Live data from Hacker News

MagSpoof: Wireless Magstrip Spoofer

github.com

21–30 of 105 posts

Re: MagSpoof: Wireless Magstrip Spoofer

#21
post #11

Credit card security is comically poor. Off the top of my head: 1. An NFC-enabled EMV card will happily reveal its entire account number and expiration date over NFC with no authentication whatsoever. I don’t know whether the CVV comes along, but I wouldn’t be surprised if it did. 2. (As mentioned in the article) issuers accept transactions from EMV (chip)-capable readers that nominally originate from EMV-capable car…

> [...] found a global pattern that allows me to accurately predict American Express card numbers by knowing a full card number, even if already reported lost or stolen. > This means if I were to obtain your Amex card and you called it in as lost or stolen, the moment you get a new card, I know your new credit card number. Criminally hilarious.

I suspect this has already been exploited in South America with at least one North American banks' Amex cards. Can't get into too much detail, but the pieces fit.

Re: MagSpoof: Wireless Magstrip Spoofer

#22

The american reliance on magstrips is crazy. Over here(Poland) I don't think I've seen a magstrip-compatible terminal for years, they just don't have the swipe part anymore, it's been removed from terminals and cash registers ages ago.

Are gift cards not a thing in Poland? How do they work?

I have McDonald's gift cards in Canada, and I use the swipe for that.

Re: MagSpoof: Wireless Magstrip Spoofer

#23
post #9

Although you can disable the bits in the service code pertaining to the cards ICC capabilities, in theory there's a good chance that the track2 equivalent data on the chip is different from the track2 data on the magstrip. That would make it easy for the issuer to determine that the track2 has been modified and reject the transaction and/or flag the account for fraudulent activity.

Yeah, whenever I try to swipe my card, it instantly tells me to use Chip and PIN. I think it's just to provide rapid localized responses, but who knows if some banks are misconfigured and overly trusted the magstripe data to block magstripe transactions.

Re: MagSpoof: Wireless Magstrip Spoofer

#24
post #11

Credit card security is comically poor. Off the top of my head: 1. An NFC-enabled EMV card will happily reveal its entire account number and expiration date over NFC with no authentication whatsoever. I don’t know whether the CVV comes along, but I wouldn’t be surprised if it did. 2. (As mentioned in the article) issuers accept transactions from EMV (chip)-capable readers that nominally originate from EMV-capable car…

> 2. (As mentioned in the article) issuers accept transactions from EMV (chip)-capable readers that nominally originate from EMV-capable cards without requiring the chip to be used. So what’s the point of the chip? (Note that this allows a card to be cloned without even touching the card - see #1.) I would think the issuer could refuse the transaction higher up in the process, but it's faster and fewer packets going…

That’s like saying you think a server can reject a wrong password on the backend, but it’s faster and fewer packets going back and forth if the client JavaScript just verified the password before sending POST. This is nuts. At least there’s nothing fundamentally wrong with a card reader also rejecting the transaction.

(It’s also not fewer packets. Although it does require the backend to know whether the card reader can read a chip, and I don’t know whether the reader reports this as part of the transaction. OTOH there are rather severe penalties assessed on merchants with non-chip-capable readers, so something up the stack has at least some idea.)

Re: MagSpoof: Wireless Magstrip Spoofer

#25

The american reliance on magstrips is crazy. Over here(Poland) I don't think I've seen a magstrip-compatible terminal for years, they just don't have the swipe part anymore, it's been removed from terminals and cash registers ages ago.

Are gift cards not a thing in Poland? How do they work? I have McDonald's gift cards in Canada, and I use the swipe for that.

They just have a chip like any other card? I bought a mastercard gift card some time ago and it just came with a pin. In fact I think gift cards don't even have a swipe part at all, and my own visa/mastercard cards still have it but I have it disabled through my online bank account - so I assume any magstrip transaction for those cards would be just rejected entirely.

Re: MagSpoof: Wireless Magstrip Spoofer

#26
post #5

I long for the day I can carry my phone or watch without needing keys or wallet. The fact that most adults carry at least 3 things (keys/phone/wallet) at all times in 2022 is crazy.

That day is closer than you may think. I sometimes only have my phone with me as i can pay using only it (something like Google/Apple pay, but through my bank's app) and can unlock my front door thanks to Home Assistant. Both of those (should, I don't have one) work with a smart watch.

Re: MagSpoof: Wireless Magstrip Spoofer

#27
post #5

I long for the day I can carry my phone or watch without needing keys or wallet. The fact that most adults carry at least 3 things (keys/phone/wallet) at all times in 2022 is crazy.

I’ve been able to do this for about five years over here in the U.K. - and very regularly do.

Re: MagSpoof: Wireless Magstrip Spoofer

#28
post #11

Credit card security is comically poor. Off the top of my head: 1. An NFC-enabled EMV card will happily reveal its entire account number and expiration date over NFC with no authentication whatsoever. I don’t know whether the CVV comes along, but I wouldn’t be surprised if it did. 2. (As mentioned in the article) issuers accept transactions from EMV (chip)-capable readers that nominally originate from EMV-capable car…

>>3. The information leaked in #1 is enough to buy things online (as long as the CVV2 can be found or guessed). Wtf? At least in EU you can't do that anymore - all online transactions are required to implement 3D secure so you have to confirm the transaction some other way in addition to your card details.

It's a legal requirement for EU vendors but the cards themselves (or at least some of them) can still be used without 3DSecure.

Re: MagSpoof: Wireless Magstrip Spoofer

#29
post #9

Although you can disable the bits in the service code pertaining to the cards ICC capabilities, in theory there's a good chance that the track2 equivalent data on the chip is different from the track2 data on the magstrip. That would make it easy for the issuer to determine that the track2 has been modified and reject the transaction and/or flag the account for fraudulent activity.

Yeah, whenever I try to swipe my card, it instantly tells me to use Chip and PIN. I think it's just to provide rapid localized responses, but who knows if some banks are misconfigured and overly trusted the magstripe data to block magstripe transactions.

But that's what's covered in the article. The "block transaction and require chip and PIN" flag is stored on the magtrack itself.

Re: MagSpoof: Wireless Magstrip Spoofer

#30

The american reliance on magstrips is crazy. Over here(Poland) I don't think I've seen a magstrip-compatible terminal for years, they just don't have the swipe part anymore, it's been removed from terminals and cash registers ages ago.

Are gift cards not a thing in Poland? How do they work? I have McDonald's gift cards in Canada, and I use the swipe for that.

All of the gift cards I’ve seen in the EU used barcodes, not mag stripes.
Post reply on HN