Plus, you (as a consumer) are only liable for up to $50 of fraudulent charges in the US (it's higher if you are slow to report). But most credit card companies don't make you pay anything when fraud happens.
So until the Target hack happened, there wasn't any motivation for anyone in the payment stack (from consumers to card networks) to move to different tech.