Live data from Hacker News

MagSpoof: Wireless Magstrip Spoofer

github.com

71–80 of 105 posts

Re: MagSpoof: Wireless Magstrip Spoofer

#71
post #69

Earlier quoted context omitted.

> Last time I tried swiping my card — and that was ages ago — the terminal displayed something to the effect of "this card has a chip, please insert the chip". The problem is that the way the terminal knows "this card has a chip" is that information is encoded on the magstripe. So rewriting the magstripe can just disable that functionality. I assume the merchant could configure their terminals to insist on using the…

Huh? I don't know what's the situation now because I hardly use the chip any more, I mostly tap (the card itself, we no longer have Google Pay), but I don't remember a single time when the chip wouldn't work. The terminals around here look like any mass-produced electronic device, nothing special about them. Though they are old — I do sometimes see newer fancier all-touchscreen ones when I travel to other countries.…

[deleted]

Re: MagSpoof: Wireless Magstrip Spoofer

#73
post #33
post #11

Credit card security is comically poor. Off the top of my head: 1. An NFC-enabled EMV card will happily reveal its entire account number and expiration date over NFC with no authentication whatsoever. I don’t know whether the CVV comes along, but I wouldn’t be surprised if it did. 2. (As mentioned in the article) issuers accept transactions from EMV (chip)-capable readers that nominally originate from EMV-capable car…

> An NFC-enabled EMV card will happily reveal its entire account number and expiration date over NFC with no authentication whatsoever. EMV was enabled with the intention of replacing magnetic stripe payments quickly. Together with 3DS on the online payment side, this would have effectively made a card number by itself worthless. Unfortunately this hasn't happend (except for mobile wallets using tokenization like App…

>At merchants not using 3DS, that is true – but these merchants also bear the full liability for any fraud happening

As far as I know, the merchant always bears the full liability for fraud, whether you use 3ds or not. The sales pitch for 3ds is simply to reduce the chances of fraud.

Also, you do don't even necessarily need the CVV to buy with a cc online. Depends on the merchant.

Re: MagSpoof: Wireless Magstrip Spoofer

#74

Earlier quoted context omitted.

> [...] found a global pattern that allows me to accurately predict American Express card numbers by knowing a full card number, even if already reported lost or stolen. > This means if I were to obtain your Amex card and you called it in as lost or stolen, the moment you get a new card, I know your new credit card number. Criminally hilarious.

Amex is already legally responsible for fraudulent charges on your card, so if they want to make the numbers predictable, why not?

Actually, the merchants are fully responsible for fraudulent charges. So Amex has little incentive to be secure.

Re: MagSpoof: Wireless Magstrip Spoofer

#75
post #74

Earlier quoted context omitted.

Amex is already legally responsible for fraudulent charges on your card, so if they want to make the numbers predictable, why not?

Actually, the merchants are fully responsible for fraudulent charges. So Amex has little incentive to be secure.

It’s not really that simple, and it’s likely that these attacks would fail CVV/3DS/etc, so it’d be hard for a reasonable merchant to be tricked regardless.

Re: MagSpoof: Wireless Magstrip Spoofer

#76
post #69

Earlier quoted context omitted.

> Last time I tried swiping my card — and that was ages ago — the terminal displayed something to the effect of "this card has a chip, please insert the chip". The problem is that the way the terminal knows "this card has a chip" is that information is encoded on the magstripe. So rewriting the magstripe can just disable that functionality. I assume the merchant could configure their terminals to insist on using the…

Huh? I don't know what's the situation now because I hardly use the chip any more, I mostly tap (the card itself, we no longer have Google Pay), but I don't remember a single time when the chip wouldn't work. The terminals around here look like any mass-produced electronic device, nothing special about them. Though they are old — I do sometimes see newer fancier all-touchscreen ones when I travel to other countries.…

> Huh? I don't know what's the situation now because I hardly use the chip any more, I mostly tap (the card itself, we no longer have Google Pay), but I don't remember a single time when the chip wouldn't work.

Wow. My main card doesn't have tap capability, so I'm forced to use the chip all the time. Read failures are extremely common. I even have my own protocol for when it fails: take it out and shove it back in while holding it firmly to the left edge of the slot. If that doesn't work, try again holding it against the right edge of the slot. Sometimes, it's just sloppy alignment in the slot and doing one of those will fix it. If normal, left-aligned and right-aligned all fail, that makes three attempts so the machine will give up and have you swipe it anyway.

Re: MagSpoof: Wireless Magstrip Spoofer

#78
post #54

Earlier quoted context omitted.

> Last time I tried swiping my card — and that was ages ago — the terminal displayed something to the effect of "this card has a chip, please insert the chip". I think it's configurable depending on merchant risk tolerance. I've seen cases where the terminal lets you swipe after three failed chip reads, for example.

Almost every terminal will fall back to mag-swipe if the chip fails to read 3 times. I had an Amex with a faulty chip and had to do this every time. Terminal (every single one) would refuse to allow me to pay with a swipe initially, insisting on chip -- but once the chip failed 3 times, they'd all happily take the swipe.

The terminal may try, but in Europe since about a decade ago most card issuers will reject stripe transactions on a terminal with a chip reader when the card also has a chip, to prevent downgrade attacks.

Re: MagSpoof: Wireless Magstrip Spoofer

#79
post #54

Earlier quoted context omitted.

Almost every terminal will fall back to mag-swipe if the chip fails to read 3 times. I had an Amex with a faulty chip and had to do this every time. Terminal (every single one) would refuse to allow me to pay with a swipe initially, insisting on chip -- but once the chip failed 3 times, they'd all happily take the swipe.

The terminal may try, but in Europe since about a decade ago most card issuers will reject stripe transactions on a terminal with a chip reader when the card also has a chip, to prevent downgrade attacks.

Ah yes, my comment was totally US-centric, which is dumb of me.

Re: MagSpoof: Wireless Magstrip Spoofer

#80
post #39

The american reliance on magstrips is crazy. Over here(Poland) I don't think I've seen a magstrip-compatible terminal for years, they just don't have the swipe part anymore, it's been removed from terminals and cash registers ages ago.

The US market has been historically different for other reasons. The big one is liability. In the US the cardholder is rarely liable for fraud charges. Which is why the minutiae of credit card security mechanisms just kind of doesn’t matter to us. But from my understanding, in Europe and places like India, the cardholder is usually liable. Which also explains why cardholders seem to be a lot more anxious about these…

The US market also has a lot higher margins to absorb any fraud - they have higher fees (since fees are capped to 0.2-0.3% in EU) and historically have had higher credit utilization. So they decided that "friction" costs more than fraud.
Post reply on HN