Page 3 of 5 FirstFirst 12345 LastLast
Results 61 to 90 of 134

Thread: Tests show fastest way to board passenger planes

  1. #61
    Senior Member
    Join Date
    Jan 2010
    Location
    Amsterdam/Istanbul
    Posts
    12,462
    Quote Originally Posted by CitizenCain View Post
    Weird... at least from a North American standpoint. Why are things that way in your charming little lowlands?
    I *think* it's got to do with the prevalence of debit cards. As most people use those I imagine it was a question of there not being enough mass in credit card payments to get the charges per transaction low enough for them to make credit cards an attractive method of payment for retailers.

    In Turkey it's the reverse; there I use my credit card pretty much everywhere and my debit card close to never.

  2. #62
    Interesting. Do lots of people just not have credit cards?

  3. #63
    Quote Originally Posted by CitizenCain View Post
    and the person doing the ringing invariably tries to fill the silence with inane banter.
    This will decrease if you can convince your fellow customers to not complain, thus lowering CRI scores, because the cashier isn't "friendly" or "personable", or "interested in doing anything but ringing up their purchase in the quickest manner possible."
    . . .

  4. #64
    De Oppresso Liber CitizenCain's Avatar
    Join Date
    Apr 2010
    Location
    Bottom of a bottle, on top of a woman
    Posts
    3,423
    Quote Originally Posted by Hazir View Post
    I *think* it's got to do with the prevalence of debit cards. As most people use those I imagine it was a question of there not being enough mass in credit card payments to get the charges per transaction low enough for them to make credit cards an attractive method of payment for retailers.

    In Turkey it's the reverse; there I use my credit card pretty much everywhere and my debit card close to never.
    Huh. You know, over here, a lot of banks discourage their customers from using their debit card as a debit card by charging a fee every time you pay with it as one, and not charging a fee if you run it as a credit card. I use my debit card all the time, and a credit card almost never, but I always run my debit card as credit, since I get charged $0.50 per transaction if I don't. (Another reason I fucking hate traveling to Europe - merchants generally won't let me run it as credit, because it doesn't have that "advanced" "security" chip deal, so I gotta either carry fat wads of cash everywhere, or get an avalanche of fees on every little purchase. Ugh.)

    I guess it's probably the same transaction processor issue (use VISA's servers instead of slamming the bank's)? Or something.

    Quote Originally Posted by Illusions View Post
    This will decrease if you can convince your fellow customers to not complain, thus lowering CRI scores, because the cashier isn't "friendly" or "personable", or "interested in doing anything but ringing up their purchase in the quickest manner possible."
    Well, sure, but that assumes I want the inane banter to stop, or don't have an easier way of stopping it.
    "I predict future happiness for Americans if they can prevent the government from wasting the labors of the people under the pretense of taking care of them."

    "The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants."

    -- Thomas Jefferson: American Founding Father, clairvoyant and seditious traitor.

  5. #65
    Quote Originally Posted by CitizenCain View Post
    Huh. You know, over here, a lot of banks discourage their customers from using their debit card as a debit card by charging a fee every time you pay with it as one, and not charging a fee if you run it as a credit card. I use my debit card all the time, and a credit card almost never, but I always run my debit card as credit, since I get charged $0.50 per transaction if I don't. (Another reason I fucking hate traveling to Europe - merchants generally won't let me run it as credit, because it doesn't have that "advanced" "security" chip deal, so I gotta either carry fat wads of cash everywhere, or get an avalanche of fees on every little purchase. Ugh.)

    I guess it's probably the same transaction processor issue (use VISA's servers instead of slamming the bank's)? Or something.
    For some reason, at least in Finland, those fees are paid by the stores, so they're hidden in the price of everything and you end up paying for other people's debit purchases if you're buying with cash. If you want to look at it that way.
    In the future, the Berlin wall will be a mile high, and made of steel. You too will be made to crawl, to lick children's blood from jackboots. There will be no creativity, only productivity. Instead of love there will be fear and distrust, instead of surrender there will be submission. Contact will be replaced with isolation, and joy with shame. Hope will cease to exist as a concept. The Earth will be covered with steel and concrete. There will be an electronic policeman in every head. Your children will be born in chains, live only to serve, and die in anguish and ignorance.
    The universe we observe has precisely the properties we should expect if there is, at bottom, no design, no purpose, no evil, no good, nothing but blind, pitiless indifference.

  6. #66
    The debit charges don't make sense. I thought stores get charged for each credit transaction, not each debit transaction? If so, why would they charge extra for debit cards instead of credit cards? I do know it's illegal for stores to charge extra for using credit cards in many states, though it's not particularly well enforced.
    Hope is the denial of reality

  7. #67
    The debit charges don't make sense. I thought stores get charged for each credit transaction, not each debit transaction? If so, why would they charge extra for debit cards instead of credit cards? I do know it's illegal for stores to charge extra for using credit cards in many states, though it's not particularly well enforced.
    Do you think that should be illegal? I've had freinds who use the fact stores are charged to use credit card to persuade the register person to discount their purchas if they pay in cash. They have.. helps they're a good socializer so the register lady was aleady warmed up to him, but it was neat.

  8. #68
    Let sleeping tigers lie Khendraja'aro's Avatar
    Join Date
    Jan 2010
    Location
    In the forests of the night
    Posts
    6,239
    Quote Originally Posted by CitizenCain View Post
    because it doesn't have that "advanced" "security" chip deal, so I gotta either carry fat wads of cash everywhere, or get an avalanche of fees on every little purchase. Ugh.)
    No reason to put the advanced in quotes. It IS advanced. You can't copy the data from the chip the way you can simply skim a magnet stripe. Skimmers have become incredibly advanced - the ideas those people have are simply astounding.
    When the stars threw down their spears
    And watered heaven with their tears:
    Did he smile his work to see?
    Did he who made the lamb make thee?

  9. #69
    Senior Member Flixy's Avatar
    Join Date
    Jan 2010
    Location
    The Netherlands
    Posts
    6,435
    Quote Originally Posted by Dreadnaught View Post
    Interesting. Do lots of people just not have credit cards?
    Most people don't no, and most who do mostly have one either for traveling, buying stuff online (though you need credit cards less and less for that), or from their job.
    Quote Originally Posted by Nessus View Post
    For some reason, at least in Finland, those fees are paid by the stores, so they're hidden in the price of everything and you end up paying for other people's debit purchases if you're buying with cash. If you want to look at it that way.
    Well, cash also costs money. Getting change and depositing money, that is. Shops often prefer debit or credit cards, because it saves them a lot of hassle, some costs, and you're safer against robbery when you simply have less cash. And the records keeping is simpeler.
    Keep on keepin' the beat alive!

  10. #70
    De Oppresso Liber CitizenCain's Avatar
    Join Date
    Apr 2010
    Location
    Bottom of a bottle, on top of a woman
    Posts
    3,423
    Quote Originally Posted by Khendraja'aro View Post
    No reason to put the advanced in quotes. It IS advanced. You can't copy the data from the chip the way you can simply skim a magnet stripe. Skimmers have become incredibly advanced - the ideas those people have are simply astounding.
    No, not true at all. The crypto routines (or implementations) make it trivial to crack that chip security. It's not actually advanced, it just looks that way to a casual observer used to no protection at all, in the case of magnetic stripes. (Wasn't it on here that we had that discussion about the fundamental flaws of that security implementation which allow "hackers" to impersonate any chip-"protected" card with less $50 worth of hardware and a few KB of crypto routines? I could swear it was...)

    It's like calling WEP "encryption." (Or ROT13 for that matter.) I guess, technically that's factual, but it's not secure when you smash through it in a few minutes (max) with a $50 LPC and a wireless adapter.

    Security theater, not actual security.

    Quote Originally Posted by Flixy View Post
    Most people don't no, and most who do mostly have one either for traveling, buying stuff online (though you need credit cards less and less for that), or from their job.
    Well, cash also costs money. Getting change and depositing money, that is. Shops often prefer debit or credit cards, because it saves them a lot of hassle, some costs, and you're safer against robbery when you simply have less cash. And the records keeping is simpeler.
    I think the problem/issue/discrepancy comes from the way transaction processors structure fees for their services. For low-volume customers, like say, the corner store, the percentage and/or fixed fee per transaction that an electronic-based credit card payment processor takes might be above the store's profit margin, plus the fact that there's a recurring monthly charge for the service. At least that's how it works over here, so I assume it's not so different over there.

    The "costs" of accepting cash won't cause you to lose money on every sale, like an ungenerous credit card processing fee structure can.
    "I predict future happiness for Americans if they can prevent the government from wasting the labors of the people under the pretense of taking care of them."

    "The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants."

    -- Thomas Jefferson: American Founding Father, clairvoyant and seditious traitor.

  11. #71
    Senior Member Flixy's Avatar
    Join Date
    Jan 2010
    Location
    The Netherlands
    Posts
    6,435
    AFAIK, accepting debit cards doesn't cost you a monthly free, only per transaction, and one time buying a reader. But I could be wrong.

    The 'cost' of accepting cash is still a very real cost, just harder to estimate per purchase. And it is very different for different market segments. I do know that supermarkets are strongly advertising and pushing for debit card payments, as are the banks (stocking atms is also costly).

    I guess it's a bit of a catch 22, people don't have credit cards because they aren't widely accepted, and they aren't accepted because they aren't widely used. Add that having a credit card costs money, and that accepting them probably costs money too, and you have our situation.

  12. #72
    Let sleeping tigers lie Khendraja'aro's Avatar
    Join Date
    Jan 2010
    Location
    In the forests of the night
    Posts
    6,239
    Quote Originally Posted by CitizenCain View Post
    No, not true at all. The crypto routines (or implementations) make it trivial to crack that chip security. It's not actually advanced, it just looks that way to a casual observer used to no protection at all, in the case of magnetic stripes. (Wasn't it on here that we had that discussion about the fundamental flaws of that security implementation which allow "hackers" to impersonate any chip-"protected" card with less $50 worth of hardware and a few KB of crypto routines? I could swear it was...).
    It's like calling WEP "encryption." (Or ROT13 for that matter.) I guess, technically that's factual, but it's not secure when you smash through it in a few minutes (max) with a $50 LPC and a wireless adapter.

    Security theater, not actual security.
    Uh, you're absolutely and factually wrong. Sorry, dude, but get your facts straight before you open your mouth. FYI, Germany's banks are using SECCOS 6.

    Besides, I was talking about SKIMMING. You wanna tell me how to brute force a card where you can't copy the contents of the chip and which you can only access for mere seconds? Even with WEP you need more than a few seconds. And the chip on the card will of course allow brute-forcing - I mean, they certainly don't have a routine on the chip which does something like "count the number of failed PIN entries" or something. Nope, they certainly won't have thought of something like that at all.
    When the stars threw down their spears
    And watered heaven with their tears:
    Did he smile his work to see?
    Did he who made the lamb make thee?

  13. #73
    Senior Member Flixy's Avatar
    Join Date
    Jan 2010
    Location
    The Netherlands
    Posts
    6,435
    As I understood it, the extra safety isn't the encryption, but that you can't skim, like Khen says. With a magnetic strip it's easy to have an extra reader that copies the magnetic strip, but it's a lot harder to scan a chip and copy it.
    Keep on keepin' the beat alive!

  14. #74
    De Oppresso Liber CitizenCain's Avatar
    Join Date
    Apr 2010
    Location
    Bottom of a bottle, on top of a woman
    Posts
    3,423
    Quote Originally Posted by Khendraja'aro View Post
    Uh, you're absolutely and factually wrong. Sorry, dude, but get your facts straight before you open your mouth. FYI, Germany's banks are using SECCOS 6.
    Back atcha, your royal highness.

    Jackass. And yes, it's been exploited "in the wild" since 19 months ago when this theoretical attack was revealed. If you're going to be an aggressive, abrasive jackass, the least you could do is go through the minimal effort involved in typing "chip PIN card hack" into Google to make sure you're not talking out of your ass.

    Quote Originally Posted by Flixy View Post
    As I understood it, the extra safety isn't the encryption, but that you can't skim, like Khen says.
    Nope, those PIN+chip cards can be skimmed too, as in that link. Only for one transaction per skim, but does that really matter if I can take $8,000 from your account when you thought you were buying a Coke and a chocolate bar?

    Quote Originally Posted by Flixy View Post
    With a magnetic strip it's easy to have an extra reader that copies the magnetic strip, but it's a lot harder to scan a chip and copy it.
    You'd think, but it seems not. Well, it takes 3 cheap and readily available hardware components instead of 1, but not much else beyond that. No decryption involved, simply relay the information along in a classic relay attack scenario... which is what "skimming" is. A simple relay attack using a magnetic reader. Same thing as this attack, just in a different, medium (magnetic stripe vs electrical or EM wavelength communications).
    "I predict future happiness for Americans if they can prevent the government from wasting the labors of the people under the pretense of taking care of them."

    "The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants."

    -- Thomas Jefferson: American Founding Father, clairvoyant and seditious traitor.

  15. #75
    Let sleeping tigers lie Khendraja'aro's Avatar
    Join Date
    Jan 2010
    Location
    In the forests of the night
    Posts
    6,239
    Quote Originally Posted by CitizenCain View Post
    Back atcha, your royal highness.

    Jackass. And yes, it's been exploited "in the wild" since 19 months ago when this theoretical attack was revealed. If you're going to be an aggressive, abrasive jackass, the least you could do is go through the minimal effort involved in typing "chip PIN card hack" into Google to make sure you're not talking out of your ass.
    Good evening. That was SECCOS 5. Want to try again?

    And your "chip reading" is bullshit. You can't read the information inside a chip using such a method.
    When the stars threw down their spears
    And watered heaven with their tears:
    Did he smile his work to see?
    Did he who made the lamb make thee?

  16. #76
    De Oppresso Liber CitizenCain's Avatar
    Join Date
    Apr 2010
    Location
    Bottom of a bottle, on top of a woman
    Posts
    3,423
    No, because the encryption protocol doesn't matter to the attack. It's the communication that's skimmed, not the data, so encrypt it with triple cascading, 256 bit AES-Twofish-Blowifsh, for all it matters. So long as the communication channels remain insecure, which they do, the encryption is irrelevant to the attack.
    "I predict future happiness for Americans if they can prevent the government from wasting the labors of the people under the pretense of taking care of them."

    "The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants."

    -- Thomas Jefferson: American Founding Father, clairvoyant and seditious traitor.

  17. #77
    Let sleeping tigers lie Khendraja'aro's Avatar
    Join Date
    Jan 2010
    Location
    In the forests of the night
    Posts
    6,239
    Quote Originally Posted by CitizenCain View Post
    No, because the encryption protocol doesn't matter to the attack. It's the communication that's skimmed, not the data, so encrypt it with triple cascading, 256 bit AES-Twofish-Blowifsh, for all it matters. So long as the communication channels remain insecure, which they do, the encryption is irrelevant to the attack.
    Okay, mind telling me what you can use that encrypted data for?
    When the stars threw down their spears
    And watered heaven with their tears:
    Did he smile his work to see?
    Did he who made the lamb make thee?

  18. #78
    De Oppresso Liber CitizenCain's Avatar
    Join Date
    Apr 2010
    Location
    Bottom of a bottle, on top of a woman
    Posts
    3,423
    Yes. Because I wouldn't have to if you'd simply read and understood the link I helpfully provided.

    But if you're so sure this isn't possible, let's try this approach. If you make it worth my time, I will personally demonstrate the attack to you next time I'm over in one of our German offices (sometime between January 15th and March 31st). All I require from you is a PIN+CHIP card of choosing, linked to an account of your choosing and an agreement that you'll authorize a purchase of this... handsome company keyboard I'm typing on with it. I'll give you a great deal... I think it's an $80 keyboard, and I'll sell it to you for 1 Euro. Put, say, 5,000 Euros (or more, don't let me limit your generosity) in the account you'll be using to accept this incredible offer and I'll take it all, even though you'll only authorize a 1 Euro purchase to me.

    Deal?
    "I predict future happiness for Americans if they can prevent the government from wasting the labors of the people under the pretense of taking care of them."

    "The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants."

    -- Thomas Jefferson: American Founding Father, clairvoyant and seditious traitor.

  19. #79
    Let sleeping tigers lie Khendraja'aro's Avatar
    Join Date
    Jan 2010
    Location
    In the forests of the night
    Posts
    6,239
    Again, this attack is not possible anymore. Because they upgraded the system... the "6" is a version number.

    That attack was possible with SECCOS 5. We're using SECCOS 6.

    So, again, what use is the encrypted data to you?
    When the stars threw down their spears
    And watered heaven with their tears:
    Did he smile his work to see?
    Did he who made the lamb make thee?

  20. #80
    De Oppresso Liber CitizenCain's Avatar
    Join Date
    Apr 2010
    Location
    Bottom of a bottle, on top of a woman
    Posts
    3,423
    Again, if you're so sure, put your money where your mouth is. I don't care what version your Card/Chip OS is or what crypto it uses, I can drain your account by getting you to authorize any transaction.

    It's fine that you don't actually understand crpto or security fundamentals, but now it's time to put up or shut up. I'm even willing to bet my own money here and give you odds, if that's the issue. I've never made $400,000 an hour before, so either put up and let me, or stop wasting my time by propagating your ignorance.
    "I predict future happiness for Americans if they can prevent the government from wasting the labors of the people under the pretense of taking care of them."

    "The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants."

    -- Thomas Jefferson: American Founding Father, clairvoyant and seditious traitor.

  21. #81
    Let sleeping tigers lie Khendraja'aro's Avatar
    Join Date
    Jan 2010
    Location
    In the forests of the night
    Posts
    6,239
    Cain, again, this attack is not possible anymore. It was only possible because they did not implement one security feature the spec actually asked for. They fixed that.

    The attack worked like this: When verifying, the (manipulated) terminal in the middle sends the message "PIN OK" to the card, intercepting the original message from a non-manipulated terminal. However, this only works because the card did not demand cryptographically signed response messages, contrary to the specifications.

    And, for the last time, tell us how to use encrypted data you intercepted to draw arbitrary amounts of money. Also notice that the attack you displayed relies on one part of the communication being without crypto-protection...

    Oh, and I'm still waiting for your method to read information from a chip by wireless transmissions - without the chip possessing any antennas or protocols for transmitting data wirelessly. Also, do you know how asymmetric encryption works? Also consider that our direct debit cards require an online connection - offline terminals are not possible.
    Last edited by Khendraja'aro; 09-10-2011 at 09:12 PM.
    When the stars threw down their spears
    And watered heaven with their tears:
    Did he smile his work to see?
    Did he who made the lamb make thee?

  22. #82
    De Oppresso Liber CitizenCain's Avatar
    Join Date
    Apr 2010
    Location
    Bottom of a bottle, on top of a woman
    Posts
    3,423
    OK, you keep saying that and not backing it up. Enjoy your arrogant ignorance.

    If you change your mind and would like me to personally deliver the educational demonstration I've offered, it still stands, until such time as my visit to our German office ends, as do the terms I laid out earlier. In fact, I'll even sweeten it, by saying that instead of a keyboard, I'll sell you the $250 USD emergency cash I carry with me for a €1 "purchase" on your PIN+Chip card. That way I don't have to carry around a keyboard, or explain to the boss why a piece of company equipment disappeared. I'm not about to cut them in my >= €5,000 revenue.

    Since I'm coming to you, bringing everything with me and will only require a minute (or less) to perform this attack, it's a $250 profit for a minute of your time. Free money, and a public something you'll have to hold over my head here in perpetuity. So what's your hesitation, son? I see no reason you wouldn't accept my bet, other than you realizing it's a bad bet because you realize I **WILL** be able to take your money, but since there's no possibility that you're wrong, what with you being always right, and protected by a "secure" PIN+Chip card, that can't be it...

    So what's it to be? Are you going to accept my attempts to bend over backwards to give you a stack of free money with this offer of mine, or are you going to explain to the class what perfectly reasonable explanation you have for not wanting to spend 60 seconds of your time to get my $250???
    "I predict future happiness for Americans if they can prevent the government from wasting the labors of the people under the pretense of taking care of them."

    "The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants."

    -- Thomas Jefferson: American Founding Father, clairvoyant and seditious traitor.

  23. #83
    Let sleeping tigers lie Khendraja'aro's Avatar
    Join Date
    Jan 2010
    Location
    In the forests of the night
    Posts
    6,239
    Cain, did you read the paper of the British scientists? They specifically stated that they sent the PIN OK response by sending a simple 0x9000. Does that look cryptographically signed to you? The rest of my "proof" is a bit difficult since it's a rather lengthy document. But you can look for yourself if you really want to:
    http://www.emvco.com/specifications.aspx?id=19
    Chapter: 15.5.3.4 Terminal Erroneously Considers Offline PIN OK Check

    And would you now please answer me how you're easily able to remotely read a non-wireless-capable chip? Or did you pull that of your ass as well? And, no, using a SQUID or something else appartment-sized usually only found in Universities does not count as well.

    Oh, and if you're not able to explain your "methods" then I have to assume that you're blowing hot air. I mean, you were talking about "WEP" and ROT13 when the system uses RSA, for chrissakes!
    I can only assume that you're trying to pull a stunt like "manipulate the terminal so it shows the correct amount but withdraws another amount". This has the small drawback of all terminals being required to print a receipt - which leaves a papertrail landing you directly in jail.
    When the stars threw down their spears
    And watered heaven with their tears:
    Did he smile his work to see?
    Did he who made the lamb make thee?

  24. #84
    De Oppresso Liber CitizenCain's Avatar
    Join Date
    Apr 2010
    Location
    Bottom of a bottle, on top of a woman
    Posts
    3,423
    Cut the shit and the posturing. I've already explained what I'll do, and how, to the extent I'm willing to indulge your arrogant, insufferable ass without compensation. I'm not a free educational resource, especially not to folks who are generally ignorant, arrogant and annoying, so no, I'm not about to waste my time or expertise helping you learn when you're nothing but an insufferable ass to me. You're not a hot chick who sucks my cock to make up your personality deficits, so I will require compensation to educate you. Either in the form of money, some good or service I desire, or the opportunity to take your money with my offer to you.

    I'm already loaded up for bear, have everything I need and will be in your area within the next several months. I'm willing to come to you and let you "purchase" $250 dollars of your money for €1 of yours, to demonstrate this "impossible" attack.

    Do you want ~$248.78 for 60 seconds of your time, or not?

    Yes or no will suffice, there's really no need to dig yourself into a deeper hole by waxing idiotic about how my attack is impossible. (And no, there's no specialized gear involved - a flash memory module, some wires and some code I wrote myself or grabbed from FOSS sources. Not even a wireless adapter.)
    "I predict future happiness for Americans if they can prevent the government from wasting the labors of the people under the pretense of taking care of them."

    "The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants."

    -- Thomas Jefferson: American Founding Father, clairvoyant and seditious traitor.

  25. #85
    Senior Member
    Join Date
    Jan 2010
    Location
    Amsterdam/Istanbul
    Posts
    12,462
    Quote Originally Posted by Dreadnaught View Post
    Interesting. Do lots of people just not have credit cards?
    I know loads of people who have a credit card for 2 reasons only; the first being internet purchases, the second being travel. I myself hardly ever use my credit card in Holland. It wouldn't suprise me If I hadn't used it nationally in 2011.

  26. #86
    Senior Member
    Join Date
    Jan 2010
    Location
    Amsterdam/Istanbul
    Posts
    12,462
    Quote Originally Posted by CitizenCain View Post
    Huh. You know, over here, a lot of banks discourage their customers from using their debit card as a debit card by charging a fee every time you pay with it as one, and not charging a fee if you run it as a credit card. I use my debit card all the time, and a credit card almost never, but I always run my debit card as credit, since I get charged $0.50 per transaction if I don't. (Another reason I fucking hate traveling to Europe - merchants generally won't let me run it as credit, because it doesn't have that "advanced" "security" chip deal, so I gotta either carry fat wads of cash everywhere, or get an avalanche of fees on every little purchase. Ugh.)

    I guess it's probably the same transaction processor issue (use VISA's servers instead of slamming the bank's)? Or something.



    Well, sure, but that assumes I want the inane banter to stop, or don't have an easier way of stopping it.
    Run your debit card as a credit card ?

  27. #87
    De Oppresso Liber CitizenCain's Avatar
    Join Date
    Apr 2010
    Location
    Bottom of a bottle, on top of a woman
    Posts
    3,423
    Quote Originally Posted by Hazir View Post
    Run your debit card as a credit card ?
    Yeah, it's run through the credit card payment processor as if it was a credit card (Visa or Mastercard, depending on your particular debit card issuer), so instead of requiring a PIN entry for user authentication and authorization (as a debit card transaction would), there is no user authentication.

    Oh, right, so if you're in the US or Canada and manage to get someone else's debit card, you can drain the account attached to it without knowing the PIN. Nifty, eh?
    "I predict future happiness for Americans if they can prevent the government from wasting the labors of the people under the pretense of taking care of them."

    "The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants."

    -- Thomas Jefferson: American Founding Father, clairvoyant and seditious traitor.

  28. #88
    Quote Originally Posted by Hazir View Post
    Any credit cards, most supermarkets in my area have big signs at the entrance that they won't accept payment with credit cards. But of course reading a big sign is too much to ask. As for shops/restaurants accepting them, you shouldn't be too surprised if they still refuse to accept cards for small amounts.
    That's messed up, its not the tourists fault. Get into the 20th century, let alone the 21st and then complain

  29. #89
    Quote Originally Posted by CitizenCain View Post
    Yeah, it's run through the credit card payment processor as if it was a credit card (Visa or Mastercard, depending on your particular debit card issuer), so instead of requiring a PIN entry for user authentication and authorization (as a debit card transaction would), there is no user authentication.

    Oh, right, so if you're in the US or Canada and manage to get someone else's debit card, you can drain the account attached to it without knowing the PIN. Nifty, eh?
    Then you're using a dual credit/debit card. The solution is to use a dedicated debit card, or a dedicated credit card. Minimum charges (at certain vendors) go through without a PIN, and don't assess a user-fee. The down-side is the vendor can treat the card as credit until the post clears....which means a debit of $5.00 can add an extra "hold" of $50.00 to include the possible over-draft fee.

    A dedicated credit card requires either a PIN (to treat as debit) or authorized signature (to treat as credit). I know this for a fact, because my kids can't use my dedicated credit card. They don't know the PIN, and their signature doesn't match mine. They can, however, use my debit card....don't have to type in the PIN if it's for a small amount, but know the PIN and are never questioned about the name or signature on the card.

  30. #90
    Let sleeping tigers lie Khendraja'aro's Avatar
    Join Date
    Jan 2010
    Location
    In the forests of the night
    Posts
    6,239
    Quote Originally Posted by CitizenCain View Post
    Cut the shit and the posturing. I've already explained what I'll do, and how, to the extent I'm willing to indulge your arrogant, insufferable ass without compensation. I'm not a free educational resource, especially not to folks who are generally ignorant, arrogant and annoying, so no, I'm not about to waste my time or expertise helping you learn when you're nothing but an insufferable ass to me. You're not a hot chick who sucks my cock to make up your personality deficits, so I will require compensation to educate you. Either in the form of money, some good or service I desire, or the opportunity to take your money with my offer to you.

    I'm already loaded up for bear, have everything I need and will be in your area within the next several months. I'm willing to come to you and let you "purchase" $250 dollars of your money for €1 of yours, to demonstrate this "impossible" attack.

    Do you want ~$248.78 for 60 seconds of your time, or not?

    Yes or no will suffice, there's really no need to dig yourself into a deeper hole by waxing idiotic about how my attack is impossible. (And no, there's no specialized gear involved - a flash memory module, some wires and some code I wrote myself or grabbed from FOSS sources. Not even a wireless adapter.)
    Again, you are the one posturing. And you have not explained anything - just some magic handwaving and it'll magically work. Quit the crap about how your exploit works with "any" protocol and tell us. I mean, if it's that easy (and it has to be, for it to work with any protocol), we surely should be able to understand, right?

    If you're unable to explain your procedure then it does not exist. Period. I'm not wasting anyone's time here, you are with your idiotic refusal to talk actual technical points. You're just spouting diffuse nonsense trying to make it look like you're an expert. You obviously are not since you're unable to explain how your attack would work. I mean, you are not required to list every single detail but surely a procedural flow should be possible?

    Unless you're able to do that, you're only wasting our time with your hot air. As of yet, I've not seen any indication that you're actually the "expert" in cryptology you make yourself out to be. In fact, you getting facts wrong only shows that you're anything but. So, stop wasting our time and lay some facts on the table.
    When the stars threw down their spears
    And watered heaven with their tears:
    Did he smile his work to see?
    Did he who made the lamb make thee?

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •