I'm not sure this is useful for credit cards at all - ever since the deadline for chipped cards to roll out passed, my issuers all decline swipe transactions. Even at middle of nowhere gas pumps that don't have chip readers, I found two during my last cross-country trip, swiping the card will get a decline response.
MagSpoof: Wireless Magstrip Spoofer
91–100 of 105 posts
Re: MagSpoof: Wireless Magstrip Spoofer
#92Earlier quoted context omitted.
But that's what's covered in the article. The "block transaction and require chip and PIN" flag is stored on the magtrack itself.
The bank/processor also knows it and is able to reject any modifications. Whether they do is a matter of their security posture.
Re: MagSpoof: Wireless Magstrip Spoofer
#93I long for the day I can carry my phone or watch without needing keys or wallet. The fact that most adults carry at least 3 things (keys/phone/wallet) at all times in 2022 is crazy.
I agree it would be convenient. But consider the new dangers: 1) pickpocketing would suddenly be 3x as profitable and 3x as easy, 2) lose one thing and you've lost everything, 3) if one thing stops working, everything stops working, 4) venues where you have to give up your phone means carrying extra cash in.... a wallet, 5) cybercriminals can now steal much more from you without ever getting near you, 6) I imagine th…
Re: MagSpoof: Wireless Magstrip Spoofer
#94Earlier quoted context omitted.
It’s a great idea until the battery in your devices fail and you’re stranded somewhere with no ID, no way to communicate, and no money for a train ticket.
Is that any different from losing your wallet in the pre-smartphone era though?
Re: MagSpoof: Wireless Magstrip Spoofer
#95Earlier quoted context omitted.
> An NFC-enabled EMV card will happily reveal its entire account number and expiration date over NFC with no authentication whatsoever. EMV was enabled with the intention of replacing magnetic stripe payments quickly. Together with 3DS on the online payment side, this would have effectively made a card number by itself worthless. Unfortunately this hasn't happend (except for mobile wallets using tokenization like App…
>At merchants not using 3DS, that is true – but these merchants also bear the full liability for any fraud happening As far as I know, the merchant always bears the full liability for fraud, whether you use 3ds or not. The sales pitch for 3ds is simply to reduce the chances of fraud. Also, you do don't even necessarily need the CVV to buy with a cc online. Depends on the merchant.
Re: MagSpoof: Wireless Magstrip Spoofer
#96Earlier quoted context omitted.
I agree it would be convenient. But consider the new dangers: 1) pickpocketing would suddenly be 3x as profitable and 3x as easy, 2) lose one thing and you've lost everything, 3) if one thing stops working, everything stops working, 4) venues where you have to give up your phone means carrying extra cash in.... a wallet, 5) cybercriminals can now steal much more from you without ever getting near you, 6) I imagine th…
I can theoretically leave my home with just my smartphone. I can use it to pay fare at the local train station, get directions to restaurants, read the news, pay for food and coffee, and even lock / unlock my apartment. I do still bring my wallet and keys, because I'd hate to run into a scenario where my phone does get lost, stolen, or damaged, leaving me stranded without a way to get home. But the concept is definit…
Re: MagSpoof: Wireless Magstrip Spoofer
#97Earlier quoted context omitted.
> An NFC-enabled EMV card will happily reveal its entire account number and expiration date over NFC with no authentication whatsoever. EMV was enabled with the intention of replacing magnetic stripe payments quickly. Together with 3DS on the online payment side, this would have effectively made a card number by itself worthless. Unfortunately this hasn't happend (except for mobile wallets using tokenization like App…
>At merchants not using 3DS, that is true – but these merchants also bear the full liability for any fraud happening As far as I know, the merchant always bears the full liability for fraud, whether you use 3ds or not. The sales pitch for 3ds is simply to reduce the chances of fraud. Also, you do don't even necessarily need the CVV to buy with a cc online. Depends on the merchant.
This is very much untrue. If a merchant initiates the 3DS flow, liability for fraudulent transactions shifts from the merchant onto the issuer. Here's documentation from Stripe[1] on the matrix of possible flows and the resulting liability shift, and docs from Adyen[2] on card networks that support liability shifting with 3DS.
[1]: https://support.stripe.com/questions/liability-shift-post-sc...
[2]: https://www.adyen.help/hc/en-us/articles/5091186681500-What-...
Re: MagSpoof: Wireless Magstrip Spoofer
#98Earlier quoted context omitted.
Actually, the merchants are fully responsible for fraudulent charges. So Amex has little incentive to be secure.
It’s not really that simple, and it’s likely that these attacks would fail CVV/3DS/etc, so it’d be hard for a reasonable merchant to be tricked regardless.
Also...ask any merchant if they've ever NOT been left holding the bag for a fraudulent purchase. The only time that happened for me was when I could prove it was fraud by the actual cardholder, and even then, the banks would often deny the counterclaim anyway.
Re: MagSpoof: Wireless Magstrip Spoofer
#99Earlier quoted context omitted.
> 3DSecure is a thing and its job is to prevent this exact situation. 3DSecure ticks all the boxes for what you're not supposed to do. Popup window: check, put in your banking username and password while using a merchant site, not your bank's site: check. I think I've seen a 3dsecure prompt once, maybe twice. I tried to enable it so I could buy fron Aliexpress without calling my card issuer and asking them to turn of…
> 3DSecure ticks all the boxes for what you're not supposed to do If your bank implemented it that way. My 3DSecure prompts just asks for a confirmation code, which is sent via SMS or an app on the phone. No creds.
Re: MagSpoof: Wireless Magstrip Spoofer
#100Earlier quoted context omitted.
In Russia no one swipes their cards, and swiping doesn't work if you try, but the terminals do have the swipe part and the cards do still come with magstripes. There's a separate magstripe reader, usually built into the cashier's monitor, at places that use magstripe cards for loyalty and gift cards.
I'm wondering why they don't use the payment terminal's reader mode for this. I know it can be done – Rimi shops in Baltic states handle both magstripe and NFC loyalty cards through the terminal (just regular Ingenico ICTxxx line terminals, like many shops in Russia use).