Live data from Hacker News

MagSpoof – wireless credit card/magstripe spoofer

github.com

101–110 of 115 posts

Re: MagSpoof – wireless credit card/magstripe spoofer

#101

One day in the future, Samy (the creator of this) will stop being the coolest person on the internet, but today isn't that day. Previous projects include: The Samy MySpace worm: https://en.wikipedia.org/wiki/Samy_%28computer_worm%29 EverCookies: http://samy.pl/evercookie/ SkyJack: https://en.wikipedia.org/wiki/SkyJack And so much more... http://samy.pl/ https://en.wikipedia.org/wiki/Samy_Kamkar

SkyJack is a drone engineered to autonomously seek out, hack, and wirelessly take over other drones within wifi distance, creating an army of zombie drones under your control. ...and then: No authentication or encryption is used by the Parrot to secure the connection with the pilot. Well, there's your problem!

It's actually just a wireless network that you connect to and send commands to the Parrot. It makes it really easy to control it from your laptop. There is a library for it that makes it possible to be up and running in under 5 minutes.

Library: https://github.com/felixge/node-ar-drone

Re: MagSpoof – wireless credit card/magstripe spoofer

#102

Earlier quoted context omitted.

When I was in school our student IDs were our social security numbers and encoded directly on our ID cards. Grades were left in folders outside the department office with our full SSNs on them. You could easily take someone else's grades, encode their SSN onto a card, and spend their money.

I'm pretty sure that, aside from the magstripe security issue, that practice (grades left in public identified by SSNs and/or student ID #s) has been a FERPA violation forever. Or since the 1970s, at least.

The law changed in the early 2000's. About a year after I discovered this they changed the ID numbers on the grades to the last 4 digits and shortly after that they moved away from SSNs.

Re: MagSpoof – wireless credit card/magstripe spoofer

#103

I was very surprised to learn there's no check for Chip and Pin requirements beyond what the magstripe requests. I naively assumed if the card had that feature the terminal could force it to be used. What would happen with the other fields he mentions, like whether or not you can withdraw cash with the card?

This would only be an issue for those that don't authorize with the issuer immediately when the card is read. The issuer would know the service code read by the pin pad and should be able to determine that it is incorrect based on the PAN read by the pin pad and the fact that the merchant is certified to support EMV. They could choose to decline the authorization at that point. Most payment processors that I'm aware of in the US do this.

Re: MagSpoof – wireless credit card/magstripe spoofer

#104
post #92
post #90

Earlier quoted context omitted.

You're a US resident with a US card? As a UK resident with a UK card it's been a long time since I swiped or signed. I think you must have the "require signature always" bit set on your cards because someone in the issuing chain doesn't trust EMV.

IIRC, US uses chip and signature 99% of the time, not chip and pin. I don't think I have a single card that supports pin.

You're correct. From my understanding, most issuers have determined that Chip and Signature is secure enough for the US market provided they support DDA. Both of my EMV cards do not even provide a way to create a PIN for them. It will most like be this way for a year or two.

Re: MagSpoof – wireless credit card/magstripe spoofer

#105

Earlier quoted context omitted.

I'm pretty sure that, aside from the magstripe security issue, that practice (grades left in public identified by SSNs and/or student ID #s) has been a FERPA violation forever. Or since the 1970s, at least.

The law changed in the early 2000's. About a year after I discovered this they changed the ID numbers on the grades to the last 4 digits and shortly after that they moved away from SSNs.

No, there was no change in FERPA In the early 2000s, except changes in 2000 and 2001 to add additional allowed disclosures (the 2001 changes were party of the USA PATRIOT Act.)

Now, lots of places in the 1970s and 1980s, and some into the 1990s and 2000s, may have been engaging in the practice of posting grades by SSN or student ID #, even though posting by either had long been explicitly prohibited by FERPA regulations.

What did happen in 2001 that may be relevant to awareness of the rule is the publication of a finding in response to a complaint for posting with the last 4 digits of the SSN.

http://www2.ed.gov/policy/gen/guid/fpco/ferpa/library/hunter...

Re: MagSpoof – wireless credit card/magstripe spoofer

#106

Earlier quoted context omitted.

The chip is being rolled out to keep up with VISA/Mastercard's deployment of chip. Note however that chip transactions are far slower than proximity or magstripe uses, making it completely redundant except for a malfunctioning magstripe reader. It would have been as much software update to have implemented PIN and would've brought security to the level of ATM cards. The generation and provisioning of card numbers is…

Most places where you can use a credit card in Europe require you to use the chip (usually with a PIN).

I wouldn't say "most places" -- after a recent trip to Europe (Ireland, England and France), the only place we couldn't use our "signature-only" card was a train ticket vending machine, every business we went to had a magnetic stripe reader and knew they had to use it when the card had no chip. (my wife's no-foreign-transaction-fee card had no chip, so we tried to use that one as much as possible)

In every case were I used a USA chip card (with no PIN), the card reader prompted for a signature, so it was no problem.

Though I really don't understand why USA issuers and merchants went with a chip-only system, seems like it would have been trivial to allow PIN too.

Though even Chip and PIN only fights a small portion of the fraud - every time I've experienced credit card fraud, it's been with internet purchases. Amex used to let me generate a temporary card number for each merchant, I used that all the time, but they dropped the service for some reason.

Re: MagSpoof – wireless credit card/magstripe spoofer

#107
post #81
post #71

Earlier quoted context omitted.

Do you have any examples of someone that would fit this description? I think a modern polymath could look a bit different than the ones in the classical sense. To be able to make contributions to the fields you mentioned, I guess you would need more years of study than anyone could dedicate to, just because those fields seem to be very hard, especially considering the degree at which nowadays we would consider someon…

Archimedes, Da Vinci, I. Newton are just a few that came to mind.

That's why I said modern polymaths.

Most people always think of the usual guys when talking about polymaths, and it seems like modern ones are never mentioned.

Re: MagSpoof – wireless credit card/magstripe spoofer

#108
post #80
post #40

Hmm, I'm very surprised that magstripe readers don't have sensors that detect physical presence of a card, even to this date. But regardless, the main point for me was how trivially one could downgrade the security by setting the bit about Chip/PIN capability off.

I'm surprised magstripe readers still exist. I don't think I've used one in years. They are often there.. but I don't see their purpose. Last non-chip card I've seen was maybe 12 years ago.

You're obviously not in America, then. Out of the 6 cards in my wallet only 2 even have a chip yet (my bank promises my most frequently used card has a chip equivalent in the mail).

Re: MagSpoof – wireless credit card/magstripe spoofer

#109
post #6

This is how Samsung Pay works, right? edit: And LoopPay which I guess Samsung acquired.

Yes. And Samsung is really in a panic right now since the chip & pin rollout is going to effectively nullify their investment. Initially they can just strip the "require pin" flag from the magstripe, but eventually opt-out won't be supported. So Samsung is investing massively into Samsung Pay adverts and promotions in order to get people using it, with the hope that once this functionality breaks that people will con…

Samsung worked directly with the banks to deploy a tokenization scheme via the magnetic card swipe system so it would be EMV equivalent. It's not sending your actual card number, but a virtual card number provided by the bank that doesn't have the 'chip required' bit.

Re: MagSpoof – wireless credit card/magstripe spoofer

#110
It mentions "disabling chip and pin", meaning it will convert the sentinel character on the magnetic stripe which tells the terminal that it is a chip card. By disabling the sentinel character and using this on a chip enabled terminal, the financial institute (BASE24) SHOULD decline the transaction because the Track 2 data will be incorrect.

Edit: I meant on an EMV compliant terminal.

Edit: Also, that is considered fraud and your best not testing it, unless you like the prison environment.

Post reply on HN