* Posts by BruceWayne

1 publicly visible post • joined 12 Feb 2010

Chip and PIN security busted

BruceWayne
Pirate

Not quite

The card also retains a 'history' of what happened during a transaction - the CVR. This will indicate that the PIN has not been verified. The CVR is sent to the issuer host via the acquirer network and thus if the issuer system is setup to crosscheck the TVR with the CVR (to ensure consistency in what the card and the terminal are reporting in terms of cardholder verification) - this will 'inconsistency' will be picked up. The issuer host may then decide to decline the transaction and raise appropriate alerts if need be.

In my opinion - close - but no cigar!