A group of researchers has found a significant flaw in the chip-and-PIN security system used by credit card companies in the UK. The weakness allows an attacker to use a card without the PIN associated with it. In a normal transaction, the cardholder needs to enter a PIN to authenticate himself. But the researchers discovered a way to use the card while entering any PIN, rendering the authentication system useless. Because of the way the system works, the transaction would look completely legitimate to the bank, which would show that the correct PIN was used.
Source: https://threatpost.com/chip-and-pin-security-completely-broken-new-attack-021210/73532/

