Contactless card transactions always struck me as bonkers. By the very nature of the system, there is nothing stopping an individual walking down the street and stealing whatever the cap is out of everyone's card.
You then immediately use this "money" to buy gift cards, which you then sell on, turning the dirty money into clean money. By the time they have traced back the money to the gift card, you're long gone (you can also cross international borders a couple of times to make things difficult/slow).
The fact banks shut down the Mythbusters' investigation into just how insecure contactless cards are really tells you everything you need to know. They know full well they are completely insecure, and they want to keep it hush hush.
Now contactless phone transactions are secure, but contactless phone transactions require action from the user to confirm the transaction. If the plastic cards had you press a button to activate contactless-mode they would be fine too, but they don't...
NFC is great technology that has a lot of uses. This is just a mis-use.
Well with contactless payments a unique CVV is generated by the card for every transaction. The attacker would have to steal the card info, CVV, and use it to purchase something before the victim uses their card again or the card will automatically be disabled by the payment processor. In any case they can only make a fraudulent purchase once for every time they trick the card. That's certainly better than the current situation where once your card is compromised you are screwed.
You've somewhat misrepresented how this works. You can't steal money "out of everyone's card". The card doesn't contain any money, it's not a digital wallet. It's an authorization mechanism.
You could certainly skim authorization codes out of everyone's pockets, but you still have to present those codes (and fairly swiftly) to the payment processing networks for clearing. That means you need a merchant account, which means someone is on the hook for your activity and the fraud has some chance of being detected and sourced.
"Some chance", but if the amounts are small enough, who is going to notice? And if it's an international payment, I'm sure that will make it that much harder too.
Aren't you insured against that? I know that we are in Quebec. That's why I love my credit card so much. It's not my cash, I don't care what happen to it. If it's stolen, I have literally nothing to pay. It's true physically, through a contactless payment or a transaction on the web.
I like your idea of button though, it wouldn't be too intrusive and it would limit some case.
"legitimate" as in "actual fraud", as opposed to "fraudulent fraud" (e.g. reporting your card stolen after a big purchase and then claiming the charge was not yours)
On a packed street, have something to debit it in your pocket. You'll probably be within that distance of enough wallets to get enough to be worthwhile…
That is eavesdropping a transaction, not soliciting one. Plus every NFC transaction generates a new token. Even if you record it as the transaction takes place, that information cannot be used again.
I assume the protocol is designed such that you cannot record a response and then replay it later. If that's true (and I could be way too optimistic here) then an attack like that would require two confederates and some communications hardware, with one guy on the street scanning people's cards at the exact same time as the other guy presents his end of the equipment to the local point of sale. This is all doable, but it doesn't scale too well.
Comments
Contactless card transactions always struck me as bonkers. By the very nature of the system, there is nothing stopping an individual walking down the street and stealing whatever the cap is out of everyone's card.
You then immediately use this "money" to buy gift cards, which you then sell on, turning the dirty money into clean money. By the time they have traced back the money to the gift card, you're long gone (you can also cross international borders a couple of times to make things difficult/slow).
The fact banks shut down the Mythbusters' investigation into just how insecure contactless cards are really tells you everything you need to know. They know full well they are completely insecure, and they want to keep it hush hush.
Now contactless phone transactions are secure, but contactless phone transactions require action from the user to confirm the transaction. If the plastic cards had you press a button to activate contactless-mode they would be fine too, but they don't...
NFC is great technology that has a lot of uses. This is just a mis-use.
For anyone wondering about the incident with the Mythbusters and banks, here's some context by Adam Savage : https://www.youtube.com/watch?v=-St_ltH90Oc
Well with contactless payments a unique CVV is generated by the card for every transaction. The attacker would have to steal the card info, CVV, and use it to purchase something before the victim uses their card again or the card will automatically be disabled by the payment processor. In any case they can only make a fraudulent purchase once for every time they trick the card. That's certainly better than the current situation where once your card is compromised you are screwed.
Sources:
research - https://www.shmoocon.org/2012/presentations/Paget_shmoocon20...
presentation - https://www.youtube.com/watch?v=HRXb-FZ6WFM
summary - http://www.forbes.com/sites/andygreenberg/2012/01/30/hackers...
You've somewhat misrepresented how this works. You can't steal money "out of everyone's card". The card doesn't contain any money, it's not a digital wallet. It's an authorization mechanism. You could certainly skim authorization codes out of everyone's pockets, but you still have to present those codes (and fairly swiftly) to the payment processing networks for clearing. That means you need a merchant account, which means someone is on the hook for your activity and the fraud has some chance of being detected and sourced.
"Some chance", but if the amounts are small enough, who is going to notice? And if it's an international payment, I'm sure that will make it that much harder too.
Aren't you insured against that? I know that we are in Quebec. That's why I love my credit card so much. It's not my cash, I don't care what happen to it. If it's stolen, I have literally nothing to pay. It's true physically, through a contactless payment or a transaction on the web.
I like your idea of button though, it wouldn't be too intrusive and it would limit some case.
You are correct, Credit Card users are not liable for legitimate fraud. About half of the credit card fees charged to merchants is to cover fraud.
When is fraud "legitimate"? Legitimate fraud sounds a lot like a contradiction.
"legitimate" as in "actual fraud", as opposed to "fraudulent fraud" (e.g. reporting your card stolen after a big purchase and then claiming the charge was not yours)
The limited scan range is the main security. 2-6 cm is what I see quoted.
On a packed street, have something to debit it in your pocket. You'll probably be within that distance of enough wallets to get enough to be worthwhile…
Man, am I glad my bank passes are in a metal container that blocks NFC. Looks like that may have to become standard for wallets in the near future.
Hmmm: http://www.bbc.com/news/technology-24743920
That is eavesdropping a transaction, not soliciting one. Plus every NFC transaction generates a new token. Even if you record it as the transaction takes place, that information cannot be used again.
Although that does sound like it's eavesdropping on the transaction, rather than picking up the card in your pocket.
I assume the protocol is designed such that you cannot record a response and then replay it later. If that's true (and I could be way too optimistic here) then an attack like that would require two confederates and some communications hardware, with one guy on the street scanning people's cards at the exact same time as the other guy presents his end of the equipment to the local point of sale. This is all doable, but it doesn't scale too well.