Earlier quoted context omitted.
You still have to request access from Target. GP is asking for it to just be published online somewhere.
It's right here: https://patents.google.com/patent/US11507762B2/ Took me five seconds. You can make one if you feel like it.
Target's EasySweep – Simplifying Skimmer Detection
101–110 of 151 posts
Re: Target's EasySweep – Simplifying Skimmer Detection
#102Could payment terminals be made with built-in physical countermeasures for detection? Ideas: (1) Terminal has a scale built into its feet/mount. It periodically weighs itself, and if (ignoring fluctuations) it weighs too much, it shuts down. It's hard to build a skimmer that weighs 0 grams. (2) Proximity sensors in key locations on the housing. My smartphone can disable its touchscreen when I hold it against my face,…
Of course they can be made that way. The countermeasure built into gambling equipment like slot machines is incredible. But then it would cost more than their competitors. With much more maintenance for false positives, etc. And the vendor doesn't really pay the price for skimmer fraud..
Re: Target's EasySweep – Simplifying Skimmer Detection
#103Earlier quoted context omitted.
Even with EMV transactions, they are apparently able to get the card # which is transmitted in clear text by the chip. And the PIN from the keyboard overlay for debit transactions. Later they can clone the card # onto a fake mag stripe card and use the fake card for card-present purchases. They probably cannot make card-not-present (online) purchases since I don't think they can get the CVV. https://krebsonsecurity.c…
EMV doesn’t transmit the full card number in the clear. I don’t know how they’d get it. IIRC the track data is sanitized, but maybe it wasn’t always. I’m not even sure all cards give it in a modern EMV transaction. The old mag stripe emulation mode of contactless did, but that’s legacy and many places won’t accept it and cards won’t do it. However the good old “break the slot or chip reader so they have to use mag st…
https://security.stackexchange.com/questions/161493/what-inf...
Re: Target's EasySweep – Simplifying Skimmer Detection
#104Earlier quoted context omitted.
It annoys me that none of the gas stations I use have the "tap to pay" that actually works. They seem to have the sensor on the pumps, but they never work.
My preferred gas station got tap to pay during the pandemic and I make it a clear effort to use it every time I get gas to try to bump the numbers up so it doesn't go away or gets fixed if it breaks. Such a great feature.
Re: Target's EasySweep – Simplifying Skimmer Detection
#105We wouldn't even need to worry about this dumb stuff if we had actual cryptographic PKI for payments. Honestly at some point fraud is 100% the card issuer's fault when the tech to prevent it is here and now. Why I still can't register a public key with my bank and say "do not under any circumstance honor a transaction unless it's signed with my private key" is beyond me.
That's EMV, and it is still not 100% foolproof because the card itself doesn't have a display and Allow/Deny button.
I'm assuming you are thinking about an attack where a compromised terminal processes an attacker-issued transaction (relayed from elsewhere) instead of the genuine one.
It seems like a solution to this would be for the card to issue a challenge to the reader and only provide a very short timeframe to answer, so that relaying it elsewhere is impossible due to speed of light and all that.
Re: Target's EasySweep – Simplifying Skimmer Detection
#106Re: Target's EasySweep – Simplifying Skimmer Detection
#107Re: Target's EasySweep – Simplifying Skimmer Detection
#108We wouldn't even need to worry about this dumb stuff if we had actual cryptographic PKI for payments. Honestly at some point fraud is 100% the card issuer's fault when the tech to prevent it is here and now. Why I still can't register a public key with my bank and say "do not under any circumstance honor a transaction unless it's signed with my private key" is beyond me.
Re: Target's EasySweep – Simplifying Skimmer Detection
#109Earlier quoted context omitted.
Alternatively they could just remove the slot and require self-pay terminals to be contactless. It really makes no sense to me why merchants don't already do this proactively; they are well incentivized: 1) Contactless merchant fees are lower than dip or swipe 2) Payment terminals are cheaper 3) Less fraud/shrink This hunk of plastic from Target is a solution looking for a problem.
Ironically, contactless has been the source of new types of skimmer attacks. A skimmer could just add an nfc coil and wouldn't even need to physically touch the card anymore.
Re: Target's EasySweep – Simplifying Skimmer Detection
#110Earlier quoted context omitted.
:-( I recently went through the opposite of this. A purchase at denon.com was declined, got a "please verify" email from my issuer which I approved and re-did the purchase. My issuer authorized the payment the second time, but then it got held up by NoFraud who sent me their own "please verify" email which I did. I had used an iCloud Hide My Email address for the purchase so a day later I get another email from NoFra…
> I had used an iCloud Hide My Email address for the purchase so a day later I get another email from NoFraud I got hit by a merchant using "NoFraud" as well. After making an order from the merchant's site, using Apple Pay on the web (which is, allegedly, rather hard to fake), I received an email saying my order was canceled as it "appears that a merchant-specific email address was used" and to "please resubmit the o…