Visa Australia kills signatures by 2013

Visa Australia said today it was moving to chip and PIN technology for all of its credit cards, with signature transactions to be banned by April 2013.

(Credit: Visa, by Declan TM, CC2.0)

The move, instigated to reduce card fraud, involves working with financial institutions and retailers to upgrade over 14 million visa cards, half a million point of sale terminals, and thousands of ATMs.

From January 2010 all new Visa cards will feature smart chips, while debit and reloadable prepaid cards will be updated from January 2011. Currently around 37 per cent of Australian Visa cards are chip-enabled. 100 per cent of credit cards will be chip cards by 1 April 2013. All merchant terminals must be chip-capable by April 2012. All ATMs must be chip capable by 1 January 2011.

"These initiatives are part of a comprehensive security upgrade aimed at providing cardholders with a higher level of confidence and significantly reducing all types of card fraud including counterfeit, skimming and online fraud," Visa's general manager for Australia and New Zealand, Chris Clark said in a statement.

The upgrade will also allow banks and merchants to offer their customers more services such as contactless payments and storing rewards program information on cards.

Moving to chip and PIN was part of Visa's seven-point security agenda, which included using Verified by Visa passwords when shopping over the internet and requiring retailers to capture the three-digit cardholder verification number when processing transactions.

"While card fraud in Australia remains low by world standards, overseas criminals are becoming increasingly active in seeking out new arenas. The time is right to take advantage of the new technologies available to work across the industry, with banks and merchants, to strengthen security across the board," Clark said.

Advertisement

Talkback 13 comments

    report scam artists Chris -- 02/11/09

    you can report scam artists anonymously and for free to suspectedscammers.com. you can also search our database for reported scam artists for free. we do this as a public service to make the internet a better place to do business.

    And you are...? Any Y. Mouse -- 02/11/09 (in reply to #320390394)

    Report scam artists to whom? What jurisdiction do you operate under? Under whose authority do you operate?

    Agreed Mel Sommersberg -- 02/11/09 (in reply to #320390401)

    The only place to report a scam artist, including Chris, is the police.

    good idea Anonymous -- 02/11/09

    But it won't eliminate fraud - it will just make it different. Case in point: EFTPOS cards have PINs, yet there are widespread card-skimming scams that defraud millions from these (such as the widespread scam in Perth that has been in the news over the last couple of months).

    VISA - Chip and PIN - Ban Passwords on Internet! Bill Caelli -- 02/11/09

    OK VISA - good move.
    Now - be consistent and stand by your security stance, statements and policies as reported here and ban use of passwords and related PC keyboard usage for Visa transactions on the Internet. Keyboard "sniffing" is now a standard part of malware "products" and SSL/https doesn't help at all in this regard.

    We don't even have a signature in those cases - unbelievably risky - but Visa doesn't offer anything else!!

    Let our Chip and PIN units become PINPads for our PCs via a USB/Bluetooth interface, for a start.

    Be logically consistent in your information security policies and products. If it is vital for security at the merchant's site, it is FAR MORE important at home, buying off the 'Net with Visa!

    Onus of pin [mis]use? Anonymous -- 02/11/09

    If (or when, as seen in WA recently) your card id and pin gets skimmed on whom will the proof of theft be required?
    I assume they will continue to use the existing hardware to read/send the same code and pin which is already being skimmed - so what difference will a mandatory pin make. At least now they cant skim the signature. Wonder how soon it will be before Visa claim YOU lost (or allowed) the pin to be made known, and thus the transaction is still yours?

    What happens when you go overseas? Q -- 02/11/09

    Surely Visa in other countries wouldn't have the same schedule for implementation. What happens when you go overseas, and the their policy requires signatures and not PIN.

    The chip part is a good move though - depending on the chip, it can be much harder than the magnetic strip to skim.

    Beware! Anonymous -- 02/11/09

    Read the T&Cs of your VISA and you'll see that if you use a PIN for a particular transaction you are then SOLELY responsible for that transaction! In other words, unlike currently how you can dispute the transaction and you will most likely win, with PIN you are stuck with having to pay if your card is comprimised.

    This has little to do with 'improving security' and more to do with who they can lay the blame on. They can reduce the amount of fraud THEY are held responsible for, by passing the blame on users.

    Here Here Anonymous -- 04/11/09 (in reply to #320390447)

    I for one have refused to move to PIN for this exact reason and it's a move that the banks and credit card companies want, as the onus is then on the card user.

    With a card scanner and a PC any card that is lost will be able to have the PIN read on that card which in turn will be able to be used for any transaction. Alternatively using your card at a retail outlet you could also have your card skimmed like at McDonalds in WA. For those transactions you will be totally liable under your T&C of the card.

    So everyone out there please read your T&C's and refuse to move blindly to PIN on your cards. It's time Australia to push back against the banks and credit card companies so they realise that they can't try and dupe us again.

    The pin is not stored on the card mike smith -- 04/11/09 (in reply to #320390588)

    The skimming happens when *you* enter the pin after having swiped your card on a compromised system.

    Visa Anonymous -- 03/11/09

    Some of us prefer to sign - I don't use EFTPOS and never have, I don't like using passwords on the Internet and it will make it even riskier to use the card. At least we have the choice at the moment - not everyone likes remembering passwords all the time and you do get blanks where you have no idea what they are. You're not supposed to have them written down on you anywhere so what do you do? Elderly people will not thank Visa for this. They will be more likely to cut the card up than remember a password as would some with certain disabilities. Signature should always be an option.

    Shifting the losses Anonymous -- 04/11/09

    Once again we have ZDNet just reprinting a media release, not actually questioning anything.

    A previous poster hinted at what's already happened in other countries - the Terms & Conditions putting full onus on the customer for fraudulent transactions where chip & PIN is used. This is unacceptable.
    Where's the detail on what if any security requirements Visa have on merchants to ensure that Chip & PIN pads use only encrypted communication with the next device (EFTPOS terminal/etc.) - some assurance that your card and PIN details can't just be skimmed?

    This type of fraud has already started in other countries (like the UK) where they have already forced the use of chip & PIN.

    As soon as Visa (or anyone else) push the cost of fraud to me, they'll lose me as a customer.
    I'll go back to cash if I have to. (Them being able to track my purchases is enough taking advantage of me already.)

    Interesting stuff Renai LeMay -- 04/11/09 (in reply to #320390581)

    Interesting comments, I'll see if we can follow this up. Thanks for highlighting this!

    Cheers,

    Renai LeMay
    News Editor
    ZDNet.com.au

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Chris Duckett Get extensions going in Firefox, redux
    Previously on Null Pointer we looked at getting extensions working in Firefox betas, and that was great until the fine folks at Firefox changed their minds.
  • Array How reliable is IP telephony?
    Have you ever heard a weird kind of hissing, crackling or popping noise when calling someone on an IP telephony line? How rare is the phenomenon these days?
  • Array Forget the NBN, 100Mbps is already here
    Telstra and TransACT will shortly begin offering 100Mbps broadband to many customers. By moving early, the companies have not only raised the bar for Australia's broadband services, but thrown down a challenge to a government that now faces increased pressure to deliver the NBN as promised.
  • More blogs »

Tags

Back to top

Featured