Monzo Labs: Improved Card Security

UK merchant’s terminals (and a few other countries - France, Ireland, Iceland come to mind)

It’s largely an accident of history. There are two ways a terminal can verify your PIN:

  • “Offline PIN verification”, where the card verifies the PIN. This is what UK cards prefer, and all non-obsolete UK terminals support. (This can be used for offline transactions)
  • “Online PIN verification”, where the issuer verifies the PIN. This is what many cards from other parts of Europe support, also what all ATMs use, and what needs to be used for contactless-and-PIN (as the card is no longer present when the PIN is entered and verified)

Which a region prefers tends to depend upon how the card networks evolved in that country:

  • Regions where magstripe & sign used to be common often adopted offline PIN; this was an easier migration as the issuer doesn’t need to start storing card PINs (Interesting note: with some magstripe only cards the PIN is stored encrypted on the magstripe and verified by the network)
  • Regions where magstripe & PIN used to be common often adopted online PIN (becuase they were already using online PIN). Lots of cards from these regions don’t support offline PIN at all.

Terminals from the offline PIN regions aren’t required to support online PIN, and aren’t permitted to support it on the contactless interface; probably this was partially because of an industry decision to encourage mobile wallet payments

13 Likes