Live data from Hacker News

MagSpoof: Wireless Magstrip Spoofer

github.com

91–100 of 105 posts

Re: MagSpoof: Wireless Magstrip Spoofer

#91

I'm not sure this is useful for credit cards at all - ever since the deadline for chipped cards to roll out passed, my issuers all decline swipe transactions. Even at middle of nowhere gas pumps that don't have chip readers, I found two during my last cross-country trip, swiping the card will get a decline response.

Many places in USA, you can 'fall back' to magstripe by inserting the chip and having it fail to read 3 or 4 or 5 times. The reader will prompt for a swipe after the threshold of failed attempts is reached. I'm really tough on my cards and when the chip dies this becomes my routine everywhere until the new one comes in the mail.

Re: MagSpoof: Wireless Magstrip Spoofer

#92
post #36

Earlier quoted context omitted.

But that's what's covered in the article. The "block transaction and require chip and PIN" flag is stored on the magtrack itself.

The bank/processor also knows it and is able to reject any modifications. Whether they do is a matter of their security posture.

the article covers that too, saying that the issuer does not seem to do such verification

Re: MagSpoof: Wireless Magstrip Spoofer

#93
post #5

I long for the day I can carry my phone or watch without needing keys or wallet. The fact that most adults carry at least 3 things (keys/phone/wallet) at all times in 2022 is crazy.

I agree it would be convenient. But consider the new dangers: 1) pickpocketing would suddenly be 3x as profitable and 3x as easy, 2) lose one thing and you've lost everything, 3) if one thing stops working, everything stops working, 4) venues where you have to give up your phone means carrying extra cash in.... a wallet, 5) cybercriminals can now steal much more from you without ever getting near you, 6) I imagine th…

1) so lose the keychain and evenly distributed your keys in all your pockets to minimize the percentage of personal items lost per successful pickpocket

Re: MagSpoof: Wireless Magstrip Spoofer

#94

Earlier quoted context omitted.

It’s a great idea until the battery in your devices fail and you’re stranded somewhere with no ID, no way to communicate, and no money for a train ticket.

Is that any different from losing your wallet in the pre-smartphone era though?

wouldn't the proper comparison be to losing your phone in the current era but still having keys and wallet?

Re: MagSpoof: Wireless Magstrip Spoofer

#95
post #73
post #33

Earlier quoted context omitted.

> An NFC-enabled EMV card will happily reveal its entire account number and expiration date over NFC with no authentication whatsoever. EMV was enabled with the intention of replacing magnetic stripe payments quickly. Together with 3DS on the online payment side, this would have effectively made a card number by itself worthless. Unfortunately this hasn't happend (except for mobile wallets using tokenization like App…

>At merchants not using 3DS, that is true – but these merchants also bear the full liability for any fraud happening As far as I know, the merchant always bears the full liability for fraud, whether you use 3ds or not. The sales pitch for 3ds is simply to reduce the chances of fraud. Also, you do don't even necessarily need the CVV to buy with a cc online. Depends on the merchant.

The amount of misinformation in this thread is staggering.

Re: MagSpoof: Wireless Magstrip Spoofer

#96
post #15

Earlier quoted context omitted.

I agree it would be convenient. But consider the new dangers: 1) pickpocketing would suddenly be 3x as profitable and 3x as easy, 2) lose one thing and you've lost everything, 3) if one thing stops working, everything stops working, 4) venues where you have to give up your phone means carrying extra cash in.... a wallet, 5) cybercriminals can now steal much more from you without ever getting near you, 6) I imagine th…

I can theoretically leave my home with just my smartphone. I can use it to pay fare at the local train station, get directions to restaurants, read the news, pay for food and coffee, and even lock / unlock my apartment. I do still bring my wallet and keys, because I'd hate to run into a scenario where my phone does get lost, stolen, or damaged, leaving me stranded without a way to get home. But the concept is definit…

You can still use phone to do everything for convenience, but carry stuff as a backup.

Re: MagSpoof: Wireless Magstrip Spoofer

#97
post #73
post #33

Earlier quoted context omitted.

> An NFC-enabled EMV card will happily reveal its entire account number and expiration date over NFC with no authentication whatsoever. EMV was enabled with the intention of replacing magnetic stripe payments quickly. Together with 3DS on the online payment side, this would have effectively made a card number by itself worthless. Unfortunately this hasn't happend (except for mobile wallets using tokenization like App…

>At merchants not using 3DS, that is true – but these merchants also bear the full liability for any fraud happening As far as I know, the merchant always bears the full liability for fraud, whether you use 3ds or not. The sales pitch for 3ds is simply to reduce the chances of fraud. Also, you do don't even necessarily need the CVV to buy with a cc online. Depends on the merchant.

> As far as I know, the merchant always bears the full liability for fraud, whether you use 3ds or not.

This is very much untrue. If a merchant initiates the 3DS flow, liability for fraudulent transactions shifts from the merchant onto the issuer. Here's documentation from Stripe[1] on the matrix of possible flows and the resulting liability shift, and docs from Adyen[2] on card networks that support liability shifting with 3DS.

[1]: https://support.stripe.com/questions/liability-shift-post-sc...

[2]: https://www.adyen.help/hc/en-us/articles/5091186681500-What-...

Re: MagSpoof: Wireless Magstrip Spoofer

#98
post #74

Earlier quoted context omitted.

Actually, the merchants are fully responsible for fraudulent charges. So Amex has little incentive to be secure.

It’s not really that simple, and it’s likely that these attacks would fail CVV/3DS/etc, so it’d be hard for a reasonable merchant to be tricked regardless.

"I also determined that the CSC (essentially behaves like a CID or CVV2 on the magstripe) for a lost or stolen card continues to work for a newer, predicted card. An attacker would be able to use a stolen card's CSC with the predicted card number and expiration to make actual purchases."

Also...ask any merchant if they've ever NOT been left holding the bag for a fraudulent purchase. The only time that happened for me was when I could prove it was fraud by the actual cardholder, and even then, the banks would often deny the counterclaim anyway.

Re: MagSpoof: Wireless Magstrip Spoofer

#99
post #84

Earlier quoted context omitted.

> 3DSecure is a thing and its job is to prevent this exact situation. 3DSecure ticks all the boxes for what you're not supposed to do. Popup window: check, put in your banking username and password while using a merchant site, not your bank's site: check. I think I've seen a 3dsecure prompt once, maybe twice. I tried to enable it so I could buy fron Aliexpress without calling my card issuer and asking them to turn of…

> 3DSecure ticks all the boxes for what you're not supposed to do If your bank implemented it that way. My 3DSecure prompts just asks for a confirmation code, which is sent via SMS or an app on the phone. No creds.

Yeah wtf. This is the only implementation I've seen, so I assumed they're all like that.

Re: MagSpoof: Wireless Magstrip Spoofer

#100
post #48

Earlier quoted context omitted.

In Russia no one swipes their cards, and swiping doesn't work if you try, but the terminals do have the swipe part and the cards do still come with magstripes. There's a separate magstripe reader, usually built into the cashier's monitor, at places that use magstripe cards for loyalty and gift cards.

I'm wondering why they don't use the payment terminal's reader mode for this. I know it can be done – Rimi shops in Baltic states handle both magstripe and NFC loyalty cards through the terminal (just regular Ingenico ICTxxx line terminals, like many shops in Russia use).

I suspect this has to do with the POS software Russian stores use being inflexible or bank SDKs being restrictive. Probably the latter, as I've seen some kiosks that take card payments just pop up a Windows window with the Sberbank logo and transaction status instead of showing that in their own UI.
Post reply on HN