If a customer has direct secure input and output communication paths, he can safely communicate with his smart card and achieve safe POS applications. However, safe communications are possible over indirect, untrusted paths if the customer has a shared secret with the smart card, such as a one-time pad. Below we establish a set of equivalences and implications for various types of customer/smart card communication.