Live data from Hacker News

Swiping left on magnetic stripes

mastercard.com

321–325 of 325 posts

Re: Swiping left on magnetic stripes

#321
post #174

Earlier quoted context omitted.

In the UK (and most of Europe afaik) the card is ejected immediately before the cash; the ejecting of the card indicates your authenticated session has ended.

There are some in the U.S. that do this, but it still didn't stop my friend from leaving his card in the ATM and having to go through a process with the bank and wait for a new card to show. Better to just make sure you have it by stopping you from doing anything else until you have it imo.

I have never, ever heard someone saying they forgot their card in the handfuls of European countries where I have been. I have heard complaints about the ATM "eating" the card (not restituting it; this happens sometimes for various reasons). You'd have to try very hard to do it (like take the card out, because otherwise you won't get any cash, and then sticking it back in, or just leaving without taking either cash or card). This just is not a problem.

Re: Swiping left on magnetic stripes

#322
post #320
post #317

Earlier quoted context omitted.

You're correct that you can't easily clone an NFC card from RF interactions alone, but beyond that just about every other aspect of these cards is worse. Most contactless cards can be asked to transmit the cardholder's name, credit card number, and expiration date, and the card will happily do so, wirelessly. This is often enough to make fraudulent online transactions. It's trivially easy to build a device that does…

> You can't clone a NFC card from RF alone You imply that it is possible to clone NFC cards with other means. Is that really possible? Crypto chips are usually hardened against all kinds of attacks, and I would assume that NFC cards are resistant to cloning even if you have physical access to the chip. I'd be curious to learn more about that if my assumption is incorrect. Regarding replay attacks, do you have a sourc…

> You imply that it is possible to clone NFC cards with other means. Is that really possible?

I mean, sure, it's always possible, but probing a secure microcontroller with needles and an electron microscope isn't really what I meant.

I was referring to what the various mobile wallet applications do behind the scenes when they allow you to "import" a plastic card and then use it as a contactless payment source via your phone's NFC radio. They're not actually cloning the private key inside the card, they're using various banking APIs to ask for a new key that, for all intents and purposes, will act exactly like the key on the physical card.

They're supposed to ask for extra info so that they're super ultra sure the person importing the card is the legitimate cardholder, but this is not always very thorough. What kind of info do they typically ask for? Numbers printed on the card that you can acquire wirelessly by accidentally bumping into someone. If you're lucky, they'll try to do two-factor via SMS or email with information that they have on file, but I've seen some that don't bother.

> Regarding replay attacks, do you have a source on that? I would assume that even offline POS terminals would use a nonce to prevent replay attacks. Is that assumption incorrect?

I worked on an EMV contact + contactless implementation several years ago, and at the time contactless replay attacks were easy to demonstrate. Things may have improved since then, but the protocol was not very good (supposedly due to constraints from early NFC cards that were small and anemic), and I think they would need to redo most of it and kill backwards compatibility to mitigate the risk completely.

https://www.youtube.com/watch?v=e023wGfVaE0

https://www.cs.bham.ac.uk/~tpc/Relay/

https://www.hackster.io/news/this-tiny-10-device-can-perform...

https://link.springer.com/chapter/10.1007/978-3-319-39814-3_...

https://en.wikipedia.org/wiki/Contactless_payment#Security

From what I can tell, there was a lot of discourse around these problems around 2015-2018. There were demonstrations and exploits galore. But the standards were already out and none of the banks or card issuers wanted to change anything. Security researchers got bored and moved on. I don't see any evidence that replay and relay attack vectors have been fixed, or that they aren't exploited in the wild, just that the banks seem to consider the risk acceptable.

> And finally, you can extract card holder name and card number from most cards just by looking at them. Claiming that NFC cards are somehow worse than mag stripe cards in that regard is just FUD.

So you'll let me rifle through your wallet and write down the card numbers and expiration dates? Would the average person let me do this? Of course they wouldn't, because basically everybody knows that they need to prevent random people from seeing the various numbers printed on their payment cards.

Is the average person aware that I can capture these markings by "accidentally" bumping into their back pocket on the subway?

It's not FUD, it's a (subtly?) different issue, one that the public largely doesn't understand yet.

What's frustrating about contactless cards is that there isn't even a good solution once you do understand the problem. Metal shields sewn into your wallet only hide the problem. The card will still respond if you shoot enough energy at it, and you'll still be able to pick up the response if you have a sensitive enough receiver.

Re: Swiping left on magnetic stripes

#323
post #35

Earlier quoted context omitted.

The USA is a big holdup. I just traveled across the country and there are still filling (petrol) stations where the only card reader is stripe. See also other comments about the stripe being a fallback for chip as chip readers on POS terminals seem to be more fragile than magnetic stripe readers. FWIW, Contactless is very hit-or-miss for me in the US; about 1/3 the time it just doesn't work at all (even with multiple…

Not just US. Take for example Germany, the largest country in EU and most places are cash-only. Although due to coronavirus adoption of different payment methods (apple pay, contactless, card, etc) has been increasing.

They just have a bit more experience with the government that has too much control over individuals. If cash is gone, govt has complete 100% control.

Re: Swiping left on magnetic stripes

#324

Earlier quoted context omitted.

Define extensively. Anybody who pays with checks in situations where credit cards or cash can be used is gonna get funny looks, unless they’re a little old lady.

The difference is that in Australia literally zero retail businesses will ever accept a cheque under any circumstance and all government payments are made using electronic transfers. I haven't been issued a cheque book from my bank in over decade and I've maybe cashed 3 in my 30+ years alive. I actually can't think of a single place outside of a bank where you can use a cheque and even then it's a challenge to actual…

Somehow those tubes keep $22tn flowing :)

Alas, I’m not sure which tubes you’re referring to. These days, banks use FTP to shuffle bank transfers around.

However, I do think checks have their uses. I’d rather write a check than use cash any day of the week. You can cancel a check, but you can’t cancel cash. Of course, I’d rather pay digitally. But sometimes that’s not an option.

Also: “cashing” a check usually just mean depositing it into your bank account. Not swapping it for cash, although you can do that, too.

Re: Swiping left on magnetic stripes

#325

I'd prefer we just phase out MasterCard. I went to a restaurant the other day. QR code on the receipt. Scan that and it opens up Toast. Toast then connects to Apple Pay, which then connects to my credit card. No less than 3 middlemen to pay the restaurant, is absurd. QRCode -> Wallet on my phone holding stablecoin on a L2 like polygon (which is collecting APY through DeFi) -> Restaurant

I got downvoted, yet we end up with things like this:

https://twitter.com/postcultrev/status/1428584131835748359

Post reply on HN