Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

Required fields*

14
  • 12
    Yes. When evaluating a security procedure, you have to consider all realistic threats. It's quite possible for a new procedure to make you more vulnerable to attack X, but nevertheless be a good idea because it makes you less vulnerable to Y to an extent that more than makes up for X. And I'd add, signatures don't really offer much security. I rarely see stores check my signature. And if someone stole your card, he could practice forging your signature. Commented Jun 14, 2016 at 3:23
  • 1
    "The biggest security risk with the new cards is that many vendors don't actually require use of the chip at all -- they still let you swipe." This. The day that new payment cards in the U.S. no longer come with magnetic stripes in the first place will be a great day for financial information security. Commented Jun 14, 2016 at 6:13
  • @halfinformed or at least the day when the terminal can verify with the issuer whether the card is supposed to have a chip, and deny a swipe if so. Until then, an attacker can clone a card from the magstripe and simply zero the "I have a chip" bit, and the "PLEASE INSERT CARD" message won't come up. Commented Jun 14, 2016 at 6:35
  • @halfinformed I personally intentionally wreck my mag stripe, and don't use it anywhere that forces me to swipe it. To me, any place that does not have a chip reader is sketchy. Commented Jun 14, 2016 at 15:07
  • 7
    @MasonWheeler: Did you actually inform your bank of your new address before you make the purchase? If you didn't, that means the fraud detection system is actually working great; I would have been much more annoyed if the bank naively let that transaction through. Leaving record of stopping automatic payments isn't the same as telling the bank that you are moving. Commented Jun 14, 2016 at 15:29