Live data from Hacker News

MagSpoof: Wireless Magstrip Spoofer

github.com

101–105 of 105 posts

Re: MagSpoof: Wireless Magstrip Spoofer

#101
post #50
post #33

Earlier quoted context omitted.

> An NFC-enabled EMV card will happily reveal its entire account number and expiration date over NFC with no authentication whatsoever. EMV was enabled with the intention of replacing magnetic stripe payments quickly. Together with 3DS on the online payment side, this would have effectively made a card number by itself worthless. Unfortunately this hasn't happend (except for mobile wallets using tokenization like App…

> I'd cut the original designers some slack. I'm willing to cut the original designers some slack. I'm not really willing to cut the industry slack for not fixing it. It's been years. Heck, EMV had been widely deployed in Europe for years before it showed up in the US. > Another reason: How would you even implement authentication? There are millions of terminals out there, operated by at least hundreds of different s…

> Just have the chip have an entirely different account number that only works for EMV transactions.

Issuers can certainly do that, and some do (e.g. Apple Card).

Some use cases don't handle that very well, though, e.g. booking a hotel online and then presenting the physical chip card for verification, comparing the last four digits printed on the card with those printed on the receipt for a refund, and others.

But there is already something that is different across all interfaces (chip, magnetic stripe, human-readable printed card number): The CVC. Practically, this makes "cross-channel skimming" pretty hard.

Re: MagSpoof: Wireless Magstrip Spoofer

#102
post #47
post #39

Earlier quoted context omitted.

The US market has been historically different for other reasons. The big one is liability. In the US the cardholder is rarely liable for fraud charges. Which is why the minutiae of credit card security mechanisms just kind of doesn’t matter to us. But from my understanding, in Europe and places like India, the cardholder is usually liable. Which also explains why cardholders seem to be a lot more anxious about these…

> in Europe and places like India, the cardholder is usually liable I suppose it depends on what you mean by "usually" but no, in the EU generally you just go to the police station which has a form for declaring credit card fraud and the bank often reimburses you before receiving it. Your replacement card is free on this situation. It is up to the bank to get their money back if they want to bother. I don't know of a…

Ok that’s possible but still a pain in the butt to do.

My point was mainly that technical differences don’t tell the whole story.

Re: MagSpoof: Wireless Magstrip Spoofer

#103
post #5

I long for the day I can carry my phone or watch without needing keys or wallet. The fact that most adults carry at least 3 things (keys/phone/wallet) at all times in 2022 is crazy.

I could leave my keys at home, but most days now I'm traveling with my security keys, partly to keep them away from my desk at home and partly in case I might need to login to a secure account while out and about.

Re: MagSpoof: Wireless Magstrip Spoofer

#104
post #33
post #11

Credit card security is comically poor. Off the top of my head: 1. An NFC-enabled EMV card will happily reveal its entire account number and expiration date over NFC with no authentication whatsoever. I don’t know whether the CVV comes along, but I wouldn’t be surprised if it did. 2. (As mentioned in the article) issuers accept transactions from EMV (chip)-capable readers that nominally originate from EMV-capable car…

> An NFC-enabled EMV card will happily reveal its entire account number and expiration date over NFC with no authentication whatsoever. EMV was enabled with the intention of replacing magnetic stripe payments quickly. Together with 3DS on the online payment side, this would have effectively made a card number by itself worthless. Unfortunately this hasn't happend (except for mobile wallets using tokenization like App…

>Another reason: How would you even implement authentication?

Have the card sign a transaction using a captive secret vs. revealing its secret to the terminal?

Re: MagSpoof: Wireless Magstrip Spoofer

#105

The american reliance on magstrips is crazy. Over here(Poland) I don't think I've seen a magstrip-compatible terminal for years, they just don't have the swipe part anymore, it's been removed from terminals and cash registers ages ago.

I have 2 gift cards and one additional "LunchPass" card issued this year in Poland, all three are magstrip only.

The magstrip readers are not removed from the terminals, even the newest smartphone-like have them, you just don't know where to look. Of course, sometimes cashiers are surprised that my card is magstrip-only and they are double-surprised when I show them where is the magstrip reader on the terminal they use :)

Post reply on HN