Credit card security is comically poor. Off the top of my head: 1. An NFC-enabled EMV card will happily reveal its entire account number and expiration date over NFC with no authentication whatsoever. I don’t know whether the CVV comes along, but I wouldn’t be surprised if it did. 2. (As mentioned in the article) issuers accept transactions from EMV (chip)-capable readers that nominally originate from EMV-capable car…
> [...] found a global pattern that allows me to accurately predict American Express card numbers by knowing a full card number, even if already reported lost or stolen. > This means if I were to obtain your Amex card and you called it in as lost or stolen, the moment you get a new card, I know your new credit card number. Criminally hilarious.
MagSpoof: Wireless Magstrip Spoofer
21–30 of 105 posts
Re: MagSpoof: Wireless Magstrip Spoofer
#22The american reliance on magstrips is crazy. Over here(Poland) I don't think I've seen a magstrip-compatible terminal for years, they just don't have the swipe part anymore, it's been removed from terminals and cash registers ages ago.
I have McDonald's gift cards in Canada, and I use the swipe for that.
Re: MagSpoof: Wireless Magstrip Spoofer
#23Although you can disable the bits in the service code pertaining to the cards ICC capabilities, in theory there's a good chance that the track2 equivalent data on the chip is different from the track2 data on the magstrip. That would make it easy for the issuer to determine that the track2 has been modified and reject the transaction and/or flag the account for fraudulent activity.
Re: MagSpoof: Wireless Magstrip Spoofer
#24Credit card security is comically poor. Off the top of my head: 1. An NFC-enabled EMV card will happily reveal its entire account number and expiration date over NFC with no authentication whatsoever. I don’t know whether the CVV comes along, but I wouldn’t be surprised if it did. 2. (As mentioned in the article) issuers accept transactions from EMV (chip)-capable readers that nominally originate from EMV-capable car…
> 2. (As mentioned in the article) issuers accept transactions from EMV (chip)-capable readers that nominally originate from EMV-capable cards without requiring the chip to be used. So what’s the point of the chip? (Note that this allows a card to be cloned without even touching the card - see #1.) I would think the issuer could refuse the transaction higher up in the process, but it's faster and fewer packets going…
(It’s also not fewer packets. Although it does require the backend to know whether the card reader can read a chip, and I don’t know whether the reader reports this as part of the transaction. OTOH there are rather severe penalties assessed on merchants with non-chip-capable readers, so something up the stack has at least some idea.)
Re: MagSpoof: Wireless Magstrip Spoofer
#25The american reliance on magstrips is crazy. Over here(Poland) I don't think I've seen a magstrip-compatible terminal for years, they just don't have the swipe part anymore, it's been removed from terminals and cash registers ages ago.
Are gift cards not a thing in Poland? How do they work? I have McDonald's gift cards in Canada, and I use the swipe for that.
Re: MagSpoof: Wireless Magstrip Spoofer
#26I long for the day I can carry my phone or watch without needing keys or wallet. The fact that most adults carry at least 3 things (keys/phone/wallet) at all times in 2022 is crazy.
Re: MagSpoof: Wireless Magstrip Spoofer
#27I long for the day I can carry my phone or watch without needing keys or wallet. The fact that most adults carry at least 3 things (keys/phone/wallet) at all times in 2022 is crazy.
Re: MagSpoof: Wireless Magstrip Spoofer
#28Credit card security is comically poor. Off the top of my head: 1. An NFC-enabled EMV card will happily reveal its entire account number and expiration date over NFC with no authentication whatsoever. I don’t know whether the CVV comes along, but I wouldn’t be surprised if it did. 2. (As mentioned in the article) issuers accept transactions from EMV (chip)-capable readers that nominally originate from EMV-capable car…
>>3. The information leaked in #1 is enough to buy things online (as long as the CVV2 can be found or guessed). Wtf? At least in EU you can't do that anymore - all online transactions are required to implement 3D secure so you have to confirm the transaction some other way in addition to your card details.
Re: MagSpoof: Wireless Magstrip Spoofer
#29Although you can disable the bits in the service code pertaining to the cards ICC capabilities, in theory there's a good chance that the track2 equivalent data on the chip is different from the track2 data on the magstrip. That would make it easy for the issuer to determine that the track2 has been modified and reject the transaction and/or flag the account for fraudulent activity.
Yeah, whenever I try to swipe my card, it instantly tells me to use Chip and PIN. I think it's just to provide rapid localized responses, but who knows if some banks are misconfigured and overly trusted the magstripe data to block magstripe transactions.
Re: MagSpoof: Wireless Magstrip Spoofer
#30The american reliance on magstrips is crazy. Over here(Poland) I don't think I've seen a magstrip-compatible terminal for years, they just don't have the swipe part anymore, it's been removed from terminals and cash registers ages ago.
Are gift cards not a thing in Poland? How do they work? I have McDonald's gift cards in Canada, and I use the swipe for that.