Live data from Hacker News

MagSpoof – wireless credit card/magstripe spoofer

github.com

21–30 of 115 posts

Re: MagSpoof – wireless credit card/magstripe spoofer

#21
post #14
post #12

Earlier quoted context omitted.

Samsung Pay's pitch is that it is (mostly) backwards compatible with existing card readers. When NFC fails, it does fallback to magnetic strip emulation.

[deleted]

It's pretty much the same as what's being described in the article. Samsung calls it Magnetic Secure Transmission (MST): http://www.samsung.com/us/support/answer/ANS00043865/9974103...

Re: MagSpoof – wireless credit card/magstripe spoofer

#22
post #14
post #12

Earlier quoted context omitted.

Samsung Pay's pitch is that it is (mostly) backwards compatible with existing card readers. When NFC fails, it does fallback to magnetic strip emulation.

[deleted]

By generating a magnetic field.

Re: MagSpoof – wireless credit card/magstripe spoofer

#23
This is too damn cool to pass up - talk about convenience... I would have been willing to pay for such an item!

Yes everyone is going to run around and scream 'security!!' when they realize how ridiculously trivial this process always has been, but it does not change facts - it has always been this easy, but this is a new way to highlight that fact.

Re: MagSpoof – wireless credit card/magstripe spoofer

#24
post #2

There's more gems in there, e.g. a couple of Amex vulnerabilities: https://github.com/samyk/magspoof#american-express-card-numb... > I found a global pattern that allows me to accurately predict American Express card numbers by knowing a full card number, even if already reported lost or stolen. > This means if I were to obtain your Amex card and you called it in as lost or stolen, the moment you get a new card, I kn…

Someone I know said they had their card cloned and when the CSR went to reissue there were already attempts to use the new number, so it seems like this may have already been known by fraudsters.

Re: MagSpoof – wireless credit card/magstripe spoofer

#25
post #2

There's more gems in there, e.g. a couple of Amex vulnerabilities: https://github.com/samyk/magspoof#american-express-card-numb... > I found a global pattern that allows me to accurately predict American Express card numbers by knowing a full card number, even if already reported lost or stolen. > This means if I were to obtain your Amex card and you called it in as lost or stolen, the moment you get a new card, I kn…

This makes sense. I've had my Amex replaced several times due to detected fraud, and the last digits are always incremented in a predictable pattern.

If it's the same as it was back in the days of Credit Master 4 for DOS, it bumps up by eights and sixteens.

Re: MagSpoof – wireless credit card/magstripe spoofer

#26

Earlier quoted context omitted.

I live in Canada and that's what happens with all of my visa/debit chip cards. If you attempt to swipe your card and it, as well as the terminal, are chip enabled then it gives you an error and asks you to insert your card into the terminal.

That is triggered by the magstripe though. The point here is you can trick the reader by turning off that feature on the magstripe and the reader doesn't do any additional check on whether EMV should be required.

Based upon my knowledge of EMV liability, the merchant would still be clear from fraudulent charges if they had an EMV reader. If the device tells the reader it can't do chip & pin, then the buyer is the least secure part of the transaction.

Re: MagSpoof – wireless credit card/magstripe spoofer

#27

It's stunning how bad many card issuing systems are (as noted in the post, AmEx et al). When I was in college all of the administrative buildings, student common areas as well as many of the student housing areas were controlled by magstripe. Meals were also kept track of by card. I knew from people losing their cards which continued working some places but not others there was a relationship in the issuing. I got a…

It could have been "good enough". Remember the whole "keeps an honest man honest" bit. Retooling their security system might cost a lot more than some spoofed meals, and we all know doors & tumbler locks are never impervious.

Re: MagSpoof – wireless credit card/magstripe spoofer

#28
post #6

This is how Samsung Pay works, right? edit: And LoopPay which I guess Samsung acquired.

Yes. And Samsung is really in a panic right now since the chip & pin rollout is going to effectively nullify their investment. Initially they can just strip the "require pin" flag from the magstripe, but eventually opt-out won't be supported. So Samsung is investing massively into Samsung Pay adverts and promotions in order to get people using it, with the hope that once this functionality breaks that people will con…

Did they ever think chip & pin wouldn't roll out? I took the magstripe emulation as a bridge play, to be the first truly viable mobile payments option in order to take pole position in the coming mobile payments scuffle.

Re: MagSpoof – wireless credit card/magstripe spoofer

#29

I was very surprised to learn there's no check for Chip and Pin requirements beyond what the magstripe requests. I naively assumed if the card had that feature the terminal could force it to be used. What would happen with the other fields he mentions, like whether or not you can withdraw cash with the card?

The terminal has no method to determine if the card is Chip and Pin enabled aside from the magstripe. Sure it could check for the actual chip, but credit card fraudsters aren't creating fake cards that include the chip so that wouldn't help either. I would argue the way they should implement it is such that the bank itself rejects the transaction if it knows the card is chip enabled and the terminal is as well.

> Sure it could check for the actual chip, but credit card fraudsters aren't creating fake cards that include the chip so that wouldn't help either.

Should that read 'credit card fraudsters are creating fake cards that include the chip' ?

Re: MagSpoof – wireless credit card/magstripe spoofer

#30
post #4

I was very surprised to learn there's no check for Chip and Pin requirements beyond what the magstripe requests. I naively assumed if the card had that feature the terminal could force it to be used. What would happen with the other fields he mentions, like whether or not you can withdraw cash with the card?

IIRC from some resarch I did, a decent card provider will reject a magstripe transaction from a terminal with EMV capability if a card is known to also be EMV capable... At least, it could in theory.

Pretty sure this has already happened to me in the USA. Though, I was scattered at the time and don't remember for certain.
Post reply on HN