The Register® — Biting the hand that feeds IT

Feeds

Stealing credit card details via NFC is easy/pointless

That might just be a netbook in his pocket

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

A US TV station has demonstrated how easy it is to lift credit card details from proximity-payment cards, though in the process showing just how pointless the activity is.

The video does a nice job of demonstrating just how close you have to be to read a card, which are induction-powered so have very limited range; you needn't worry about the chap walking behind you, but tube travellers might be concerned about the one pressed against them... But with typical hyperbole, the channel fails to point out the limited risk such reading presents.

 

The attacker is shown reading the card number and expiry date, which the presenter interprets to mean that 140 million credit card users are at risk, and goes on to ask why the credit card companies aren't doing anything about it.

The reason, of course, is that the risk isn't significant, at least not yet. Remote readers can't pick up the CCV code, which is on the back of the card (the three digits on the signature strip), or the card holder's address – both of which will be required for any online transaction.

So could sniffing the card allow the criminal to create a clone of the card sniffed, then use it at a contactless pay point? Probably, though it would be difficult and not risk-free for the criminal – proximity payments are only used for small-value transactions, and will ask for a PIN at random (which the criminal won't have) as well as leaving a detailed paper trail. Such a card would only work for offline payments, where no challenge-response mechanism is used, and while such things are permitted by the standards, their use could easily be reduced if it became a problem.

So if you notice the stranger behind you shuffling too close, they're more likely trying to cop a feel than to wirelessly pick your pocket: there are a lot more perverts than technically-proficient thieves prepared to go so far for the price of a cup of coffee. ®

Agentless Backup is Not a Myth

Anonymous Coward

and the benefits over cash are?

I keep asking this question but no-one seems to have an answer;-

If i use the nearest of near field comms;- contact through putting coins in the shopkeep's hand then i do not need to be concerned about skimming in my pocket. Problem solved by keeping it simple, stupid.

No one seems to have done a cost benefit analysis on NFC or why i need it.

13
2

NFC Scanning is pointless?

Surely if an NFC card can be used to make payments then a payment can be sucked out of it by the bloke next to you in the tube... They said Chip&Pin couldn't be hacked only to be proven wrong.

Obvious methods are:

1) Copy details from as many cards as possible and process them en-masse through a broken/modified NFC till, small amount x many transactions = big number.

2) Duplicate cards and sell them 'in the pub' - punter beware but seller long since gone.

Sounds like tech best avoided!

11
0

@Advantages over cash

@Advantages over cash

It's not 1% free cash, it's 1% extra charged to the merchant who in turn has to increase his prices by at least 1%. The reality is you're paying more than you get back and forfeiting some of your freedom of choice and privacy in the process.

7
0

More from The Register

 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
'BadNews is malware' says outfit that found it
Google says code harmless but Lookout says code base is evolving
Panda-peddlers cuffed for chess gambling gambit
More porridge on the menu for Chinese coders after second offence