On Fri, 17 Jun 2005, Steven M. Bellovin wrote:
> Designing a system that deflects this sort of attack is challenging.
> The right answer is smart cards that can digitally sign transactions,
> but that would require rolling out new readers to all the merchants.

I was amazed to hear of the UK's fast progress in rolling out their
Chip-and-PIN system.  I would not have guessed that they could get
about 85% of cardholders to switch and 75% of retail equipment
upgraded by the end of 2004, only 15 months after the beginning of
the rollout.


Naturally, conditions are different in the United States, but it's
still an impressive result.

-- ?!ng

