3 ms·
How would you “steal” money from a contactless card or a phone?
by m-s 4y ago
How would you “steal” money from a contactless card or a phone?
- RektBoy 4y agoFor example: NFC Proxy?
- __alexs 4y ago1) Gain access to something like a Stripe Terminal (https://stripe.com/gb/terminal https://stripe.com/gb/terminal) You should probably avoid using your real identity here. 2) Type in a charge like $50 3) Discretely wave the device at your targets wallet 4) Repeat steps 2-3 as much as possible in a short amount of time. 5) Hope you can withdraw the funds before anyone notices. I don't think this is a wildly plausible attack and also at least here in the UK your targets card issuer takes 100% liability for fraudulent charges.
- kybernetikos 4y agoThis attack (and some variants of it, e.g. fooling the proximity detection or man in the middle) work because the acknowledgement action that the user does is simply having the device nearby. This seems like a poor choice of acknowledgement action for something that transfers money. Payment devices should probably have a physical or soft button that you have to press to acknowledge payment.
- underdeserver 4y agoStrong disagree. The usability hit is not worth the added security. Having a cutoff for PIN entry requirement and the card issuer taking responsibility for fraud means customers are quite safe (as long as they look at their charges).
- samhw 4y agoYou could do something like "you need to be physically holding the card with your hand", which would complete some circuit. I can't think of many cases where that wouldn't work, except perhaps people who don't take their cards out of their wallets(?).
- kybernetikos 4y agoWork could be done to make it more usable. With a phone, it could be a button you could press just by holding it. With a smart watch, it could be hooked into any kind of bluetooth sensor. The point is that in normal society, you don't have that much control over who and what gets into proximity with you, and having a system where anything that does get into proximity can take money from you without you even acknowledging that in any way is just a bad way of doing things.
- alonsonic 4y ago> 1) Gain access to something like a Stripe Terminal (https://stripe.com/gb/terminal https://stripe.com/gb/terminal) Getting a payments terminal is not easy, this would requires ID verification and working business bank account (acquirer), this terminals are highly regulated. Someone doing this can get caught easily by just a couple of customers reporting the fraudulent transactions. This is very small risk and is rarely seen.
- rusticpenn 4y agoMost new wallets ac as faraday cages.
- yencabulator 4y ago> 3) Discretely wave the device at your targets wallet Phone payments generally require the phone to be unlocked. Also, it's a credit card transaction: the user will complain later, attacker will get into legal trouble, and user will be refunded fully.