Live data from Hacker News

Ultrasonic Payments

charliegerard.dev

51–60 of 95 posts

Re: Ultrasonic Payments

#51

LISNR is the leader in Ultrasonic Data Transfer, including payment data. https://LISNR.com *full disclosure I worked there 2019 - 2020

I came here to say that this is not exactly new and point to LISNR, although I was not exactly impressed by the payment use case the LISNR tech is pretty cool.

Re: Ultrasonic Payments

#52
post #50

I will say this is a cool project. However, the implementation of the idea in reality is even worse than NFC. While NFC is useful in many contexts, it then requires you to put a faraday cage around your card and manually turn on or off the NFC to not get your money stolen, and even then can be circumvented. Even further relaxing the distance constraints even makes it even easier to steal money. I'd imagine a lot of t…

Cool technology, bad problem. I fully agree getting more distance is problematic. Not even in the sense of getting your data stolen, but also to allow pro active payment. I mean you want the customer to do an action (holding the card close to a device which shows the amount deducted) to conclusively agree to that payment. Not the cashier presses a button, and anybody too close pays for it.

modem/phone couplers, anyone?

Re: Ultrasonic Payments

#53

I will say this is a cool project. However, the implementation of the idea in reality is even worse than NFC. While NFC is useful in many contexts, it then requires you to put a faraday cage around your card and manually turn on or off the NFC to not get your money stolen, and even then can be circumvented. Even further relaxing the distance constraints even makes it even easier to steal money. I'd imagine a lot of t…

How would you “steal” money from a contactless card or a phone?

Re: Ultrasonic Payments

#54

Earlier quoted context omitted.

I remember back in the time, during the eighties, one of the radio stations broadcasted ZX-Spectrum games over the air. You would record that noise to a tape, and later you could load to your ZX and play. It worked remarkably good.

Generally datasette formats were meant to work with the extremely lossy media of tape. Also, I'm not sure but telephone audio tends to be much more compressed compared to radio. That on top of the fact you are going from earpiece to mic with an air gap and the background noise, it's probably much much worse.

Regular telephone audio is usually filtered 0.3-3.4 kHz (this on analog phone lines). Digital phone lines use PCM with A-law (or µ-law in the US and some other places) logarithmic sample encoding, with 8 kHz sampling rate, getting more or less the same result of an analog phone line, possibly with less distortion. FM radio has much higher bandwidth, usually up to around 15 kHz and with better basses too.

Re: Ultrasonic Payments

#55
post #50

Earlier quoted context omitted.

Cool technology, bad problem. I fully agree getting more distance is problematic. Not even in the sense of getting your data stolen, but also to allow pro active payment. I mean you want the customer to do an action (holding the card close to a device which shows the amount deducted) to conclusively agree to that payment. Not the cashier presses a button, and anybody too close pays for it.

modem/phone couplers, anyone?

Phone carriers cut off the frequency spectrum.

Re: Ultrasonic Payments

#57

Earlier quoted context omitted.

I also have a cochlear implant; it doesn't allow me to hear ultrasonic frequencies -- in fact, my hearing range is still a subset of "normal."

I have one as well, and I've noticed that area proximity detectors (in hallways used to detect presence/motion) do get picked up and come through as loud pops.

There are also electricity poles with a strong EM field that cause a humming sound.

Re: Ultrasonic Payments

#58
post #53

I will say this is a cool project. However, the implementation of the idea in reality is even worse than NFC. While NFC is useful in many contexts, it then requires you to put a faraday cage around your card and manually turn on or off the NFC to not get your money stolen, and even then can be circumvented. Even further relaxing the distance constraints even makes it even easier to steal money. I'd imagine a lot of t…

How would you “steal” money from a contactless card or a phone?

For example: NFC Proxy?

Re: Ultrasonic Payments

#59

I'm reminded of Google Tone[0], which beamed URLs audibly to nearby browsers in an Airdrop-style experience. A neat trick, but ultimately useless given that most devices have less obtrusive ways of sharing data P2P. The ultrasonic aspect of this experiment makes the technology a lot more useful. Tone also came with the unfortunate side effect of Google software having constant access to your microphone. 0: https://ch…

> Tone also came with the unfortunate side effect of Google software having constant access to your microphone.

In today's world, most phones or "smart" devices are also constantly listening; I want to believe they don't listen until the trigger phrase is uttered, which could also be implemented for these ultrasonic applications, but I'm not entirely convinced and them always listening is but a silent over-the-air update or setting change away.

Re: Ultrasonic Payments

#60
post #53

I will say this is a cool project. However, the implementation of the idea in reality is even worse than NFC. While NFC is useful in many contexts, it then requires you to put a faraday cage around your card and manually turn on or off the NFC to not get your money stolen, and even then can be circumvented. Even further relaxing the distance constraints even makes it even easier to steal money. I'd imagine a lot of t…

How would you “steal” money from a contactless card or a phone?

1) Gain access to something like a Stripe Terminal (https://stripe.com/gb/terminal) You should probably avoid using your real identity here.

2) Type in a charge like $50

3) Discretely wave the device at your targets wallet

4) Repeat steps 2-3 as much as possible in a short amount of time.

5) Hope you can withdraw the funds before anyone notices.

I don't think this is a wildly plausible attack and also at least here in the UK your targets card issuer takes 100% liability for fraudulent charges.

Post reply on HN