Earlier quoted context omitted.
Yes, he has quite a resume there. However, maybe I'm just older, but my ideal polymath is not just coding/hacking electronics. I personally think it should be those plus knowing more diverse fields and skills such as: applied mathematics, celestial navigation, biohacking, chemistry, milling/lathe work, building machinery from scratch by smelting and casting [1], animatronics, boatbuilding, horology, mechatronics, mus…
Do you have any examples of someone that would fit this description? I think a modern polymath could look a bit different than the ones in the classical sense. To be able to make contributions to the fields you mentioned, I guess you would need more years of study than anyone could dedicate to, just because those fields seem to be very hard, especially considering the degree at which nowadays we would consider someon…
MagSpoof – wireless credit card/magstripe spoofer
81–90 of 115 posts
Re: MagSpoof – wireless credit card/magstripe spoofer
#82This is how Samsung Pay works, right? edit: And LoopPay which I guess Samsung acquired.
Yes. And Samsung is really in a panic right now since the chip & pin rollout is going to effectively nullify their investment. Initially they can just strip the "require pin" flag from the magstripe, but eventually opt-out won't be supported. So Samsung is investing massively into Samsung Pay adverts and promotions in order to get people using it, with the hope that once this functionality breaks that people will con…
Re: MagSpoof – wireless credit card/magstripe spoofer
#83Earlier quoted context omitted.
It's pretty much the same as what's being described in the article. Samsung calls it Magnetic Secure Transmission (MST): http://www.samsung.com/us/support/answer/ANS00043865/9974103...
> Magnetic Secure Transmission They dare to call this secure...
Re: MagSpoof – wireless credit card/magstripe spoofer
#84Re: MagSpoof – wireless credit card/magstripe spoofer
#85Earlier quoted context omitted.
Do you have any examples of someone that would fit this description? I think a modern polymath could look a bit different than the ones in the classical sense. To be able to make contributions to the fields you mentioned, I guess you would need more years of study than anyone could dedicate to, just because those fields seem to be very hard, especially considering the degree at which nowadays we would consider someon…
Archimedes, Da Vinci, I. Newton are just a few that came to mind.
Re: MagSpoof – wireless credit card/magstripe spoofer
#86Earlier quoted context omitted.
Yeah, until a man gains easy access to 17-year-old girls' housing, then everyone will flip out. I mean, it's one thing to break stuff to get in, or conspicuously pick a lock, it's another to casually slide a card like everyone else and leave no trail other than maybe video surveillance or access logs showing the same card being used at two ends of campus faster than possible (which nobody will check until something b…
it's another to casually slide a card like everyone else How about to casually insert a duplicated key like everyone else?
My point is that being able to trivially hijack arbitrary identities without even knowing the person let alone physically finding them, is not "good enough." It'd be like if you could make arbitrary car keys with just a VIN, and the VIN is displayed prominently, it would be silly to say "Well now, it keeps honest people honest, so it's good enough."
Re: MagSpoof – wireless credit card/magstripe spoofer
#87Earlier quoted context omitted.
Do you have any examples of someone that would fit this description? I think a modern polymath could look a bit different than the ones in the classical sense. To be able to make contributions to the fields you mentioned, I guess you would need more years of study than anyone could dedicate to, just because those fields seem to be very hard, especially considering the degree at which nowadays we would consider someon…
Archimedes, Da Vinci, I. Newton are just a few that came to mind.
Re: MagSpoof – wireless credit card/magstripe spoofer
#88Earlier quoted context omitted.
I got a replacement Amex card (after some fraudulent charges) 4 or 5 months ago, and it had an all new number, not just a few digits. This card also had the embedded chip, so that may be why it had the new number.
The chip is being rolled out to keep up with VISA/Mastercard's deployment of chip. Note however that chip transactions are far slower than proximity or magstripe uses, making it completely redundant except for a malfunctioning magstripe reader. It would have been as much software update to have implemented PIN and would've brought security to the level of ATM cards. The generation and provisioning of card numbers is…
Re: MagSpoof – wireless credit card/magstripe spoofer
#89I recall people demonstrating something similar this with passports at defcon some years back from quite the distance. Picking up credit card data and ids wirelessly is definitely not new. This is why I use small magnetic / RFID blocking case while traveling.
Re: MagSpoof – wireless credit card/magstripe spoofer
#90Earlier quoted context omitted.
The problem of tricking the reader will be solved in the US the same way the rest of the world solved the problem. You stop using magnetic stripes. For the longest time, chip-and-pin readers in most european countries would let you just swipe the magnetic card if you didn't have a chip.. this allowed americans (and whoever else still uses this technology) to be able to shop when they travel. Unfortunately a dispropor…
I can't claim to spend a ton of time in a huge variety of countries, but in the past year I've been to Iceland, England, Wales, Scotland, Italy, France, and New Zealand, and I can't remember anywhere I had to use the EMV chip in my credit cards except places like parking garages that didn't have the physical facility for a mag stripe swipe. Every retailer terminal could read a magstripe. More annoyingly, whether I sw…
As a UK resident with a UK card it's been a long time since I swiped or signed. I think you must have the "require signature always" bit set on your cards because someone in the issuing chain doesn't trust EMV.