One day in the future, Samy (the creator of this) will stop being the coolest person on the internet, but today isn't that day. Previous projects include: The Samy MySpace worm: https://en.wikipedia.org/wiki/Samy_%28computer_worm%29 EverCookies: http://samy.pl/evercookie/ SkyJack: https://en.wikipedia.org/wiki/SkyJack And so much more... http://samy.pl/ https://en.wikipedia.org/wiki/Samy_Kamkar
SkyJack is a drone engineered to autonomously seek out, hack, and wirelessly take over other drones within wifi distance, creating an army of zombie drones under your control. ...and then: No authentication or encryption is used by the Parrot to secure the connection with the pilot. Well, there's your problem!
MagSpoof – wireless credit card/magstripe spoofer
101–110 of 115 posts
Re: MagSpoof – wireless credit card/magstripe spoofer
#102Earlier quoted context omitted.
When I was in school our student IDs were our social security numbers and encoded directly on our ID cards. Grades were left in folders outside the department office with our full SSNs on them. You could easily take someone else's grades, encode their SSN onto a card, and spend their money.
I'm pretty sure that, aside from the magstripe security issue, that practice (grades left in public identified by SSNs and/or student ID #s) has been a FERPA violation forever. Or since the 1970s, at least.
Re: MagSpoof – wireless credit card/magstripe spoofer
#103I was very surprised to learn there's no check for Chip and Pin requirements beyond what the magstripe requests. I naively assumed if the card had that feature the terminal could force it to be used. What would happen with the other fields he mentions, like whether or not you can withdraw cash with the card?
Re: MagSpoof – wireless credit card/magstripe spoofer
#104Earlier quoted context omitted.
You're a US resident with a US card? As a UK resident with a UK card it's been a long time since I swiped or signed. I think you must have the "require signature always" bit set on your cards because someone in the issuing chain doesn't trust EMV.
IIRC, US uses chip and signature 99% of the time, not chip and pin. I don't think I have a single card that supports pin.
Re: MagSpoof – wireless credit card/magstripe spoofer
#105Earlier quoted context omitted.
I'm pretty sure that, aside from the magstripe security issue, that practice (grades left in public identified by SSNs and/or student ID #s) has been a FERPA violation forever. Or since the 1970s, at least.
The law changed in the early 2000's. About a year after I discovered this they changed the ID numbers on the grades to the last 4 digits and shortly after that they moved away from SSNs.
Now, lots of places in the 1970s and 1980s, and some into the 1990s and 2000s, may have been engaging in the practice of posting grades by SSN or student ID #, even though posting by either had long been explicitly prohibited by FERPA regulations.
What did happen in 2001 that may be relevant to awareness of the rule is the publication of a finding in response to a complaint for posting with the last 4 digits of the SSN.
http://www2.ed.gov/policy/gen/guid/fpco/ferpa/library/hunter...
Re: MagSpoof – wireless credit card/magstripe spoofer
#106Earlier quoted context omitted.
The chip is being rolled out to keep up with VISA/Mastercard's deployment of chip. Note however that chip transactions are far slower than proximity or magstripe uses, making it completely redundant except for a malfunctioning magstripe reader. It would have been as much software update to have implemented PIN and would've brought security to the level of ATM cards. The generation and provisioning of card numbers is…
Most places where you can use a credit card in Europe require you to use the chip (usually with a PIN).
In every case were I used a USA chip card (with no PIN), the card reader prompted for a signature, so it was no problem.
Though I really don't understand why USA issuers and merchants went with a chip-only system, seems like it would have been trivial to allow PIN too.
Though even Chip and PIN only fights a small portion of the fraud - every time I've experienced credit card fraud, it's been with internet purchases. Amex used to let me generate a temporary card number for each merchant, I used that all the time, but they dropped the service for some reason.
Re: MagSpoof – wireless credit card/magstripe spoofer
#107Earlier quoted context omitted.
Do you have any examples of someone that would fit this description? I think a modern polymath could look a bit different than the ones in the classical sense. To be able to make contributions to the fields you mentioned, I guess you would need more years of study than anyone could dedicate to, just because those fields seem to be very hard, especially considering the degree at which nowadays we would consider someon…
Archimedes, Da Vinci, I. Newton are just a few that came to mind.
Most people always think of the usual guys when talking about polymaths, and it seems like modern ones are never mentioned.
Re: MagSpoof – wireless credit card/magstripe spoofer
#108Hmm, I'm very surprised that magstripe readers don't have sensors that detect physical presence of a card, even to this date. But regardless, the main point for me was how trivially one could downgrade the security by setting the bit about Chip/PIN capability off.
I'm surprised magstripe readers still exist. I don't think I've used one in years. They are often there.. but I don't see their purpose. Last non-chip card I've seen was maybe 12 years ago.
Re: MagSpoof – wireless credit card/magstripe spoofer
#109This is how Samsung Pay works, right? edit: And LoopPay which I guess Samsung acquired.
Yes. And Samsung is really in a panic right now since the chip & pin rollout is going to effectively nullify their investment. Initially they can just strip the "require pin" flag from the magstripe, but eventually opt-out won't be supported. So Samsung is investing massively into Samsung Pay adverts and promotions in order to get people using it, with the hope that once this functionality breaks that people will con…
Re: MagSpoof – wireless credit card/magstripe spoofer
#110Edit: I meant on an EMV compliant terminal.
Edit: Also, that is considered fraud and your best not testing it, unless you like the prison environment.