Live data from Hacker News

'Shimmers' are the newest tool for stealing credit card info

cbc.ca

71–80 of 88 posts

Re: 'Shimmers' are the newest tool for stealing credit card info

#71

I haven't actually physically inserted my card into a machine for at least 2 years now. It's contactless everywhere. If the transaction is more than ~$50 it just asks for my pin and that's it. Maybe we should just introduce this everywhere and then see how criminals can possibly break it?

I'm assuming you're not in the US? I used to have contactless cards on all my accounts until they started rolling out chip cards, at which point they sent me replacements with chips but no contactless functionality. I've considered calling the issuers to see if they can still get me one, but I dread the thought of trying to explain the difference between a chip card and a contactless card - it was hard enough the first time before chip cards became a thing!

Re: 'Shimmers' are the newest tool for stealing credit card info

#72
post #66

Earlier quoted context omitted.

IMO it's super dumb that we're going through the whole business of replacing card readers to get chip support but NOT getting pin requirements. I've had a few CCs stolen from my mailbox (apartment with a large shared mailbox with simple padlocks). The new chip-only doesn't protect against this at all. MasterCard SecureCode was also a step in the right direction IMO, but the adoption rate seems very low. Basically, I…

How were thieves able to activate cards stolen from your mail box?

My current bank considers a purchase using a PIN to be sufficient for automatic instant activation of the card. I was surprised given my previous bank required a phone call to confirm my identity. I guess the policy varies from bank to bank.

Re: 'Shimmers' are the newest tool for stealing credit card info

#73

> "Businesses really need to be checking for these kinds of devices and consumers need to be aware of them." Disagree. Consumers and businesses (ultimately) pay the interchange fees, and this class of problem is the domain of payment infrastructure providers. I'm not interested in keeping vigilant against the latest exploit, and unless the responsibility for dealing with the problem lies with credit card networks and…

What is a good way for a consumer to validate the physical integrity of a box in an essentially unsecured environment?

Re: 'Shimmers' are the newest tool for stealing credit card info

#74
post #5

Earlier quoted context omitted.

Not all terminals in the States support chip functionality, so for the time being chip & pin cards here still have normal mag strips and can be run as older, regular cards - the mag strips can still be read/stolen & used.

IMO it's super dumb that we're going through the whole business of replacing card readers to get chip support but NOT getting pin requirements. I've had a few CCs stolen from my mailbox (apartment with a large shared mailbox with simple padlocks). The new chip-only doesn't protect against this at all. MasterCard SecureCode was also a step in the right direction IMO, but the adoption rate seems very low. Basically, I…

Merchant groups actually advocated chip+pin over chip+signature...

(though mostly because they don't want credit card payments to be easier than debit or cash).

Re: 'Shimmers' are the newest tool for stealing credit card info

#75
post #49

Earlier quoted context omitted.

> the chip used to contain all the information present on the magstripe Not all of it - the chip has a dynamic CVV that differs from the one on the magstripe. This only works if the bank isn't checking CVVs.

> This only works if the bank isn't checking CVVs. Source please? Because if you're right, my bank lied to me when they said they couldn't see whether I paid by chip or by magstripe.

They have to know for fraud investigation. I believe it's also why many companies can't upgrade: they need a new POS that can log the transaction as stripe, chip or NFC/Apple aPay

Re: 'Shimmers' are the newest tool for stealing credit card info

#76
post #20

Unlike skimmers, a shimmer — named for its slim profile — fits inside a card reader... So shouldn't it be called a sLimmer?

Slimming sheds pounds, this accumulates them.

When can we expect NLP to "get" this?

Re: 'Shimmers' are the newest tool for stealing credit card info

#77
post #6

Krebs has a post on this as well: https://krebsonsecurity.com/2017/01/atm-shimmers-target-chip... “The only way for this attack to be successful is if a [bank card] issuer neglects to check the CVV when authorizing a transaction,”

I have not had the largest confidence in banks abilities to understand security. I've personally dealt with: 1) 'Two factor auth is on, you have to answer two security questions to access your account!' 2) 'Your password is limited to exactly 8 characters ... for security' 3) 'Oh, we now support SMS two factor auth' -- 4 months in, I've received 1 SMS challenge 4) 'You don't want a chip card, they are more hassle' 5)…

Ugh! This is my pet peeve. My brokerage house will reset your password (which is fine) and convert your account back to single factor authentication (which is... WTF?!) if you answer the security questions over the phone. What was the point of getting that stupid fob when any idiot can bypass it if he knows my mother's maiden name?

Re: 'Shimmers' are the newest tool for stealing credit card info

#78

So at some level there is an issue with the "inside" aspect of card readers. If you had four guide posts and you just pressed your card against the pogo pins would it make it harder to interpose?

Agreed, this type of device could be easy to detect with some simple upgrades to the card readers. However, the cost of upgrading card reader hardware at all vulnerable banks and retailers is unlikely to be small.

Re: 'Shimmers' are the newest tool for stealing credit card info

#79

I haven't actually physically inserted my card into a machine for at least 2 years now. It's contactless everywhere. If the transaction is more than ~$50 it just asks for my pin and that's it. Maybe we should just introduce this everywhere and then see how criminals can possibly break it?

Contactless is even less secure than chip and pin. You can literally read card details out of someone's wallet without them having any way to tell. Even if someone uses a wallet that guards against this sort of attack, they're still vulnerable at the point of use.

http://youtu.be/x3S_6EJCjn0

http://youtu.be/vmajlKJlT3U

Re: 'Shimmers' are the newest tool for stealing credit card info

#80

I haven't actually physically inserted my card into a machine for at least 2 years now. It's contactless everywhere. If the transaction is more than ~$50 it just asks for my pin and that's it. Maybe we should just introduce this everywhere and then see how criminals can possibly break it?

Contactless is even less secure than chip and pin. You can literally read card details out of someone's wallet without them having any way to tell. Even if someone uses a wallet that guards against this sort of attack, they're still vulnerable at the point of use. http://youtu.be/x3S_6EJCjn0 http://youtu.be/vmajlKJlT3U

That's RFID. Yeah, you can read that with a $5 reader off ebay.

I'm talking about Visa PayWave/Mastercard PayPass - both work through NFC and won't surrender any data to a normal reader, you need an authorized terminal that can give an authorization key valid for a given time. There were some attacks against it, but you can't just swipe a card through a wallet, it's extremely time sensitive and requires access to a valid terminal.

Post reply on HN