LosOjos Posted September 12, 2014 Posted September 12, 2014 Paget's demonstration is a lab test and the article says why your theory of tap-to-clone cards won't work: :doh:
Garacesh Posted September 12, 2014 Posted September 12, 2014 (edited) You can steal the card details at the train station or a shop queue, but as soon as they tap the card on the barriers or point-of-sale the information gleaned from the card becomes useless. Still entirely feasible if card clones are made immediately elsewhere by a second party. There's no reason that wouldn't work. Far more time consuming scams have been put in place. In fact, I don't see why the details couldn't be transmitted to a remote machine and the rest be done automatically (although that would cost more than getting a second dude to help, since a physical copy has to be made, you'd need an Emmett Brown-style machination to scan the cards) Also I'm having a bit of trouble getting my head around this one-time CVV. Bad guy scans the card, card gives out deetz and CVV. Criminal uses CVV to authorise payment of $SomeAmount Guy then goes to shop and uses card to buy something. Card issues CVV to PoS terminal. Right? But the device the bad guy is using identifies as a PoS terminal. So why would the card not issue a different CVV (and thus the transactions would still be 'in order' and not raise a red flag) because as far as the card 'knows', the previous scan (bad guy's scanner) was a legitimate transaction. Edited September 12, 2014 by Garacesh
hardtailstar Posted September 12, 2014 Posted September 12, 2014 Ive only used it once or twice If more shops had it where I lived then id use it more.
plexer Posted September 12, 2014 Posted September 12, 2014 Ok but then the bad guy can only use those card details once and has to use his clone before the card is used again by the owner otherwise the cvv would be in the wrong order and for a maximum of £20 per card it's not worth the hassle. Still much more lucrative to suck up mag stripe details and encode them on to cards abroad. Ben
CAM Posted September 12, 2014 Posted September 12, 2014 (edited) CVVs won't be in numerical order, I am doing them incrementally for clarity: Bad guy obtains a read from the NFC chip with intent to clone card, CVV issued (001). Customer uses card for legitimate transaction, CVV issued (002). Bad guy uses card fraudulently, CVV from compromised details given to payment provider is 001. Anti-fraud system realises CVV 001 is being used after CVV 002. The card is marked as compromised and blocked because the CVV numbers are not being used in the right order. This prevents details from being captured for later fraudulent use. Regarding payment there and then, already covered earlier. It'd be impractical. Edited September 12, 2014 by CAM
Garacesh Posted September 12, 2014 Posted September 12, 2014 Ok but then the bad guy can only use those card details once and has to use his clone before the card is used again by the owner otherwise the cvv would be in the wrong order and for a maximum of £20 per card it's not worth the hassle. Still much more lucrative to suck up mag stripe details and encode them on to cards abroad. Unless you're a criminal who doesn't have a passport Even if you do, travel records can help tie you to the crime. I'm not being massively paranoid, I'm just saying that if the details were transmitted to a third party they could easily clone the card and use it in time. Bumping into people on the high street would give enough time. Maybe not at a train station where contactless is used to get through barriers, or if they were in a queue to buy something in a shop. But there are still many situations where this would be possible. They can only use it once, sure, but this is scalable and just means they have to increase the amount of marks rather than the amount of cash. (Risk goes up, admittedly) Plus, given it's small amounts, people may not even notice if they don't regularly check their statement (which is still too many people, to be honest.) It's not a massive risk. It's not a "writing your PIN on your card in permanent marker" sized hole. But it's still possible, and the banks saying it isn't is just stupid.
CAM Posted September 12, 2014 Posted September 12, 2014 (edited) You would need to clone the card there and then for a single use for a tiny sum in a small timeframe and no guarantee it'd work. A shopkeeper is unlikely to accept anything but a legitimate looking credit card, certainly not a dodgy box with some wires and an antenna! Also the stuff being purchased would hardly be saleable at £20 after buying it. Some cigarettes, a beer and some snacks? The thief would get less then £20 plus a load of effort obtaining it and selling the useless stuff on. Edited September 12, 2014 by CAM
zag Posted September 12, 2014 Author Posted September 12, 2014 Ive only used it once or twice If more shops had it where I lived then id use it more. Yeh it just seems to have exploded in popularity recently around here which is why I mentioned it. I've used it in: Marks and Spencers Aldi McDonalds Local Pub Subway Burrito place I get my lunch in on a Friday Pretty much all I need haha. I've actually found myself shopping in M&S and Aldi more because sainsburys don't accept it yet.
Garacesh Posted September 12, 2014 Posted September 12, 2014 You would need to clone the card there and then for a single use for a tiny sum in a small timeframe and no guarantee it'd work. A shopkeeper is unlikely to accept anything but a legitimate looking credit card, certainly not a dodgy box with some wires and an antenna! Also the stuff being purchased would hardly be saleable at £20 after buying it. Some cigarettes, a beer and some snacks? The thief would get less then £20 plus a load of effort obtaining it and selling the useless stuff on. Didn't the article say she 'received the money via an attachment to her phone'? In this scenario, the thieves aren't buying some smokes and a burger, they're transferring actual cash.
CAM Posted September 12, 2014 Posted September 12, 2014 Which in turn is payment processing which will tie any fraudulent activity to your name and address, maybe even your phone? It comes back to leaving that note in the victim's wallet. Card skimming on the other hand would be safer as it won't directly tie back to your details.
Garacesh Posted September 12, 2014 Posted September 12, 2014 Well, yeah, but they've probably bought a stolen account/identity for that, and just head to an ATM to withdraw the monies later on. I'm still not arguing it would be lucrative and worthwhile for someone to do. Just that the banks saying "lol not possible, don't worry." is a wee bit on the daft side. Because it completely is possible. Personally, I'll stick to Chip&Pin for the same reason I use strong passwords instead of 'Password1'. It all boils down to security. Plus I personally think you look like bit of a buffoon when you use contactless payment but maybe that's because the people I've seen use it seem to try and look 'flashy' and show off.
john Posted September 12, 2014 Posted September 12, 2014 and for all those who's banks are still in the 1990s (glares at Natwest who want me to call them up and request a new one grr) you can get one of these - https://www.bpayband.co.uk and then set auto-topup and off you go
Garacesh Posted September 12, 2014 Posted September 12, 2014 and for all those who's banks are still in the 1990s (glares at Natwest who want me to call them up and request a new one grr) you can get one of these - https://www.bpayband.co.uk and then set auto-topup and off you go Ooh, those look kinda cool. Probably won't get one, but an interesting concept if you're heavily investing in contactless.
plexer Posted September 12, 2014 Posted September 12, 2014 hmmm you can't sign up for one for either of the events listed and they expire in June 2015 looks like a marketing gimmick for some events? Ben
Alkaline Posted September 12, 2014 Posted September 12, 2014 (edited) I have started using CP on the London buses and in shops which have them. Much quicker, don't even have to get the card out of my wallet. Oyster can be ditched soon once they work on the tube. However i would not use the mobile phone version. or this Apple pay when it comes out. One day there is going to be a massive server hack. Edited September 12, 2014 by Alkaline
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now