* Some banks cards were vulnerable due to faulty crypto. The banks phased those cards out.
* Attacks based on a malicious PIN pad logging the PIN code, then feigning a chip error and telling the user to fall back to the magstrip, thus turning to traditional skimming.
I haven't read anything that attacks the chip itself on current cards. Do you have any links?
edit2: Wikipedia TL;DR: There are two currently-relevant attacks:
* One lets attackers trick a terminal into initiating a PINless transaction in order to use a stolen card. This information is sent to the issues as part of the authentication, so a bank could deny all PINless chip charges if they wished (I'm not sure what cases this legitimately used in?), plus there's a clear trail that the cardholder isn't liable.
* The latest attack tricks the card into downgrading to an older, plaintext method of transferring the PIN from the terminal to the card, allowing the PIN to be skimmed. I'm not sure how this is useful in recreating the card to steal money.
There's some evidence that the first attack was used in the wild, but the banks deleted the logs showing whether a PINless transaction took place so the customers were found liable for the charges.
* Some banks cards were vulnerable due to faulty crypto. The banks phased those cards out.
* Attacks based on a malicious PIN pad logging the PIN code, then feigning a chip error and telling the user to fall back to the magstrip, thus turning to traditional skimming.
I haven't read anything that attacks the chip itself on current cards. Do you have any links?
edit; Just found http://en.wikipedia.org/wiki/EMV#Vulnerabilities
edit2: Wikipedia TL;DR: There are two currently-relevant attacks:
* One lets attackers trick a terminal into initiating a PINless transaction in order to use a stolen card. This information is sent to the issues as part of the authentication, so a bank could deny all PINless chip charges if they wished (I'm not sure what cases this legitimately used in?), plus there's a clear trail that the cardholder isn't liable.
* The latest attack tricks the card into downgrading to an older, plaintext method of transferring the PIN from the terminal to the card, allowing the PIN to be skimmed. I'm not sure how this is useful in recreating the card to steal money.