Live data from Hacker News

MagSpoof: Wireless Magstrip Spoofer

github.com

41–50 of 105 posts

Re: MagSpoof: Wireless Magstrip Spoofer

#41
post #24

Earlier quoted context omitted.

> 2. (As mentioned in the article) issuers accept transactions from EMV (chip)-capable readers that nominally originate from EMV-capable cards without requiring the chip to be used. So what’s the point of the chip? (Note that this allows a card to be cloned without even touching the card - see #1.) I would think the issuer could refuse the transaction higher up in the process, but it's faster and fewer packets going…

That’s like saying you think a server can reject a wrong password on the backend, but it’s faster and fewer packets going back and forth if the client JavaScript just verified the password before sending POST. This is nuts. At least there’s nothing fundamentally wrong with a card reader also rejecting the transaction. (It’s also not fewer packets. Although it does require the backend to know whether the card reader c…

> That’s like saying you think a server can reject a wrong password on the backend, but it’s faster and fewer packets going back and forth if the client JavaScript just verified the password before sending POST. This is nuts.

I don't think it is nuts. The terminal doing the rejection accounts for the "oops the customer did something wrong" case of swiping the card when the issuer wants them to use chip. It's better to tell the customer this now than run an entire transaction.

But checking on the far end that the transaction meets all of the issuers rule accounts for the fraud case of "someone has maliciously rewritten the magnetic stripe data to try to go around the requirement to insert the card." Since, hopefully, this happens far less often than the first case, it is an acceptable path.

Re: MagSpoof: Wireless Magstrip Spoofer

#42

Earlier quoted context omitted.

American here- most retail terminals here support NFC and chip- I haven't used magstrip in a retail environment for years- even mom-and-pop shops support NFC. Most gas stations accept chip, but not many accept NFC yet, though I'm seeing it more and more. Some gas stations still only accept magstrip. We still have the stupid policy in restaurants where you hand your card to the server and they walk away with it (their…

> We still have the stupid policy in restaurants where you hand your card to the server and they walk away with it (their terminals are usually chip), which is something that a lot of foreigners freak out about. And rightfully so! What is stopping them from copying the PAN, expiry date and CVV2? I wouldn't give my card to anyone - that's what portable (wifi/BT) terminals are for.

What stops a server with a good memory from looking at your card as they put it in their terminal and remembering it for the 30 seconds it takes to walk away and note it down? They already reliably remember fairly complicated table orders which have got to have more bits of entropy than a credit card number.

Credit cards handle risk very differently than we do for account passwords. They expect numbers to leak regularly, but the downside of a leak is bounded in a way that password leaks often aren't, and the issuers and merchants eat those losses as a cost of business.

Re: MagSpoof: Wireless Magstrip Spoofer

#44

Earlier quoted context omitted.

Are gift cards not a thing in Poland? How do they work? I have McDonald's gift cards in Canada, and I use the swipe for that.

They just have a chip like any other card? I bought a mastercard gift card some time ago and it just came with a pin. In fact I think gift cards don't even have a swipe part at all, and my own visa/mastercard cards still have it but I have it disabled through my online bank account - so I assume any magstrip transaction for those cards would be just rejected entirely.

They’re talking about store-specific gift cards, not generic visa/Mastercard cards.

Re: MagSpoof: Wireless Magstrip Spoofer

#45
post #11

Credit card security is comically poor. Off the top of my head: 1. An NFC-enabled EMV card will happily reveal its entire account number and expiration date over NFC with no authentication whatsoever. I don’t know whether the CVV comes along, but I wouldn’t be surprised if it did. 2. (As mentioned in the article) issuers accept transactions from EMV (chip)-capable readers that nominally originate from EMV-capable car…

> 2. (As mentioned in the article) issuers accept transactions from EMV (chip)-capable readers that nominally originate from EMV-capable cards without requiring the chip to be used.

Last time I tried swiping my card — and that was ages ago — the terminal displayed something to the effect of "this card has a chip, please insert the chip".

> 3. The information leaked in #1 is enough to buy things online (as long as the CVV2 can be found or guessed). Wtf?

3DSecure is a thing and its job is to prevent this exact situation.

So credit card security is comically poor, but only in the US. You were somehow still using the magstripe until recently and probably still do sometimes at places that didn't upgrade their readers in time.

Re: MagSpoof: Wireless Magstrip Spoofer

#46

Earlier quoted context omitted.

American here- most retail terminals here support NFC and chip- I haven't used magstrip in a retail environment for years- even mom-and-pop shops support NFC. Most gas stations accept chip, but not many accept NFC yet, though I'm seeing it more and more. Some gas stations still only accept magstrip. We still have the stupid policy in restaurants where you hand your card to the server and they walk away with it (their…

> We still have the stupid policy in restaurants where you hand your card to the server and they walk away with it (their terminals are usually chip), which is something that a lot of foreigners freak out about. And rightfully so! What is stopping them from copying the PAN, expiry date and CVV2? I wouldn't give my card to anyone - that's what portable (wifi/BT) terminals are for.

I always scratch away cvv2 code from a card.

Re: MagSpoof: Wireless Magstrip Spoofer

#47
post #39

The american reliance on magstrips is crazy. Over here(Poland) I don't think I've seen a magstrip-compatible terminal for years, they just don't have the swipe part anymore, it's been removed from terminals and cash registers ages ago.

The US market has been historically different for other reasons. The big one is liability. In the US the cardholder is rarely liable for fraud charges. Which is why the minutiae of credit card security mechanisms just kind of doesn’t matter to us. But from my understanding, in Europe and places like India, the cardholder is usually liable. Which also explains why cardholders seem to be a lot more anxious about these…

> in Europe and places like India, the cardholder is usually liable

I suppose it depends on what you mean by "usually" but no, in the EU generally you just go to the police station which has a form for declaring credit card fraud and the bank often reimburses you before receiving it. Your replacement card is free on this situation. It is up to the bank to get their money back if they want to bother.

I don't know of a situation where you wouldn't get reimbursed by your bank.

Re: MagSpoof: Wireless Magstrip Spoofer

#48

The american reliance on magstrips is crazy. Over here(Poland) I don't think I've seen a magstrip-compatible terminal for years, they just don't have the swipe part anymore, it's been removed from terminals and cash registers ages ago.

In Russia no one swipes their cards, and swiping doesn't work if you try, but the terminals do have the swipe part and the cards do still come with magstripes. There's a separate magstripe reader, usually built into the cashier's monitor, at places that use magstripe cards for loyalty and gift cards.

Re: MagSpoof: Wireless Magstrip Spoofer

#49
post #5

I long for the day I can carry my phone or watch without needing keys or wallet. The fact that most adults carry at least 3 things (keys/phone/wallet) at all times in 2022 is crazy.

Can’t help you with the keys or ID (yet), but I exclusively use the stored cards on my Apple Watch for payment. It is so reliable (in Norway) that I haven’t brought my wallet on normal days in 2+ years.

Even on vacation in Northern Europe (Belgium, Netherlands, France, Germany) and on a business trip to the US (California+Texas) this year, I very rarely had to use the physical cards. NFC just works. Everywhere.

I still bring the cards on important occasions or when going further than a normal drive, though - a testament to the fact that the day you’re longing for is not _quite_ here yet.

Re: MagSpoof: Wireless Magstrip Spoofer

#50
post #33
post #11

Credit card security is comically poor. Off the top of my head: 1. An NFC-enabled EMV card will happily reveal its entire account number and expiration date over NFC with no authentication whatsoever. I don’t know whether the CVV comes along, but I wouldn’t be surprised if it did. 2. (As mentioned in the article) issuers accept transactions from EMV (chip)-capable readers that nominally originate from EMV-capable car…

> An NFC-enabled EMV card will happily reveal its entire account number and expiration date over NFC with no authentication whatsoever. EMV was enabled with the intention of replacing magnetic stripe payments quickly. Together with 3DS on the online payment side, this would have effectively made a card number by itself worthless. Unfortunately this hasn't happend (except for mobile wallets using tokenization like App…

> I'd cut the original designers some slack.

I'm willing to cut the original designers some slack. I'm not really willing to cut the industry slack for not fixing it. It's been years. Heck, EMV had been widely deployed in Europe for years before it showed up in the US.

> Another reason: How would you even implement authentication? There are millions of terminals out there, operated by at least hundreds of different service providers. What key would you use for authentication and how would you hide it in a way that wouldn't eventually be leaked from legitimate terminals?

There's no need. Just have the chip have an entirely different account number that only works for EMV transactions. This wouldn't even need updates to existing card readers.

> Some issuers do, some don't. That's not the protocol's fault.

This is the payment card industry, which has an entire tome of moderately onerous requirements that everyone must follow. Surely there could be a new requirement for issuers to verify that the transaction is authenticated properly.

Post reply on HN