Live data from Hacker News

MagSpoof: Wireless Magstrip Spoofer

github.com

81–90 of 105 posts

Re: MagSpoof: Wireless Magstrip Spoofer

#81
post #5

I long for the day I can carry my phone or watch without needing keys or wallet. The fact that most adults carry at least 3 things (keys/phone/wallet) at all times in 2022 is crazy.

It’s a great idea until the battery in your devices fail and you’re stranded somewhere with no ID, no way to communicate, and no money for a train ticket.

Is that any different from losing your wallet in the pre-smartphone era though?

Re: MagSpoof: Wireless Magstrip Spoofer

#82
post #69

Earlier quoted context omitted.

Huh? I don't know what's the situation now because I hardly use the chip any more, I mostly tap (the card itself, we no longer have Google Pay), but I don't remember a single time when the chip wouldn't work. The terminals around here look like any mass-produced electronic device, nothing special about them. Though they are old — I do sometimes see newer fancier all-touchscreen ones when I travel to other countries.…

> Huh? I don't know what's the situation now because I hardly use the chip any more, I mostly tap (the card itself, we no longer have Google Pay), but I don't remember a single time when the chip wouldn't work. Wow. My main card doesn't have tap capability, so I'm forced to use the chip all the time. Read failures are extremely common. I even have my own protocol for when it fails: take it out and shove it back in wh…

That's really odd. I don't think mine has _ever_ failed. Maybe see if you can get a new card? Or it could be a regional thing I guess.

Re: MagSpoof: Wireless Magstrip Spoofer

#83
post #82

Earlier quoted context omitted.

> Huh? I don't know what's the situation now because I hardly use the chip any more, I mostly tap (the card itself, we no longer have Google Pay), but I don't remember a single time when the chip wouldn't work. Wow. My main card doesn't have tap capability, so I'm forced to use the chip all the time. Read failures are extremely common. I even have my own protocol for when it fails: take it out and shove it back in wh…

That's really odd. I don't think mine has _ever_ failed. Maybe see if you can get a new card? Or it could be a regional thing I guess.

It's happened with every chip card I've ever had. Even with ones that were a couple days old. The cashiers often say "yeah, that chip reader has been acting up" so I know it's not me. There's even a subway sandwich place I go to frequently where one day they had a whole brand new POS system with new readers, and it failed on me, and the cashier said "yeah, brand new system and it almost never works."

The Safeway POS grunts this very annoying alarm sound and shows CHIP MALFUNCTION on the screen, and it's just a standard part of my shopping experience now.

Re: MagSpoof: Wireless Magstrip Spoofer

#84
post #45
post #11

Credit card security is comically poor. Off the top of my head: 1. An NFC-enabled EMV card will happily reveal its entire account number and expiration date over NFC with no authentication whatsoever. I don’t know whether the CVV comes along, but I wouldn’t be surprised if it did. 2. (As mentioned in the article) issuers accept transactions from EMV (chip)-capable readers that nominally originate from EMV-capable car…

> 2. (As mentioned in the article) issuers accept transactions from EMV (chip)-capable readers that nominally originate from EMV-capable cards without requiring the chip to be used. Last time I tried swiping my card — and that was ages ago — the terminal displayed something to the effect of "this card has a chip, please insert the chip". > 3. The information leaked in #1 is enough to buy things online (as long as the…

> 3DSecure is a thing and its job is to prevent this exact situation.

3DSecure ticks all the boxes for what you're not supposed to do. Popup window: check, put in your banking username and password while using a merchant site, not your bank's site: check.

I think I've seen a 3dsecure prompt once, maybe twice. I tried to enable it so I could buy fron Aliexpress without calling my card issuer and asking them to turn off all fraud protection on my account for an hour, but that still doesn't work, when I want weird junk direct, gotta call in.

Re: MagSpoof: Wireless Magstrip Spoofer

#85
I'm not sure this is useful for credit cards at all - ever since the deadline for chipped cards to roll out passed, my issuers all decline swipe transactions. Even at middle of nowhere gas pumps that don't have chip readers, I found two during my last cross-country trip, swiping the card will get a decline response.

Re: MagSpoof: Wireless Magstrip Spoofer

#86

Earlier quoted context omitted.

It’s a great idea until the battery in your devices fail and you’re stranded somewhere with no ID, no way to communicate, and no money for a train ticket.

Is that any different from losing your wallet in the pre-smartphone era though?

Depends.

In pre-smartphone era I usually had an 'in case of emergency' bill tucked away in my ID, which was in other pocket than wallet.

Re: MagSpoof: Wireless Magstrip Spoofer

#87
post #84
post #45

Earlier quoted context omitted.

> 2. (As mentioned in the article) issuers accept transactions from EMV (chip)-capable readers that nominally originate from EMV-capable cards without requiring the chip to be used. Last time I tried swiping my card — and that was ages ago — the terminal displayed something to the effect of "this card has a chip, please insert the chip". > 3. The information leaked in #1 is enough to buy things online (as long as the…

> 3DSecure is a thing and its job is to prevent this exact situation. 3DSecure ticks all the boxes for what you're not supposed to do. Popup window: check, put in your banking username and password while using a merchant site, not your bank's site: check. I think I've seen a 3dsecure prompt once, maybe twice. I tried to enable it so I could buy fron Aliexpress without calling my card issuer and asking them to turn of…

> 3DSecure ticks all the boxes for what you're not supposed to do

If your bank implemented it that way.

My 3DSecure prompts just asks for a confirmation code, which is sent via SMS or an app on the phone. No creds.

Re: MagSpoof: Wireless Magstrip Spoofer

#88
post #48

The american reliance on magstrips is crazy. Over here(Poland) I don't think I've seen a magstrip-compatible terminal for years, they just don't have the swipe part anymore, it's been removed from terminals and cash registers ages ago.

In Russia no one swipes their cards, and swiping doesn't work if you try, but the terminals do have the swipe part and the cards do still come with magstripes. There's a separate magstripe reader, usually built into the cashier's monitor, at places that use magstripe cards for loyalty and gift cards.

I'm wondering why they don't use the payment terminal's reader mode for this. I know it can be done – Rimi shops in Baltic states handle both magstripe and NFC loyalty cards through the terminal (just regular Ingenico ICTxxx line terminals, like many shops in Russia use).

Re: MagSpoof: Wireless Magstrip Spoofer

#89
> the bits stating the card has Chip-and-PIN can be turned off from the magstripe

This is true, but it's not the last line of defence, right? The bank could still reject the transaction if it sees a chip card used to do a magstripe transaction on a chip-capable reader. That relies on the reader providing that information to the bank, though, and while I believe the EMV protocol can do that, I don't know if that's used for magstripe transactions (talking purely reader to bank here, not reader to card).

I don't think it can be fairly considered a security issue that the “I'm a chip card, why are you swiping me” bit is on the magnetic stripe. It's obvious that doesn't protect against modification, but it's not supposed to! Hell, it's probably only meant to be a reminder anyway, as you can subvert it by making the card reader think the chip isn't working.

Re: MagSpoof: Wireless Magstrip Spoofer

#90
post #84

Earlier quoted context omitted.

> 3DSecure is a thing and its job is to prevent this exact situation. 3DSecure ticks all the boxes for what you're not supposed to do. Popup window: check, put in your banking username and password while using a merchant site, not your bank's site: check. I think I've seen a 3dsecure prompt once, maybe twice. I tried to enable it so I could buy fron Aliexpress without calling my card issuer and asking them to turn of…

> 3DSecure ticks all the boxes for what you're not supposed to do If your bank implemented it that way. My 3DSecure prompts just asks for a confirmation code, which is sent via SMS or an app on the phone. No creds.

Other verification methods I’ve seen: specific characters from a 3DS-specific password (old nationwide.co.uk), in-app approval notification (wise.com), Swedish BankID app verification (ICA banken, Handelsbanken).
Post reply on HN