Tiny open-source gadget simulates replacement Amex cards, disables chip-&-PIN

The Canadian banks pretty much do chip and pin properly. But then all the Canadian banks are part of a (legal) cartel called Interac, which allows the banks to impose good security on the customers, since there’s essentially no where else the customers can go.

And frankly, the idea that good security is painless is a dream. The whole point of good security is that it prevents taking any shortcuts, including the shortcuts we take when things don’t work properly. Chip reader out of order - no sale. Communication with the bank down - no sale. HSM unit breaks down - no sale, etc., etc.

Security can certainly be done badly, and many security errors could be corrected without impacting the customer experience. But I’m amazed at the number of holes that are deliberately left in in deference to customer demand. As a Canadian, it boggles my mind that American consumers have this much power over their banks. I guess it’s that consumer choice thing.