Earlier quoted context omitted.
When I was in school our student IDs were our social security numbers and encoded directly on our ID cards. Grades were left in folders outside the department office with our full SSNs on them. You could easily take someone else's grades, encode their SSN onto a card, and spend their money.
I'm pretty sure that, aside from the magstripe security issue, that practice (grades left in public identified by SSNs and/or student ID #s) has been a FERPA violation forever. Or since the 1970s, at least.
MagSpoof – wireless credit card/magstripe spoofer
61–70 of 115 posts
Re: MagSpoof – wireless credit card/magstripe spoofer
#62There's more gems in there, e.g. a couple of Amex vulnerabilities: https://github.com/samyk/magspoof#american-express-card-numb... > I found a global pattern that allows me to accurately predict American Express card numbers by knowing a full card number, even if already reported lost or stolen. > This means if I were to obtain your Amex card and you called it in as lost or stolen, the moment you get a new card, I kn…
I got a replacement Amex card (after some fraudulent charges) 4 or 5 months ago, and it had an all new number, not just a few digits. This card also had the embedded chip, so that may be why it had the new number.
It would have been as much software update to have implemented PIN and would've brought security to the level of ATM cards.
The generation and provisioning of card numbers is limited by other systems which includes fraud detection, account processing, auditing and other backend systems.
Re: MagSpoof – wireless credit card/magstripe spoofer
#63Earlier quoted context omitted.
It could have been "good enough". Remember the whole "keeps an honest man honest" bit. Retooling their security system might cost a lot more than some spoofed meals, and we all know doors & tumbler locks are never impervious.
Yeah, until a man gains easy access to 17-year-old girls' housing, then everyone will flip out. I mean, it's one thing to break stuff to get in, or conspicuously pick a lock, it's another to casually slide a card like everyone else and leave no trail other than maybe video surveillance or access logs showing the same card being used at two ends of campus faster than possible (which nobody will check until something b…
How about to casually insert a duplicated key like everyone else?
Re: MagSpoof – wireless credit card/magstripe spoofer
#64Re: MagSpoof – wireless credit card/magstripe spoofer
#65One day in the future, Samy (the creator of this) will stop being the coolest person on the internet, but today isn't that day. Previous projects include: The Samy MySpace worm: https://en.wikipedia.org/wiki/Samy_%28computer_worm%29 EverCookies: http://samy.pl/evercookie/ SkyJack: https://en.wikipedia.org/wiki/SkyJack And so much more... http://samy.pl/ https://en.wikipedia.org/wiki/Samy_Kamkar
Re: MagSpoof – wireless credit card/magstripe spoofer
#66Re: MagSpoof – wireless credit card/magstripe spoofer
#67This is how Samsung Pay works, right? edit: And LoopPay which I guess Samsung acquired.
Yes. And Samsung is really in a panic right now since the chip & pin rollout is going to effectively nullify their investment. Initially they can just strip the "require pin" flag from the magstripe, but eventually opt-out won't be supported. So Samsung is investing massively into Samsung Pay adverts and promotions in order to get people using it, with the hope that once this functionality breaks that people will con…
Re: MagSpoof – wireless credit card/magstripe spoofer
#68Re: MagSpoof – wireless credit card/magstripe spoofer
#69of credit, whatsapp, facebook, clearing of criminal
records, contact the hack guru demon_teco@gmx.com . we
also track cheating spouses, locations, messages, call
records and all forms of hacking demon_teco@gmx.com
Re: MagSpoof – wireless credit card/magstripe spoofer
#70Earlier quoted context omitted.
The terminal has no method to determine if the card is Chip and Pin enabled aside from the magstripe. Sure it could check for the actual chip, but credit card fraudsters aren't creating fake cards that include the chip so that wouldn't help either. I would argue the way they should implement it is such that the bank itself rejects the transaction if it knows the card is chip enabled and the terminal is as well.
I always assumed that chip/pin being used was at least checked by the credit card company. The machine should be telling them if it supports chip/pin, and the cc company independently knows all the information about your card, so... urrrrgh.
(for example, the EMV standard explicitly handles various failure modes like "PIN-pad is broken", "card holder does not remember PIN" and so on, and allows configurations that accept such transactions)