Chip and PIN

James Davis ukcrypto at chiark.greenend.org.uk
Fri, 25 Jan 2008 12:04:37 +0000


Peter Tomlinson wrote:

> So why cannot we get them to divulge their investigative methods (if 
> indeed they do investigate)?

I've never been convinced that the banks understand their systems well 
enough to investigate. Out of the three times my card has been locked 
due to suspected fraud the reasons have been..

"Buying expensive electronic goods" ... from a shop I'd been a customer 
at for years and spent non-trivial amounts with.

"An unsuccessful attempt to withdraw money at ATM1 and then a minute 
later successfully using ATM2 across the street." ... even though their 
records showed the failure of ATM1 was due to a fault and not an 
incorrect PIN.

"We don't know, the system has been flagging lots of false positives 
since Chip and PIN was introduced".

James

-- 
James Davis	+44 1235 822 229    	   PGP: 0x890F159E
JANET CSIRT	0870 850 2340	        (+44 1235 822 340)
Lumen House, Library Avenue, Didcot, Oxfordshire, OX11 0SG