Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Hold on. PIN is not secure either. With the card reader, you can verify the pin locally: You don't need anything but the card and a card reader. No internet, no nothing.

Since the verification can be done on the client side entirely it's subject to hacking. You can freeze the chip, slowing it down so you can actually see it run under a microscope. You can make it read-only (so the pin miss is not recorded on the chip, aso aso).

There are recorded cases where the card also held a digital wallet and students made it read only so they had an infinite wallet for small expenses ...



Most credit card fraud happens by cloning an existing card because the victim will stay unaware of the crime. If you physically steal a card it will be frozen by its owner who will also pay close attention to suspicious transactions.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: