advertisement
advertisement

Is A Rewritable Mag-Stripe The Answer To Cloned Cards?

Written by Evan Schuman
July 21st, 2010

The security worlds of bankers and retailers (ATMs and POSes/card swipes) have as much in common as they have differences. But some security work the Bank of New Zealand is doing–its version is called Liquid Encryption Number (LEN)–may hold a clue for the best way to combat cloned payment cards.

The idea, which isn’t especially new in security circles, has LEN rewriting “the data on a valid mag-stripe whenever a customer completes a transaction,” thereby making cloned card attempts pointless, according to a recent report in The Nilson Report. The technique has been used on all of the bank’s cards since 2008 and claims a 50 percent fraud reduction from counterfeit cards.

Clearly, there are pragmatic problems with applying this approach in retail. It requires specialized hardware. Plus, the bank’s control of ATMs is much more powerful and direct than a chain’s control over various card swipe devices, which are rarely replaced until it’s necessary.

“The thing with LEN, as I understand it, is that the bank needs to partially re-encode the stripe (like the old plans for track 3). Therefore, retailers need more than just a mag-stripe reader,” opined StorefrontBacktalk PCI Columnist Walter Conway. “Banks can put these in their ATMs, because they own/control them. Also, there are fewer units than if they had to replace every POS terminal in New Zealand. Maybe the answer to a secure card is EMV with a re-writable mag-stripe–and a picture, a signature, embossing, a hologram and writing the first 4 digits on the card.”

Walt’s point is a good one. Today, the most popular idea for attacking the cloners is some version of a digital fingerprint of the card. But isn’t rewriting the mag-stripe a different way of achieving the same objective? You either take a picture of the card and match future card attempts to that picture, or you change the card each time to what you want it to be.

Either way, you’ve made cloning much more difficult and less profitable. “It may be limited, but so was just about every disruptive and new technology at the start,” Conway said.


advertisement

2 Comments | Read Is A Rewritable Mag-Stripe The Answer To Cloned Cards?

  1. Steve Sommers Says:

    On paper this works but this was tried in the early days of mag stripe credit cards and it failed miserably. The problem is, one bad writer, or more likely, some percentage of faulty writers can render the entire system useless. There is a good chance that hardware has significantly improved in the 20+ years since it was tried, but I think you’ll still have some percentage of faulty writers and the overall system must compensate for this factor to be successful.

  2. David Griffiths Says:

    So … LEN has been sold to me as a cost-effective magstripe alternative to EMV, because EMV needs special card readers and processing systems. Just run that past me again, I must be missing something. EMV needs a certain infrastructure, but now that it’s pretty much implemented throughout the developed world, it’s not so much of an issue. Interesting that the cost effective magstripe alternative to EMV, the LEN solution, needs hardware upgrades to every POS and ATM in the world, in order to render the data on the stripe, clone resistant.

    Chips are already clone resistant, and magstripe clones only really affect transactions in the undeveloped world. Why should the developed world worry?

Newsletters

StorefrontBacktalk delivers the latest retail technology news & analysis. Join more than 60,000 retail IT leaders who subscribe to our free weekly email. Sign up today!
advertisement

Most Recent Comments

Why Did Gonzales Hackers Like European Cards So Much Better?

I am still unclear about the core point here-- why higher value of European cards. Supply and demand, yes, makes sense. But the fact that the cards were chip and pin (EMV) should make them less valuable because that demonstrably reduces the ability to use them fraudulently. Did the author mean that the chip and pin cards could be used in a country where EMV is not implemented--the US--and this mis-match make it easier to us them since the issuing banks may not have as robust anti-fraud controls as non-EMV banks because they assumed EMV would do the fraud prevention for them Read more...
Two possible reasons that I can think of and have seen in the past - 1) Cards issued by European banks when used online cross border don't usually support AVS checks. So, when a European card is used with a billing address that's in the US, an ecom merchant wouldn't necessarily know that the shipping zip code doesn't match the billing code. 2) Also, in offline chip countries the card determines whether or not a transaction is approved, not the issuer. In my experience, European issuers haven't developed the same checks on authorization requests as US issuers. So, these cards might be more valuable because they are more likely to get approved. Read more...
A smart card slot in terminals doesn't mean there is a reader or that the reader is activated. Then, activated reader or not, the U.S. processors don't have apps certified or ready to load into those terminals to accept and process smart card transactions just yet. Don't get your card(t) before the terminal (horse). Read more...
The marketplace does speak. More fraud capacity translates to higher value for the stolen data. Because nearly 100% of all US transactions are authorized online in real time, we have less fraud regardless of whether the card is Magstripe only or chip and PIn. Hence, $10 prices for US cards vs $25 for the European counterparts. Read more...
@David True. The European cards have both an EMV chip AND a mag stripe. Europeans may generally use the chip for their transactions, but the insecure stripe remains vulnerable to skimming, whether it be from a false front on an ATM or a dishonest waiter with a handheld skimmer. If their stripe is skimmed, the track data can still be cloned and used fraudulently in the United States. If European banks only detect fraud from 9-5 GMT, that might explain why American criminals prefer them over American bank issued cards, who have fraud detection in place 24x7. Read more...

StorefrontBacktalk
Our apologies. Due to legal and security copyright issues, we can't facilitate the printing of Premium Content. If you absolutely need a hard copy, please contact customer service.