchants in that country. Say SNCF French Rail. It's a billion dollar company in France. Do you think VISA is going to pull the plug of their relationship with SNCF because SNCF refuses to do mag-stripe processing at their unmanned train station kiosk? Of course not. Be realistic.
6. And lastly, if you're up against an unstaffed toll kiosk, gas pump or train ticket machine, are you going to yell curses at the machine?
But I want my credit card to be able to be used in the US too!
No worries. They have not gotten rid of the mag-stripe on the back of the card for backward compatibility reasons, just like we still have embossed numbers on our cards for backwards compatibility to using those old carbon copy imprinters.
[insert own Hyatt card image front and back together with red arrows pointing to all the backward compatibility features]
You use the chip on the front of the card abroad (for now), and the mag-stripe just like any other card for the US. Basically, you're increasing your credit card's acceptance rate by getting a card that both via the chip and the mag-stripe. You're getting a better deal for free.
And when 2015 comes along and US switches to EMV, you'll be way ahead of everyone else too!
So why did the rest of the world and the US moved/moving toward EMV?
Primarily, due to fraud concerns. You see, the mag-stripe has been with us since the 1950s. It may have been the most high tech thing back in the day, but with the technology that is available today, any shmo can pick up a $100 USB magnetic card skimming device off of eBay and get your credit card info.
And unlike skimming off contactless cards which actually need the person to have l33t programming skills, skimming off a magnetic stripe has become so ubiquitous that nary a day goes about skimming fraud going on somewhere in America, from gas pumps, Michael's stores (2011), Target breaches (2013), restaurant waiters/waitresses, to even McDonald's drive thrus.
https://www.google.com/search?q=skimming+fraud
These type of fraud used to be prevalent in Europe. But once they started switching over to EMV starting over 2 decades ago, this type of fraud went elsewhere. It went over to Asia, Canada and Mexico, Latin America, etc. etc. until they too began implementing EMV to combat skimming fraud. The US is practically the only country left that hasn't done so, therefore all the fraud that used to take place elsewhere is now happening here.
But EMV is old and it's not fool proof. Shouldn't we just skip over it and do something new instead?
Yes, EMV is old. It was developed in the 1990s and its smart card payment predecessor was first introduced in France. But as of today, it has become the defacto global standard of payments.
But then, what else is there? There is no other de facto global standard of payments alternative. For example, if we decide to skip over it and do something new, hypothetically like DNA matching technology, it still means US int'l travelers will continue to have problems abroad with useless plastic acceptance because no other country is using this DNA matching technology except the US.
Besides, nothing is fool proof. You can say that the bank vault isn't fool proof because you can crack it open if enough C4 is used. But your average low-life scumbag isn't likely to get military grade C4 easily either. But the bank vault does make it harder to get the bank's money over say a petty cash box. That's the point here. EMV is akin to a security tight bank vault, the old mag-stripe is akin to a petty cash box lying around inside the drawer.
I'm a business owner and I don't think EMV is going to take off. I'm not going to spend extra hundreds of dollars to upgrade my credit card machine. Convince me other wise why I should.
I can understand the added extra cost to your business once this switchover takes place. But before even saying that, look at your existing POS terminal. Does it have a slot somewhere to insert a card?
Most likely, if you had replaced your POS terminal within the past five years, you already have an EMV capable terminal. EMV is basically just not turned on yet from the processor and acquirer side.
If you have an EMV capable terminal, then a best bet would be to contact your acquirer to have the EMV feature turned on. You did your end of the deal already by having an EMV capable terminal, it is now the acquirers' responsibility to turn it on in accordance to the EMV switchover mandate.
And if you don't, you are going to replace your POS terminal anyway from common wear and tear. It isn't a hard switch-over. You can continue to use your POS terminal until it dies out because EMV cardholders will still have the mag-stripe on the back. And by the time your non-EMV capable POS terminal is up for replacement the market will be full with these newer POS terminals that can accept the mag-stripe, EMV, as well as contactless payments.
In addition, you may also want to check with your acquirer or processor about EMV capable terminals. Some of them are willing to replace your terminal for free in preparation for the US EMV switchover. Call and ask for details.
But what's in it for me? I'm the one that has to pay for the upgrade.
All the major card networks have given incentives for merchants for the upcoming EMV switchover.
If 75% or more of your credit card transactions are done on an EMV contact and contactless terminal, they are going to waive your annual PCI-DSS fees, which usually costs you around $5.00-$19.95/month per terminal. The overall long term cost savings of those compliance fees will be larger than the cost of an one time upgrade for the terminal.
The downside is that once EMV switchover happens and if you do not have a POS terminal that is able to accept EMV, the fraud liability shifts over to the merchant.
I own several fast food franchises. If I upgrade my POS terminals at all of my restaurants, it's going to cost me thousands, if not millions. I don't think anyone is going to use a fake credit card to buy $5 burgers. And if they do, wouldn't it be cheaper for me to eat the fraud cost?
Remember also that fraud isn't just committed by dishonest customers using fraudulent cards. Fraud can also happen with dishonest employees skimming off credit card data from the mag-stripe as in the case of a teenage McDonald's drive thru employee skimming off $13,000 of customers' credit cards in Olympia, WA. Consider the public relations fall out that your business may have if this happens (i.e. the big Target breach of 2013, where someone used a mag stripe card to load malware INTO Target's system). Is it worth risking to take such a huge PR disaster?
EMV wikipost volunteers: kebosabi
What is EMV?
EMV is a defacto global standard of technology where there is a visible microchip on the front of the card. It looks like this:
Who issues them?
See Google Docs spreadsheet in Post #1
SFOAMS also has created a list of excellent webpage that shows US EMV cards in a more interactive interface
Another site, which lets you narrow the search for an EMV card by various parameters, is http://www.spotterswiki.com/emv/index.php.
Several credit unions issue some form of Chip-and-PIN credit cards or prepaid cards. Prepaid EMV cards however are not recommended due to junk fees. USAA (currently restricted to members of military) used to offer Chip-and-PIN cards, but as late has backtracked to Chip-and-Signature priority.
Hey that's a cool Google Docs list! I know others that aren't on that list. How can I help by adding them to the list?
My bad for not putting this into the wiki sooner. Right now, the Google Docs is locked out of editing and only in "read-only" view because there were instances in the past where people would just delete the rows not thinking that it affects others viewing the list.
If you promise not to delete any rows and input all the pertinent info (annual fee, rewards, FTF, etc.), I can provide you with edit access. Just shoot me a PM to kebosabi with your gmail address and I'll provide you edit access.
Thanks for helping out!
As of October 2014, no USA-based card issuer offers Chip-and-PIN priority cards except for BMO Harris (Diners Club) and UN Federal Credit Union. Other major USA-based banks such as BofA, Chase, Citi, as well as others issue Chip-and-Signature cards which may work at many automated kiosks. However, bear in mind the word may is used above is a context where there is no absolute certainty of success for certain environments such as automated kiosks due to different natures of offline and online transactions. It is highly recommended to read Post #3 which lists real life FTer examples on how Chip-and-Signature worked and did not work at various transaction environments.
Can I upgrade it right now?
If it's listed on that Google Docs spreadsheet or SFOAMS' Silk page, wouldn't hurt to call/twitter them for a free upgrade. If you get the response you don't like, hang up, try again.
What is the difference between Chip-and-Signature and Chip-and-PIN?
You insert the chipped card into the slot. The physical contact terminal will read the EMV chip and the terminal will automatically read the preferred cardholder verification methods (called CVM) for that card.
Chip-and-Signature means that the terminal will printout a receipt for you to sign. This is the most prevalent authentication for most US issued EMV cards. Chip-and-Signature helps in a way that it will get through to face-to-face merchant transactions where you and the merchant do not speak the same language.
Chip-and-PIN means that the terminal will prompt you to input a PIN for authentication. Some credit union issued credit cards will have this CVM as secondary if Chip-and-Signature cannot be done. Chip-and-PIN is the more prevalent method of authentication used outside the US, especially in transaction environments where no human interaction is needed (i.e. automated gas pumps, toll roads, train kiosks, etc.).
The Google Docs spreadsheet will list which CVM are used in the EMV cards listed. Some cards can only do Chip-and-Signature. Other cards can do both Chip-and-Signature and Chip-and-PIN. And others might have a third option called No CVM (no authentication needed) which is reserved for low value transactions.
One chip can hold a lot more data, therefore it is capable of doing multiple verification methods. That's one of the great things about EMV over the mag-stripe which can hold very little data.
I want to know for sure what my EMV chip does. Is there anyway I can test out my own EMV card to see what the CVM list is?
alexmt has written up a nice step-by-step procedure on Post #3615.
If most of the EMV cards in the US is the Chip-and-Signature type, doesn't that mean it's still useless abroad?
Depends if you see it as glass half empty or glass half full. See Post #3 for further details on how Chip-and-Signature has worked both successfully and unsuccessfully depending on the merchant transaction environment and use your best judgment whether which one is right for you.
Are there any places in the US that are accepting transactions via the EMV chip?
tmiw has created a dedicated Google maps webpage to show where EMV has been proven to work here: http://emvacceptedhere.com/ Per his Post #4240, feel free to add any places with active EMV terminals if you come across one.
As of 2014/05, the EMV terminals in most Walmarts and Sam's Clubs are being turned on. Hence, the best place to try them out would be your local Walmart or Sam's Club. For other merchants, it's slowly being phased in.
I hope people will post them in the Post your receipt of your 1st EMV based transaction in the US thread. cvarming has shown us an EMV transaction receipt from Brooklyn, NY in Post #2380. I myself had my first EMV based (Chip-and-Signature) transaction in two stores in the Los Angeles area, as shown in detail in Post #2705 (courtesy of WhatWhatTech for pointing these two stores out)
I don't want a chip in my card. I heard horror stories all over the media saying hackers can steal my credit card info from a mile away.
There are two types of chips. One is contactless and the other is contact. Cards can be either one or the other, or both.
In the Google Docs spreadsheet, the cards that are capable of contactless payments are listed seperately under the "RFID or NFC contactless chip" column. If it says yes, then that means it has the ability to do contactless payments. If it says no, it doesn't have that feature.
The one that the media has overhyped about hackers "stealing your information wirelessly" was the contactless type like this:
You are worried about this happening, right?
You don't have to worry. EMV is a chip standard that can have both contact and contactless interfaces. With the traditional contact interface, this means you actually have to physically insert the chip into a POS terminal for it to be authorized, like this:
With the contact interface, nothing is wireless. No data is sent out in a stand-alone contact type EMV chip. With the EMV contactless interface, data is sent wirelessly.
Furthermore, contactless chip cards are required to show a symbol (looks like Wi-Fi symbol) somewhere on the card that to denote it's capability as a contactless card. For example, here's an example of a Discover Card with contactless capability (in which Discover calls "Discover ZIP") showing the contactless symbol on the back of the card:
Don't believe everything that the media says. Besides, millions of people all over the world from London to Singapore, uses contactless payments daily in extremely crowded subways and mass transit with nary any problems. There are multiple layers of encrypted securities and keys that are needed to break the code.
Frankly, giving your physical card to a waiter/waitress who takes the card out of your view is much more susceptible to fraud than contactless payments.
Why should I care?
If you are an international traveler, you will want this because majority of the world has or in the process of converting to this payment format.
In fact, in 2012, even North Korea moved to the EMV format, leaving the US as one of the countries in the world that hasn't done so.
In addition, VISA, MC, AMEX, and Discover have all agreed to incentivize the USA shifting to EMV payments by 2015 by shifting liability for fraudulent transactions to merchants if they do not have EMV equipment and the cardholder has an EMV card. So if you travel internationally or would like to get one before the others, you might be interested in getting one.
BS! I had no problems using my card in [insert whereever country], [insert whatever point in time]
If you stick to the tourist path where they have lots of visitors from the US, you should have no problems using your mag-stripe only card in hotels and restaurants, at least for now. But as things can change as things go forward.
However, consider that once you start taking the off-beaten path, go to non-touristy places where they are not familiar with mag-stripes, rent a car and use toll roads, fill up gas, or try to buy train tickets you might end up into a trouble of the machine not recognizing your card because it lacks the chip. Furthermore, a lot of toll roads, gas pumps, and automated ticket machines lack any human assistance to help you when you need it the most.
But [insert credit card company] told me all merchants that display their logo must accept them! All I have to do is report them for violating their agreements, right?
There are several factors against this.
1. You can only speak English. The merchant representative, most likely a part-time clerk earning minimum wage, speaks in a different language, let's say French. If you have no French language skills, how are you going to get your point across? Are you going to whip out your cell phone at exorbitant int'l roaming charges and hope the customer service is going to translate it for you on the spot? Or maybe you might actually know French. But how about Swahili, Farsi, Balinese, or the multiple languages in mainland China?
2. Just like US, the rest of the world's businesses uses part-time minimum wage workers as cashiers to cut down on labor costs. Most of their SOP training manuals are written by MBA types to not to do anything they are not familiar with. Do not expect them to understand the intricate details of credit card mumbo jumbo. You don't expect Taco Bell employees to understand the minute details of Discover-JCB-Union Pay agreements, right? Same thing the other way around: be respectful as a guest in their country, prepare in advance in their ways, avoid being an "ugly American" stereotype.
3. You are a guest in their country. You are a minority. If 99.9% of their country's people and other tourists from around the world uses EMV, do you really think they are going to accomodate the 0.1% of American tourists who only have mag-stripes credit cards?
4. Again, you are a guest in their country. How would you, as an American standing in line, react if a Chinese tourist was clogging up the lines at a local Taco Bell because the clerk doesn't understand the Discover-Union Pay agreement and has trouble communicating between Mandarin spoken by the tourist and English spoken by the Taco Bell clerk? Same way the other way around. You do not want to clog up the lines for everyone. The less hassle, the better.
5. VISA and MC make tons of money from merchants in that country. Say SNCF French Rail. It's a billion dollar company in France. Do you think VISA is going to pull the plug of their relationship with SNCF because SNCF refuses to do mag-stripe processing at their unmanned train station kiosk? Of course not. Be realistic.
6. And lastly, if you're up against an unstaffed toll kiosk, gas pump or train ticket machine, are you going to yell curses at the machine?
But I want my credit card to be able to be used in the US too!
No worries. They have not gotten rid of the mag-stripe on the back of the card for backward compatibility reasons, just like we still have embossed numbers on our cards for backwards compatibility to using those old carbon copy imprinters.
[insert own Hyatt card image front and back together with red arrows pointing to all the backward compatibility features]
You use the chip on the front of the card abroad (for now), and the mag-stripe just like any other card for the US. Basically, you're increasing your credit card's acceptance rate by getting a card that both via the chip and the mag-stripe. You're getting a better deal for free.
And when 2015 comes along and US switches to EMV, you'll be way ahead of everyone else too!
So why did the rest of the world and the US moved/moving toward EMV?
Primarily, due to fraud concerns. You see, the mag-stripe has been with us since the 1950s. It may have been the most high tech thing back in the day, but with the technology that is available today, any shmo can pick up a $100 USB magnetic card skimming device off of eBay and get your credit card info.
And unlike skimming off contactless cards which actually need the person to have l33t programming skills, skimming off a magnetic stripe has become so ubiquitous that nary a day goes about skimming fraud going on somewhere in America, from gas pumps, Michael's stores (2011), Target breaches (2013), restaurant waiters/waitresses, to even McDonald's drive thrus.
https://www.google.com/search?q=skimming+fraud
These type of fraud used to be prevalent in Europe. But once they started switching over to EMV starting over 2 decades ago, this type of fraud went elsewhere. It went over to Asia, Canada and Mexico, Latin America, etc. etc. until they too began implementing EMV to combat skimming fraud. The US is practically the only country left that hasn't done so, therefore all the fraud that used to take place elsewhere is now happening here.
But EMV is old and it's not fool proof. Shouldn't we just skip over it and do something new instead?
Yes, EMV is old. It was developed in the 1990s and its smart card payment predecessor was first introduced in France. But as of today, it has become the defacto global standard of payments.
But then, what else is there? There is no other de facto global standard of payments alternative. For example, if we decide to skip over it and do something new, hypothetically like DNA matching technology, it still means US int'l travelers will continue to have problems abroad with useless plastic acceptance because no other country is using this DNA matching technology except the US.
Besides, nothing is fool proof. You can say that the bank vault isn't fool proof because you can crack it open if enough C4 is used. But your average low-life scumbag isn't likely to get military grade C4 easily either. But the bank vault does make it harder to get the bank's money over say a petty cash box. That's the point here. EMV is akin to a security tight bank vault, the old mag-stripe is akin to a petty cash box lying around inside the drawer.
I'm a business owner and I don't think EMV is going to take off. I'm not going to spend extra hundreds of dollars to upgrade my credit card machine. Convince me other wise why I should.
I can understand the added extra cost to your business once this switchover takes place. But before even saying that, look at your existing POS terminal. Does it have a slot somewhere to insert a card?
Most likely, if you had replaced your POS terminal within the past five years, you already have an EMV capable terminal. EMV is basically just not turned on yet from the processor and acquirer side.
If you have an EMV capable terminal, then a best bet would be to contact your acquirer to have the EMV feature turned on. You did your end of the deal already by having an EMV capable terminal, it is now the acquirers' responsibility to turn it on in accordance to the EMV switchover mandate.
And if you don't, you are going to replace your POS terminal anyway from common wear and tear. It isn't a hard switch-over. You can continue to use your POS terminal until it dies out because EMV cardholders will still have the mag-stripe on the back. And by the time your non-EMV capable POS terminal is up for replacement the market will be full with these newer POS terminals that can accept the mag-stripe, EMV, as well as contactless payments.
In addition, you may also want to check with your acquirer or processor about EMV capable terminals. Some of them are willing to replace your terminal for free in preparation for the US EMV switchover. Call and ask for details.
But what's in it for me? I'm the one that has to pay for the upgrade.
All the major card networks have given incentives for merchants for the upcoming EMV switchover.
If 75% or more of your credit card transactions are done on an EMV contact and contactless terminal, they are going to waive your annual PCI-DSS fees, which usually costs you around $5.00-$19.95/month per terminal. The overall long term cost savings of those compliance fees will be larger than the cost of an one time upgrade for the terminal.
The downside is that once EMV switchover happens and if you do not have a POS terminal that is able to accept EMV, the fraud liability shifts over to the merchant.
I own several fast food franchises. If I upgrade my POS terminals at all of my restaurants, it's going to cost me thousands, if not millions. I don't think anyone is going to use a fake credit card to buy $5 burgers. And if they do, wouldn't it be cheaper for me to eat the fraud cost?
Remember also that fraud isn't just committed by dishonest customers using fraudulent cards. Fraud can also happen with dishonest employees skimming off credit card data from the mag-stripe as in the case of a teenage McDonald's drive thru employee skimming off $13,000 of customers' credit cards in Olympia, WA. Consider the public relations fall out that your business may have if this happens (i.e. the big Target breach of 2013, where someone used a mag stripe card to load malware INTO Target's system). Is it worth risking to take such a huge PR disaster?
USA EMV cards: Availability, Q&A (Chip & PIN -or- Chip & Signature) [2012-2015]
#8341
FlyerTalk Evangelist
Join Date: Jan 2014
Location: San Diego, CA
Programs: GE, Marriott Platinum
Posts: 15,507
I agree with this. I could think of nothing more frustrating than having the issuer deny me a chargeback because of the assumption that there is no card present fraud with chip-and-PIN. The possibility is remote, but it is nonzero. I still maintain that public perception in the US would keep zero liability policies in place, but I think there will be additional scrutiny of fraudulent card present transactions in the future.
Additional scrutiny might not be a bad thing because it reduces a moral hazard that now exists. Right now everybody in the US seems to take a cavalier attitude when it comes to credit card security. Consumers know that they're protected from any fraudulent transactions, so they make little effort. If a card gets lost or stolen there isn't the immediate need to cancel it. Merchants in the US rarely check for signature (or ID - even though this violates Visa/MC policy as long as the card has been signed), and why should they at this point? Someone can just clone a magstripe card, so it's impossible to tell if it's even a legit card. Issuers pretty readily courtesy credit small transactions and will remove any fraudulent ones. Everybody seems to accept a certain amount of fraud in the system as it currently stands without wanting to do much about it.
Additional scrutiny might not be a bad thing because it reduces a moral hazard that now exists. Right now everybody in the US seems to take a cavalier attitude when it comes to credit card security. Consumers know that they're protected from any fraudulent transactions, so they make little effort. If a card gets lost or stolen there isn't the immediate need to cancel it. Merchants in the US rarely check for signature (or ID - even though this violates Visa/MC policy as long as the card has been signed), and why should they at this point? Someone can just clone a magstripe card, so it's impossible to tell if it's even a legit card. Issuers pretty readily courtesy credit small transactions and will remove any fraudulent ones. Everybody seems to accept a certain amount of fraud in the system as it currently stands without wanting to do much about it.
- International travelers are having problems using magstripe-only cards now.
- A perception by consumers that CC fraud is out of control (thanks to Target, Home Depot, etc.) even if it's not true in reality.
- Waiting for "better" tech to come around isn't productive when the first two problems exist and need to be solved now.
From that perspective, the US banks' adoption of EMV so far makes complete sense. Their goals are basically to ensure interoperability and give consumers confidence, so why implement more than necessary?
Also, it's arguable that Apple Pay is the better technology, even if it's mostly a rehash of contactless/NFC with tokenization and biometrics added. The latter two also help satisfy goal #2, with additional security being a side-effect. If the banks can get enough people using it, then they won't ever have to implement PIN (barring failure of Apple Pay in the market and/or a sharp increase in lost/stolen fraud with physical cards, of course). Most fraud will probably turn to CNP before lost/stolen though due to the higher risk of getting caught by pickpocketing or mugging.
#8342
FlyerTalk Evangelist
Join Date: Jan 2014
Location: San Diego, CA
Programs: GE, Marriott Platinum
Posts: 15,507
That I can get behind, but to call it "skimming" is such a stretch. It's an attack that 1. depends on poor implementation of the EMV standards and 2. requires a great deal of thought and planning (most skimmers are into the quick and easy it seems).
Now, as for poor implementation, I've been reading just how badly EMV is implemented by many banks. For one, apparently it is quite common for banks to authorise transactions where the service code or other stripe data has been tampered with (as described above by "emvchip") - this despite the fact the data is available to the issuing bank to clearly see that the card has been tampered with. There are quite a few other examples too, but they all come down to the same thing - banks authorising transactions that are clearly fraudulent.
Which makes one wonder - why the horrid implementation?
Now, as for poor implementation, I've been reading just how badly EMV is implemented by many banks. For one, apparently it is quite common for banks to authorise transactions where the service code or other stripe data has been tampered with (as described above by "emvchip") - this despite the fact the data is available to the issuing bank to clearly see that the card has been tampered with. There are quite a few other examples too, but they all come down to the same thing - banks authorising transactions that are clearly fraudulent.
Which makes one wonder - why the horrid implementation?
#8343
Join Date: Jul 2009
Location: SJC
Programs: AA, AS, Marriott
Posts: 6,060
Visa's global fraud rate is still only six cents per $100. IMO, the US would stick with magstripe forever if it weren't for the following:
From that perspective, the US banks' adoption of EMV so far makes complete sense. Their goals are basically to ensure interoperability and give consumers confidence, so why implement more than necessary?
Also, it's arguable that Apple Pay is the better technology, even if it's mostly a rehash of contactless/NFC with tokenization and biometrics added. The latter two also help satisfy goal #2, with additional security being a side-effect. If the banks can get enough people using it, then they won't ever have to implement PIN (barring failure of Apple Pay in the market and/or a sharp increase in lost/stolen fraud with physical cards, of course). Most fraud will probably turn to CNP before lost/stolen though due to the higher risk of getting caught by pickpocketing or mugging.
- International travelers are having problems using magstripe-only cards now.
- A perception by consumers that CC fraud is out of control (thanks to Target, Home Depot, etc.) even if it's not true in reality.
- Waiting for "better" tech to come around isn't productive when the first two problems exist and need to be solved now.
From that perspective, the US banks' adoption of EMV so far makes complete sense. Their goals are basically to ensure interoperability and give consumers confidence, so why implement more than necessary?
Also, it's arguable that Apple Pay is the better technology, even if it's mostly a rehash of contactless/NFC with tokenization and biometrics added. The latter two also help satisfy goal #2, with additional security being a side-effect. If the banks can get enough people using it, then they won't ever have to implement PIN (barring failure of Apple Pay in the market and/or a sharp increase in lost/stolen fraud with physical cards, of course). Most fraud will probably turn to CNP before lost/stolen though due to the higher risk of getting caught by pickpocketing or mugging.
Not every merchant is going to accept mobile payments. Apple Pay may or may not catch on more broadly. The existing solution of chip-and-PIN, while imperfect, at least already has widespread acceptance.
#8344
FlyerTalk Evangelist
Join Date: Jan 2014
Location: San Diego, CA
Programs: GE, Marriott Platinum
Posts: 15,507
But you can make the same argument about the first point. How many international travelers are inconvenienced enough such that the US issuers issue EMV cards specifically for international travel? I know that some of the early EMV issuers were spinning the marketing that way, but the big issuers were moving in that direction anyway. And a chip-and-signature card gets you a few more places, but we're getting some reports of those being refused by merchants in chip-and-PIN countries and still can't use them in payment terminals that require offline PIN.
Not every merchant is going to accept mobile payments. Apple Pay may or may not catch on more broadly. The existing solution of chip-and-PIN, while imperfect, at least already has widespread acceptance.
Not every merchant is going to accept mobile payments. Apple Pay may or may not catch on more broadly. The existing solution of chip-and-PIN, while imperfect, at least already has widespread acceptance.
And while NFC definitely won't be accepted universally, all they need to do is have it adopted enough to make up for any increase in lost and stolen fraud that happens. If CNP fraud does rise far faster than lost and stolen as predicted, that might not be that big of a hurdle.
#8345
Join Date: Feb 2013
Posts: 401
Visa's global fraud rate is still only six cents per $100. IMO, the US would stick with magstripe forever if it weren't for the following:
From that perspective, the US banks' adoption of EMV so far makes complete sense. Their goals are basically to ensure interoperability and give consumers confidence, so why implement more than necessary?
Also, it's arguable that Apple Pay is the better technology, even if it's mostly a rehash of contactless/NFC with tokenization and biometrics added. The latter two also help satisfy goal #2, with additional security being a side-effect. If the banks can get enough people using it, then they won't ever have to implement PIN (barring failure of Apple Pay in the market and/or a sharp increase in lost/stolen fraud with physical cards, of course). Most fraud will probably turn to CNP before lost/stolen though due to the higher risk of getting caught by pickpocketing or mugging.
- International travelers are having problems using magstripe-only cards now.
- A perception by consumers that CC fraud is out of control (thanks to Target, Home Depot, etc.) even if it's not true in reality.
- Waiting for "better" tech to come around isn't productive when the first two problems exist and need to be solved now.
From that perspective, the US banks' adoption of EMV so far makes complete sense. Their goals are basically to ensure interoperability and give consumers confidence, so why implement more than necessary?
Also, it's arguable that Apple Pay is the better technology, even if it's mostly a rehash of contactless/NFC with tokenization and biometrics added. The latter two also help satisfy goal #2, with additional security being a side-effect. If the banks can get enough people using it, then they won't ever have to implement PIN (barring failure of Apple Pay in the market and/or a sharp increase in lost/stolen fraud with physical cards, of course). Most fraud will probably turn to CNP before lost/stolen though due to the higher risk of getting caught by pickpocketing or mugging.
#8346
FlyerTalk Evangelist
Join Date: Jan 2014
Location: San Diego, CA
Programs: GE, Marriott Platinum
Posts: 15,507
NFC/contactless is an open standard though. Google Wallet (and maybe Softcard too?) just use PIN instead of biometrics. You would have a point if Apple were to use Bluetooth LE with a proprietary protocol on top like they were/are using for Passbook loyalty cards.
#8347
Join Date: Feb 2013
Posts: 401
Interesting. I just paid at a garage that certainly did not allow manual entry of credit card information. The entertainment on my last flight did not as well.
#8348
Join Date: Feb 2013
Posts: 401
But that isn't ApplePay per se, that is NFC/contactless (ISO 14443 and related standards). ApplePay may use that standard, and I think we are in agreement, but I was referring to an earlier comment specific to ApplePay being the arguably "the better technology."
#8349
FlyerTalk Evangelist
Join Date: Jan 2014
Location: San Diego, CA
Programs: GE, Marriott Platinum
Posts: 15,507
Apple Pay combines everything in such a way that people actually want to use mobile payments, increasing use of Softcard and Google Wallet as well. It's perceived as the better technology by the public. If it weren't, it wouldn't be adopted by people and thus banks would eventually have to implement PIN.
#8350
Join Date: Jul 2007
Posts: 1,762
I absolutely agree that if it were up to the US banks, they would stick with mag strips as in relation to profits, credit card fraud is a small part of doing business. They hire bean counters to come up with the most economical ways of doing business and I have no reason to doubt their findings that at this point in time, (not saying I agree though), the best solution for American adoption of emv is chip and signature. And of course, at least in this country, in the interests of speed, they allow merchants for purchases ujder $50 to not even bother with signatures.
Of course we have seen how grudgingly some of the banks have been to enter the world of emv (see Capital One) or used emv to try to entice customers to go for the higher priced cards with annual fees (see Barclay). All part, of course, of doing business and maximizing profits as Kebosabi-san always reminds us which is their prime purpose in life. As it stands today, emv is the game in town that best minimizes the cloning of cards and we all know that it is not perfect and that there will be a shift by these hackers, who we must grudgingly admit are good at what they do, to other forms of credit card fraud; probably online fraud until such time as they cam compromise the emv chips.
As far as the problem of merchants refusing chip and signature cards, it doesn't seem to be that big a problem. Yes there have been a few reports of this, but very few. And whether you believe them or not, visa and mc do claim they will be doing whatever possible to dispel the illusion among merchants that signature transactions are any more subject to chargebacks than pin transactions. Also they have pledged, again you can believe them or not, to work with the local banks to make sure that at least small purchases at kiosks can be made with chip and signature cards or perhaps at some point they will require all cards be hybrid cards such as the FCU's we talk about here which default to signature but can function as pin cards in unpersonneled kiosks. And if you're paranoid about the whole thing, at least there exists one free card with chip and pin priority (UNFCU) which you can carry just in case (of course the fee for joining the UN group necessary to become a member is in effect an annual fee but it is only $25).
Finally as to the question of entering cc info manually, I do understand that many merchants don't want to do it but that's not the question. Can they do so in theory? The answer is yes every terminal makes provision if the communication lines go down to enter information manually even with old fashioned imprinters.
Of course we have seen how grudgingly some of the banks have been to enter the world of emv (see Capital One) or used emv to try to entice customers to go for the higher priced cards with annual fees (see Barclay). All part, of course, of doing business and maximizing profits as Kebosabi-san always reminds us which is their prime purpose in life. As it stands today, emv is the game in town that best minimizes the cloning of cards and we all know that it is not perfect and that there will be a shift by these hackers, who we must grudgingly admit are good at what they do, to other forms of credit card fraud; probably online fraud until such time as they cam compromise the emv chips.
As far as the problem of merchants refusing chip and signature cards, it doesn't seem to be that big a problem. Yes there have been a few reports of this, but very few. And whether you believe them or not, visa and mc do claim they will be doing whatever possible to dispel the illusion among merchants that signature transactions are any more subject to chargebacks than pin transactions. Also they have pledged, again you can believe them or not, to work with the local banks to make sure that at least small purchases at kiosks can be made with chip and signature cards or perhaps at some point they will require all cards be hybrid cards such as the FCU's we talk about here which default to signature but can function as pin cards in unpersonneled kiosks. And if you're paranoid about the whole thing, at least there exists one free card with chip and pin priority (UNFCU) which you can carry just in case (of course the fee for joining the UN group necessary to become a member is in effect an annual fee but it is only $25).
Finally as to the question of entering cc info manually, I do understand that many merchants don't want to do it but that's not the question. Can they do so in theory? The answer is yes every terminal makes provision if the communication lines go down to enter information manually even with old fashioned imprinters.
#8351
Join Date: Jul 2014
Location: United Kingdom
Posts: 93
The US is not unique in having these "zero liability" policies (which are of course, nothing more than contractual clauses between cardholders and card issuers which carry several conditions).
In most countries with "Chip and PIN", cardholders are not legally liable unless the bank can prove that you made the transaction - and use of a PIN is not enough for that.
#8352
Join Date: Jul 2009
Location: SJC
Programs: AA, AS, Marriott
Posts: 6,060
We're still seeing comments like this in the thread.
The US is not unique in having these "zero liability" policies (which are of course, nothing more than contractual clauses between cardholders and card issuers which carry several conditions).
In most countries with "Chip and PIN", cardholders are not legally liable unless the bank can prove that you made the transaction - and use of a PIN is not enough for that.
The US is not unique in having these "zero liability" policies (which are of course, nothing more than contractual clauses between cardholders and card issuers which carry several conditions).
In most countries with "Chip and PIN", cardholders are not legally liable unless the bank can prove that you made the transaction - and use of a PIN is not enough for that.
#8353
Join Date: Jun 2013
Location: SJC/SFO
Posts: 373
With all this talk about banks potentially blaming the customer for fraud I am wondering what function the receipt plays. The majority of merchant terminals print out a receipt slip with details of the transactions, but I never keep it. Does it serve some useful function? In case of fraud, it is up to the merchant to prove that the slip was signed. Should I keep my copy for some reason that I'm missing?
#8354
Join Date: May 2010
Location: ORDwest
Posts: 332
If this was an update/replacement CSP, maybe the transaction was already in the pipeline as your card was being replaced? Did you initiate the card cancellation, or did Chase? If they did, maybe they also "migrated" your recurring payment to the new card. My experience has been that Chase is especially efficient at processing replacement cards and updating their records.
#8355
Join Date: Feb 2013
Posts: 401
We're still seeing comments like this in the thread.
The US is not unique in having these "zero liability" policies (which are of course, nothing more than contractual clauses between cardholders and card issuers which carry several conditions).
In most countries with "Chip and PIN", cardholders are not legally liable unless the bank can prove that you made the transaction - and use of a PIN is not enough for that.
The US is not unique in having these "zero liability" policies (which are of course, nothing more than contractual clauses between cardholders and card issuers which carry several conditions).
In most countries with "Chip and PIN", cardholders are not legally liable unless the bank can prove that you made the transaction - and use of a PIN is not enough for that.