Earlier quoted context omitted.
In the UK (and most of Europe afaik) the card is ejected immediately before the cash; the ejecting of the card indicates your authenticated session has ended.
There are some in the U.S. that do this, but it still didn't stop my friend from leaving his card in the ATM and having to go through a process with the bank and wait for a new card to show. Better to just make sure you have it by stopping you from doing anything else until you have it imo.
Swiping left on magnetic stripes
321–325 of 325 posts
Re: Swiping left on magnetic stripes
#322Earlier quoted context omitted.
You're correct that you can't easily clone an NFC card from RF interactions alone, but beyond that just about every other aspect of these cards is worse. Most contactless cards can be asked to transmit the cardholder's name, credit card number, and expiration date, and the card will happily do so, wirelessly. This is often enough to make fraudulent online transactions. It's trivially easy to build a device that does…
> You can't clone a NFC card from RF alone You imply that it is possible to clone NFC cards with other means. Is that really possible? Crypto chips are usually hardened against all kinds of attacks, and I would assume that NFC cards are resistant to cloning even if you have physical access to the chip. I'd be curious to learn more about that if my assumption is incorrect. Regarding replay attacks, do you have a sourc…
I mean, sure, it's always possible, but probing a secure microcontroller with needles and an electron microscope isn't really what I meant.
I was referring to what the various mobile wallet applications do behind the scenes when they allow you to "import" a plastic card and then use it as a contactless payment source via your phone's NFC radio. They're not actually cloning the private key inside the card, they're using various banking APIs to ask for a new key that, for all intents and purposes, will act exactly like the key on the physical card.
They're supposed to ask for extra info so that they're super ultra sure the person importing the card is the legitimate cardholder, but this is not always very thorough. What kind of info do they typically ask for? Numbers printed on the card that you can acquire wirelessly by accidentally bumping into someone. If you're lucky, they'll try to do two-factor via SMS or email with information that they have on file, but I've seen some that don't bother.
> Regarding replay attacks, do you have a source on that? I would assume that even offline POS terminals would use a nonce to prevent replay attacks. Is that assumption incorrect?
I worked on an EMV contact + contactless implementation several years ago, and at the time contactless replay attacks were easy to demonstrate. Things may have improved since then, but the protocol was not very good (supposedly due to constraints from early NFC cards that were small and anemic), and I think they would need to redo most of it and kill backwards compatibility to mitigate the risk completely.
https://www.youtube.com/watch?v=e023wGfVaE0
https://www.cs.bham.ac.uk/~tpc/Relay/
https://www.hackster.io/news/this-tiny-10-device-can-perform...
https://link.springer.com/chapter/10.1007/978-3-319-39814-3_...
https://en.wikipedia.org/wiki/Contactless_payment#Security
From what I can tell, there was a lot of discourse around these problems around 2015-2018. There were demonstrations and exploits galore. But the standards were already out and none of the banks or card issuers wanted to change anything. Security researchers got bored and moved on. I don't see any evidence that replay and relay attack vectors have been fixed, or that they aren't exploited in the wild, just that the banks seem to consider the risk acceptable.
> And finally, you can extract card holder name and card number from most cards just by looking at them. Claiming that NFC cards are somehow worse than mag stripe cards in that regard is just FUD.
So you'll let me rifle through your wallet and write down the card numbers and expiration dates? Would the average person let me do this? Of course they wouldn't, because basically everybody knows that they need to prevent random people from seeing the various numbers printed on their payment cards.
Is the average person aware that I can capture these markings by "accidentally" bumping into their back pocket on the subway?
It's not FUD, it's a (subtly?) different issue, one that the public largely doesn't understand yet.
What's frustrating about contactless cards is that there isn't even a good solution once you do understand the problem. Metal shields sewn into your wallet only hide the problem. The card will still respond if you shoot enough energy at it, and you'll still be able to pick up the response if you have a sensitive enough receiver.
Re: Swiping left on magnetic stripes
#323Earlier quoted context omitted.
The USA is a big holdup. I just traveled across the country and there are still filling (petrol) stations where the only card reader is stripe. See also other comments about the stripe being a fallback for chip as chip readers on POS terminals seem to be more fragile than magnetic stripe readers. FWIW, Contactless is very hit-or-miss for me in the US; about 1/3 the time it just doesn't work at all (even with multiple…
Not just US. Take for example Germany, the largest country in EU and most places are cash-only. Although due to coronavirus adoption of different payment methods (apple pay, contactless, card, etc) has been increasing.
Re: Swiping left on magnetic stripes
#324Earlier quoted context omitted.
Define extensively. Anybody who pays with checks in situations where credit cards or cash can be used is gonna get funny looks, unless they’re a little old lady.
The difference is that in Australia literally zero retail businesses will ever accept a cheque under any circumstance and all government payments are made using electronic transfers. I haven't been issued a cheque book from my bank in over decade and I've maybe cashed 3 in my 30+ years alive. I actually can't think of a single place outside of a bank where you can use a cheque and even then it's a challenge to actual…
Alas, I’m not sure which tubes you’re referring to. These days, banks use FTP to shuffle bank transfers around.
However, I do think checks have their uses. I’d rather write a check than use cash any day of the week. You can cancel a check, but you can’t cancel cash. Of course, I’d rather pay digitally. But sometimes that’s not an option.
Also: “cashing” a check usually just mean depositing it into your bank account. Not swapping it for cash, although you can do that, too.
Re: Swiping left on magnetic stripes
#325I'd prefer we just phase out MasterCard. I went to a restaurant the other day. QR code on the receipt. Scan that and it opens up Toast. Toast then connects to Apple Pay, which then connects to my credit card. No less than 3 middlemen to pay the restaurant, is absurd. QRCode -> Wallet on my phone holding stablecoin on a L2 like polygon (which is collecting APY through DeFi) -> Restaurant