PIN numbers are completely irrelevant. Why would typing a static pin number into a hostile terminal gain me any security at all?
Alright first; GREAT post. Cleared things up - nice to see my research was correct.
I disagree with the PIN thing though: It offers some safety:
1. PIN is used and the card is locked 30-90 sec.
2. User removes card and leaves.
3. Merchant secretly stored the PIN.
4. Merchant does not have the card - how will he use his stolen PIN?
5. He has to either A rob the guy or B get the person to come back another time.
6. He can then destroy ALL reputation he had to make 5. happen for maybe 40-200$!
WITHOUT a PIN:
1. Send money request of "ALL YOUR BASE... PLZ".
2. Done.
3. His reputation is still ruined, but it was a lot easier to do the stealing.
(90% of the times you use your card a new place, you will never use it there again - hence you're safe)