Signature solution

[Dave Birch] There was a half-written blog post on my laptop that was about the US options for EMV migration, prompted by a discussion I was party to earlier in the year. The discussion was about cutting the cost of US EMV deployment by forgetting about offline transactions.

Let’s say for a moment that the US implements EMV and goes the way of on-line PIN verification only.

[From� Why US travellers’ EMV cards may not work in Europe]

This would be crazy. At the recent Smart Card Alliance conference in Chicago, my colleague� Stuart Fiske from� Consult Hyperion had a (moderately intemperate) go at a couple of speakers who were saying chip and online PIN was a good idea. He made the point that offline PIN was the� only globally interoperable solution and that the US should go with it and he got a big round of applause for doing saying so. I don’t see the point of issuing EMV cards and then using them with an online PIN: if the merchant has a PIN pad then why wouldn’t you use chip and offline PIN? And I can see a practical problem here: if customers are encouraged to continue to use cards that are chip and online PIN only, then when they get off the plane at Heathrow and try and buy a train ticket in a machine, they won’t be able to buy anything because the online PIN won’t work (it will only work in ATMs).

Having just got back from a few days in the US, I decided to dust off this piece about the EMV options and tidy it up, because Visa has announced its EMV migration plan for the USA. In our little corner of the payments world, this is officially a big deal.

But in a departure from nearly every other global market that has switched to EMV cards, which are commonly called chip-and-PIN for their most prominent security feature, Visa’s plan excludes PINs.

[From� Visa s Plan to Drop PINs Leaves Some Concerned About Security - American Banker Article]

It would be interesting to understand the reason for this, so I went over to Visa’s site to see and I found a rather odd statement.

And we continue to believe that long-term static data elements, including PIN, can create an increased risk for fraud. An increase in ATM fraud could occur in cases in which the PIN is stolen along with cardholder account information.

[From� PIN largely unaffected in U.S. migration to EMV chip « Visa’s Blog – Visa Viewpoints]

This is what used to happen in the UK. People would steal card details along with the PIN and then use those details to create counterfeit magnetic stripe cards to use at US ATMs. But they can’t do that anymore because the UK issuers have moved to ICVV (which means that the card details on the chip are different from the card details on the stripe, so you can’t make a bogus stripe card with chip details). And in any case this only worked because you could copy magnetic stripe cards: you can’t use the cardholder data to make chip cards. So once the US ATMs turn off the magnetic stripe fallback for Visa card, counterfeiting isn’t a threat at ATMs and it doesn’t matter if someone gets hold of the card details and the PIN. There must be another dynamic.

In the US market there are about six million POS terminals in use and about a quarter of them already have PIN pads. These PIN pads, which are used for online PINs, are already secure enough to use for offline PINs. Hence Visa’s point…

Visa will continue to support online PIN as a cardholder verification method for debit transactions, and at the same time encourages the move toward future adoption of dynamic cardholder verification methods.

[From� PIN largely unaffected in U.S. migration to EMV chip « Visa’s Blog – Visa Viewpoints]

A digression. If you’re getting confused about what’s going on here, you need to take a break and go back to EMV basics. The EMV specification allows for a number of different Cardholder Verification Methods (CVMs) and any particular card will have the acceptable CVMs stored on it, in order, by its issuer. These could be (in no particular order):

  • Plain-text offline PIN, the default in the UK;
  • Enciphered offline PIN—which should be the only option in the UK, but isn’t because we started by issuing Static Data Authentication (SDA) cards that couldn’t support it. Now we are issuing Dynamic Data Authentication (DDA) cards we really should be moving over to this option to stop PINs from being harvested from terminals that have been tampered with;
  • Encrypted online PIN—where there is an offline PIN as well (e.g., my Barclays debit card) then the online and offline PINs are synchronised in the back end.
  • Signature.
  • Nothing.

You can also have combinations of these, with the most obvious example being signature plus enciphered offline PIN for the paranoid. To illustrate the point with a real case study: one of the UK cards that is in my pocket right now has the following actual CVM list in priority order:

  • encrypted online PIN for cash at ATMs;
  • plain text offline PIN for purchases;
  • enciphered offline PIN for purchases;
  • signature for purchases.

This means that if I go into a shop and their PIN pad is broken or my chip is damaged, I can still buy something and sign for it. I could imagine a typical Visa US debit card having a different CVM list:

  • encrypted online PIN for cash at ATMs;
  • signature;
  • encrypted online PIN for purchases.

Please note: this is speculation based on public documentation only. Why does this approach make sense when online PIN only doesn’t? Well, the US is never going to get rid of signatures in the timeframe under discussion for EMV this makes for an easy transition. The signature is decoupled from the chip infrastructure as it as anyway so, basically, whatever the chip says the merchant terminal can just ask for a signature anyway and most Americans won’t notice any difference.

that there are more EMV markets that have implemented chip and signature than chip and PIN.

[From� PIN largely unaffected in U.S. migration to EMV chip « Visa’s Blog – Visa Viewpoints]

There may be another factor here, though. The US is a special case because the interchange on signature transactions is higher than the interchange on PIN transactions (or at least it was: who knows where Durbin will take it) and therefore issuers want to keep signature going for a long as possible despite the large retailers having PIN pads in place.

If Wal-Mart had its way, mag-stripe cards would disappear immediately, to be replaced with cards running chip and PIN.

[From� Untitled]

As I said. So why bother with chip and signature? I think the explanation might be that Visa USA, in common with many industry observers, just don’t see the current cards and terminals as a long-term technology worth investing in. Hence the reasonable, from their point of view, compromise. You issue chip and signature cards for credit and debit. The debit cards have encrypted online PIN as well for use at POS with the current pin pads. This works fine in the US and at international ATMs. The only place where it causes problems is international unattended terminals that accept offline PIN only (such as Belgian petrol stations) and for international travellers the US banks can issue cards with offline PIN anyway. All sensible from the US perspective. While I was googling for something else on this topic, as an aside, I came across this voice of the customer that confirms this analysis.

I have a Citibank Singapore chip-and-signature EMV card. It caused a lot of confusion in Europe when it was a chip card that wanted a signature, and again in New Zealand as they started their EMV rollout. Only time I recall it failing in Europe was trying to buy rail tickets at AMS, where my mag-only cards also didn’t work

[From� USA issuers announce EMV cards (Chip & PIN -or- Chip & Signature). - Page 3 - FlyerTalk Forums]

When I last used my chip and PIN card in Singapore, I was asked for PIN and signature, because of the decoupling mentioned earlier, but that’s a digression. At some point in the future, we’re going to stop entering PINs in POS terminals. I’ve said before that in the next generation of consumer payments, we must make a fundamental change in the point-of-sale (POS) user interface by ending the practice of having customer enter a PIN into something that isn’t theirs. The cost of providing certified PIN pads is high: making customers buy their own non-certified PIN pad seems like a much better solution all round. Since most customers have already bought a non-certified PIN pad (their mobile phone) that has other security features associated with it, we (the industry) may as well use them. This means using the “PIN” to unlock a handset-based wallet, not to authenticate card transactions.

To see the more interesting future context Visa USA’s announcement, then, you have to stop thinking about cards and terminals and start thing about virtual cards and phones. Post 2015 people will be using their chip and signature cards, it’s just that those cards will be inside mobile phones and will have all sorts of other security that cards don’t so the offline PIN is less relevant. This way, the readers (POS terminals, television, Squares, iPhones and goodness knows what else) will be spared the expense of a certified PIN entry devices and innovative new solutions can come to market exploiting chip-based dynamic authentication. These are, I stress, merely my reflections on the topic based on public statement, but I think they’re a reasonable summary of the current situation.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers


These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

There’s a fine line between legal and illegal counterfeiting, isn’t there?

[Dave Birch] I was fascinated to read about this recent addition to the historical collection of the Holocaust museum in Israel.

the collection of 43 drawings by Felix Cytrin of his fellow Jewish prisoners have been donated to Yad Vashem, Israel’s Holocaust memorial and museum, where researchers can study them and they will be exhibited for public viewing.

[From� Portraits of Jewish ‘counterfeiters’ donated - Israel Jewish Scene, Ynetnews]

Why was I reading about these particular drawings of these particular prisoners? Well, its because

They are among the few images that exist of the young men who worked in an infamous secret Nazi operation to produce fake money, fictionalized in the Oscar-winning film “The Counterfeiters.”

[From� Portraits of Jewish ‘counterfeiters’ donated - Israel Jewish Scene, Ynetnews]

If you’ve never seen it, “The Counterfeiters” is an excellent film. It won the 2007 Oscar for best foreign film (I saw it in the original German with English subtitles) and is the true story of the Nazi’s plot to destroy the British economy. I originally came across it because my son was studying German at high school and he visited Sachsenhausen as part of a cultural visit to Germany a couple of years ago. I was so fascinated by the story he came back with that I ordered the movie on Amazon immediately.

The film is based on a memoir written by Adolf Burger, a Jewish Slovak typographer who was imprisoned in 1942 for forging baptismal certificates to save Jews from deportation, and later interned at Sachsenhausen to work on Operation Bernhard.

[From� The Counterfeiters (film) - Wikipedia, the free encyclopedia]

Operation Bernhard was the Nazi plan to devastate the British and American economies by flooding them with counterfeit banknotes. They took 143 Jews from a variety of trades—printing, engraving and at least one convicted master counterfeiter,� Salomon Smolianoff—and moved them from different death camps to a special unit: “Block 19” in� Sachsenhausen concentration camp. There they set about forging first the British and then the American currency. They succeeded in making Sterling notes that fooled the Bank of England and then, almost at the end of the war, fake Dollars.

With defeat staring them in the face, the Nazis packed up all their paraphernalia, including printers’ plates and counterfeit bills, into crates which they dumped into Lake Toplitz, the deepest, most isolated lake in Austria. Toward the end of the war, they also cast chests of Nazi gold into its depths, gold which they had looted from conquered European countries. Ever since the end of the war, this has been a lodestone for treasure hunters.

[From� The Counterfeiters]

The Nazis were never able to put their plot into operation. The original idea, conceived at the very start of the Second World War, was to drop the worthless banknotes over England, thus causing economic instability, inflation and recession. Remember, in 1939 the German people had very recent memory of worthless paper currency devastating the economy, as chronicled in Adam Fergusson’s book “When Money Dies” that was given out at the last London BarCampBank. In the end, the prisoners forged around Sterling 132 million, which is about four billion quid in today’s prices. Now, printing four billion quid’s worth of worthless paper money not backed by anything might sound like a reasonable way to destabilise the economy, but I don’t think it would have worked. In the last four years, under what is now know as “quantitative easing” rather than “counterfeiting”, the Bank of England has printed around two hundred billion of imaginary Sterling (i.e., fifty times as much as the Nazis).

UK’s £200bn programme of asset purchases – known as quantitative easing – on hold, Bank of England announces

[From� Bank of England halts quantitative easing | Business | guardian.co.uk]

Rumours abound in today’s newspapers that they are about to turn the printing presses on again. It’s interesting to reflect that many economists think that Hitler’s plan (i.e., dropping the money from planes) would have had a more positive impact on economic growth than the Bank of England’s (i.e. giving the money to bankers). That kind of economic warfare predates Hitler by some time. In fact, he probably stole the idea from us Brits in the first place.

During the American Revolution, the British counterfeited U.S. currency in such large amounts that the Continental currency soon became worthless. “Not worth a Continental” became a popular expression of the era.

[From� United States Secret Service: Criminal Investigations]

The idea was already old then! During the American revolution, the British had taken to counterfeiting money on a large scale while they occupied New York, an action seen as being one of perfidious Albion’s sneakiest tactics.

Thomas Paine was even more outraged, publishing an open letter to the British commander in which he assailed the decision to counterfeit the dollar. “You, sir,” he wrote, “have the honor of adding a new vice to the military catalogue, and the reason, perhaps, why the invention was reserved for you, is, because no general before was mean enough even to think of it.”

[From� The New $100 Bill and the War Against Counterfeit Money - WSJ.com]

I can’t imagine that this is true—I’m sure it had been done before—but Paine’s outrage about the underhand nature of economic warfare is worth noting, not that economic warfare was either new or a stranger to our shores even then. Britain’s first economic terrorist and our official blog hero,� Sir Thomas Gresham, had dabbled most effectively two centuries before.

In 1587, he “cornered” bills of exchange drawn on Genoan banks so effectively that he was able to disrupt the build-up of resources for Phillip II’s Great Armada , demonstrating how sophisticated economic warfare had become by the 1580s.

[From� Digital Money: The queen would not have it called, as in other countries, the Bourse]

So is quantitative easing a sound government policy or a secret plot to destroy our economy? Personally, I’ll always support the cock-up theory of history over the conspiracy version. In which vein I can’t help noting the final supreme irony of Hitler’s attempt to ruin Sterling more effectively than the Chancellor of the Exchequer. Laurence Malkin (author of a detailed history of Operation Bernhard called “Krueger’s Men: The Secret Nazi Counterfeit Plot and the Prisoners of Block 19”) notes that after the war,

Through one of the Jewish money launderers, the Jewish underground passed on thousands of counterfeits to help the ingathering of exiles to Palestine and the purchase of war materiel for the nascent Israeli army.

[From� Lawrence Malkin - Krueger’s Men Secret Nazi Counterfeit Plot Operation Bernhard - The Story]

There really is a law of unexpected consequences and it really does apply to money.

These are personal opinions and should not be misunderstood as representing the opinions of
Consult Hyperion or any of its clients or suppliers


These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.