Live data from Hacker News

Target's EasySweep – Simplifying Skimmer Detection

tech.target.com

101–110 of 151 posts

Re: Target's EasySweep – Simplifying Skimmer Detection

#101
post #68
post #53

Earlier quoted context omitted.

You still have to request access from Target. GP is asking for it to just be published online somewhere.

It's right here: https://patents.google.com/patent/US11507762B2/ Took me five seconds. You can make one if you feel like it.

That is not the "Step CAD file" available to retailers who contact Target and this thread is asking to be published.

Re: Target's EasySweep – Simplifying Skimmer Detection

#102
post #50

Could payment terminals be made with built-in physical countermeasures for detection? Ideas: (1) Terminal has a scale built into its feet/mount. It periodically weighs itself, and if (ignoring fluctuations) it weighs too much, it shuts down. It's hard to build a skimmer that weighs 0 grams. (2) Proximity sensors in key locations on the housing. My smartphone can disable its touchscreen when I hold it against my face,…

Of course they can be made that way. The countermeasure built into gambling equipment like slot machines is incredible. But then it would cost more than their competitors. With much more maintenance for false positives, etc. And the vendor doesn't really pay the price for skimmer fraud..

If someone comes up with an anti-skimmer terminal the payment processors would benefit from having a lower transaction fee for transactions posted from such a terminal. That would in time push the market to use such terminals.

Re: Target's EasySweep – Simplifying Skimmer Detection

#103
post #80
post #16

Earlier quoted context omitted.

Even with EMV transactions, they are apparently able to get the card # which is transmitted in clear text by the chip. And the PIN from the keyboard overlay for debit transactions. Later they can clone the card # onto a fake mag stripe card and use the fake card for card-present purchases. They probably cannot make card-not-present (online) purchases since I don't think they can get the CVV. https://krebsonsecurity.c…

EMV doesn’t transmit the full card number in the clear. I don’t know how they’d get it. IIRC the track data is sanitized, but maybe it wasn’t always. I’m not even sure all cards give it in a modern EMV transaction. The old mag stripe emulation mode of contactless did, but that’s legacy and many places won’t accept it and cards won’t do it. However the good old “break the slot or chip reader so they have to use mag st…

Googling "EMV sniffer" returns a bunch of sketchy sites that claim they get the card number from the chip, not the mag stripe. That's also what seems to be implied by the submitted link. Here's another post claiming the card # is readable from the chip:

https://security.stackexchange.com/questions/161493/what-inf...

Re: Target's EasySweep – Simplifying Skimmer Detection

#104
post #44

Earlier quoted context omitted.

It annoys me that none of the gas stations I use have the "tap to pay" that actually works. They seem to have the sensor on the pumps, but they never work.

My preferred gas station got tap to pay during the pandemic and I make it a clear effort to use it every time I get gas to try to bump the numbers up so it doesn't go away or gets fixed if it breaks. Such a great feature.

Preferred gas station here did something to the UI--you can "pay" by waving your phone at it, but then it will prompt for your zip code. When you enter the zip code there's a couple of prompts about ensuring you know you're paying credit price--oops, entering the zip code also answers no to the first question.

Re: Target's EasySweep – Simplifying Skimmer Detection

#105
post #93

We wouldn't even need to worry about this dumb stuff if we had actual cryptographic PKI for payments. Honestly at some point fraud is 100% the card issuer's fault when the tech to prevent it is here and now. Why I still can't register a public key with my bank and say "do not under any circumstance honor a transaction unless it's signed with my private key" is beyond me.

That's EMV, and it is still not 100% foolproof because the card itself doesn't have a display and Allow/Deny button.

> still not 100% foolproof because the card itself doesn't have a display and Allow/Deny button.

I'm assuming you are thinking about an attack where a compromised terminal processes an attacker-issued transaction (relayed from elsewhere) instead of the genuine one.

It seems like a solution to this would be for the card to issue a challenge to the reader and only provide a very short timeframe to answer, so that relaying it elsewhere is impossible due to speed of light and all that.

Re: Target's EasySweep – Simplifying Skimmer Detection

#107
post #73

Earlier quoted context omitted.

This is a good thing, some troll could patent it and then deny anyone else the right to use it.

Wouldn't an attempt to do that fail the prior art test?

Why even risk it? Just get the patent and license it for free.

Re: Target's EasySweep – Simplifying Skimmer Detection

#108

We wouldn't even need to worry about this dumb stuff if we had actual cryptographic PKI for payments. Honestly at some point fraud is 100% the card issuer's fault when the tech to prevent it is here and now. Why I still can't register a public key with my bank and say "do not under any circumstance honor a transaction unless it's signed with my private key" is beyond me.

The credit card number is both your public key and your private key: https://www.icanbarelydraw.com/comic/2702

Re: Target's EasySweep – Simplifying Skimmer Detection

#109
post #88
post #66

Earlier quoted context omitted.

Alternatively they could just remove the slot and require self-pay terminals to be contactless. It really makes no sense to me why merchants don't already do this proactively; they are well incentivized: 1) Contactless merchant fees are lower than dip or swipe 2) Payment terminals are cheaper 3) Less fraud/shrink This hunk of plastic from Target is a solution looking for a problem.

Ironically, contactless has been the source of new types of skimmer attacks. A skimmer could just add an nfc coil and wouldn't even need to physically touch the card anymore.

Yes by all means, let's use the threat of a possible attack on EMV to continue to prop up the magstrip and completely disregard that pretty much all of the successful attacks against chip or contactless involve legacy magstrip emulation. If it's good enough for Granddad, it's good enough for me!

Re: Target's EasySweep – Simplifying Skimmer Detection

#110
post #31

Earlier quoted context omitted.

:-( I recently went through the opposite of this. A purchase at denon.com was declined, got a "please verify" email from my issuer which I approved and re-did the purchase. My issuer authorized the payment the second time, but then it got held up by NoFraud who sent me their own "please verify" email which I did. I had used an iCloud Hide My Email address for the purchase so a day later I get another email from NoFra…

> I had used an iCloud Hide My Email address for the purchase so a day later I get another email from NoFraud I got hit by a merchant using "NoFraud" as well. After making an order from the merchant's site, using Apple Pay on the web (which is, allegedly, rather hard to fake), I received an email saying my order was canceled as it "appears that a merchant-specific email address was used" and to "please resubmit the o…

as if Email is some sort of durable identifier in the first place.
Post reply on HN