Jump to content

Recommended Posts

Posted (edited)
You can steal the card details at the train station or a shop queue, but as soon as they tap the card on the barriers or point-of-sale the information gleaned from the card becomes useless.

Still entirely feasible if card clones are made immediately elsewhere by a second party. There's no reason that wouldn't work. Far more time consuming scams have been put in place. In fact, I don't see why the details couldn't be transmitted to a remote machine and the rest be done automatically (although that would cost more than getting a second dude to help, since a physical copy has to be made, you'd need an Emmett Brown-style machination to scan the cards)

 

Also I'm having a bit of trouble getting my head around this one-time CVV.

 

Bad guy scans the card, card gives out deetz and CVV. Criminal uses CVV to authorise payment of $SomeAmount

Guy then goes to shop and uses card to buy something. Card issues CVV to PoS terminal. Right?

 

But the device the bad guy is using identifies as a PoS terminal. So why would the card not issue a different CVV (and thus the transactions would still be 'in order' and not raise a red flag) because as far as the card 'knows', the previous scan (bad guy's scanner) was a legitimate transaction.

Edited by Garacesh
Posted

Ok but then the bad guy can only use those card details once and has to use his clone before the card is used again by the owner otherwise the cvv would be in the wrong order and for a maximum of £20 per card it's not worth the hassle.

 

Still much more lucrative to suck up mag stripe details and encode them on to cards abroad.

 

Ben

Posted (edited)

CVVs won't be in numerical order, I am doing them incrementally for clarity:

 

Bad guy obtains a read from the NFC chip with intent to clone card, CVV issued (001).

Customer uses card for legitimate transaction, CVV issued (002).

Bad guy uses card fraudulently, CVV from compromised details given to payment provider is 001.

Anti-fraud system realises CVV 001 is being used after CVV 002. The card is marked as compromised and blocked because the CVV numbers are not being used in the right order.

 

This prevents details from being captured for later fraudulent use. Regarding payment there and then, already covered earlier. It'd be impractical.

Edited by CAM
Posted
Ok but then the bad guy can only use those card details once and has to use his clone before the card is used again by the owner otherwise the cvv would be in the wrong order and for a maximum of £20 per card it's not worth the hassle.

 

Still much more lucrative to suck up mag stripe details and encode them on to cards abroad.

 

Unless you're a criminal who doesn't have a passport :p Even if you do, travel records can help tie you to the crime.

 

I'm not being massively paranoid, I'm just saying that if the details were transmitted to a third party they could easily clone the card and use it in time. Bumping into people on the high street would give enough time. Maybe not at a train station where contactless is used to get through barriers, or if they were in a queue to buy something in a shop. But there are still many situations where this would be possible.

 

They can only use it once, sure, but this is scalable and just means they have to increase the amount of marks rather than the amount of cash. (Risk goes up, admittedly)

Plus, given it's small amounts, people may not even notice if they don't regularly check their statement (which is still too many people, to be honest.)

 

It's not a massive risk. It's not a "writing your PIN on your card in permanent marker" sized hole. But it's still possible, and the banks saying it isn't is just stupid.

Posted (edited)

You would need to clone the card there and then for a single use for a tiny sum in a small timeframe and no guarantee it'd work. A shopkeeper is unlikely to accept anything but a legitimate looking credit card, certainly not a dodgy box with some wires and an antenna!

 

Also the stuff being purchased would hardly be saleable at £20 after buying it. Some cigarettes, a beer and some snacks? The thief would get less then £20 plus a load of effort obtaining it and selling the useless stuff on.

Edited by CAM
Posted
Ive only used it once or twice

 

If more shops had it where I lived then id use it more.

 

Yeh it just seems to have exploded in popularity recently around here which is why I mentioned it.

 

I've used it in:

 

Marks and Spencers

Aldi

McDonalds

Local Pub

Subway

Burrito place I get my lunch in on a Friday

 

Pretty much all I need haha.

 

I've actually found myself shopping in M&S and Aldi more because sainsburys don't accept it yet.

Posted
You would need to clone the card there and then for a single use for a tiny sum in a small timeframe and no guarantee it'd work. A shopkeeper is unlikely to accept anything but a legitimate looking credit card, certainly not a dodgy box with some wires and an antenna!

 

Also the stuff being purchased would hardly be saleable at £20 after buying it. Some cigarettes, a beer and some snacks? The thief would get less then £20 plus a load of effort obtaining it and selling the useless stuff on.

 

Didn't the article say she 'received the money via an attachment to her phone'? In this scenario, the thieves aren't buying some smokes and a burger, they're transferring actual cash.

Posted
Which in turn is payment processing which will tie any fraudulent activity to your name and address, maybe even your phone? It comes back to leaving that note in the victim's wallet. Card skimming on the other hand would be safer as it won't directly tie back to your details. :)
Posted

Well, yeah, but they've probably bought a stolen account/identity for that, and just head to an ATM to withdraw the monies later on.

 

I'm still not arguing it would be lucrative and worthwhile for someone to do. Just that the banks saying "lol not possible, don't worry." is a wee bit on the daft side. Because it completely is possible.

 

Personally, I'll stick to Chip&Pin for the same reason I use strong passwords instead of 'Password1'. It all boils down to security. Plus I personally think you look like bit of a buffoon when you use contactless payment :p but maybe that's because the people I've seen use it seem to try and look 'flashy' and show off.

Posted
and for all those who's banks are still in the 1990s (glares at Natwest who want me to call them up and request a new one grr) you can get one of these - https://www.bpayband.co.uk and then set auto-topup and off you go :)

 

Ooh, those look kinda cool. Probably won't get one, but an interesting concept if you're heavily investing in contactless.

Posted (edited)

I have started using CP on the London buses and in shops which have them. Much quicker, don't even have to get the card out of my wallet. Oyster can be ditched soon once they work on the tube.

 

However i would not use the mobile phone version. or this Apple pay when it comes out.

 

One day there is going to be a massive server hack.

Edited by Alkaline

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...