8 ms·
An Android app that collects Mag-Stripe data and CVC3 codes from PayPass cards
- techinsidr 12y agoHas anyone tried to verify this?
- ZaneA 12y agoWorking for me, Nexus 5 with Visa Paywave Edit: Reading that is...
- voltagex_ 12y agoWorks for me too - Nexus 5, MasterCard PayPass. The app in its current form isn't dangerous, it takes ~2 minutes to read the card and if the screen goes off or the reader loses contact you have to start again.
- ZaneA 12y agoThough as I understand from the source this also acts as an emulator, so if you scan your phone it may replay those card details, worth keeping in mind.
- voltagex_ 12y agoI'd love this. My bank wants me to pay $2.99 for a sticker to go on the back of my phone (to do contactless purchases) while supporting Galaxy S* phones natively...
- cbhl 12y agoGoogle Wallet's "Tap and Pay" works with select phones in the US: https://support.google.com/wallet/answer/1347934?hl=en https://support.google.com/wallet/answer/1347934?hl=en You might also be interested in Coin: https://onlycoin.com/ https://onlycoin.com/
- jackvalentine 12y agoSounds to me like his bank is the Commonwealth Bank of Australia(1), so Google Wallet is a non-starter. Coin is interesting, but the payments landscape in .au is rapidly moving away from card swipes to Paywave/Paypass. I've seen quite a few places that offer Cash or Tap, no swipe (I presume because of the fee structure). 1) https://www.commbank.com.au/paytag https://www.commbank.com.au/paytag
- XorNot 12y agoCommonwealth Bank charge $2.99 a year regardless of what you want to do. To use their Android app, they also bill you that to have the functionality turned on.
- oxplot 12y agoThe annual fee is not applicable in case of the PayTag (https://www.commbank.com.au/personal/can/can-tap.html https://www.commbank.com.au/personal/can/can-tap.html). Also, can you refer me to the doc that mentions the extra cost of using the Android app for that purpose?
- XorNot 12y agoThe Android app itself says it (I have it open right here).
- voltagex_ 12y agoCorrect!
- deleted 12y ago[deleted]
- deleted 12y ago[deleted]
- tonteldoos 12y agoI'll try using my phone to buy coffee tomorrow, and let you know how it goes ;) (Aus, big four bank, not Commbank...)
- tonteldoos 12y agoDoesn't this make it an impractical attack in most situations? I've never thought that buying RF shielding cases is of much use for 99% of situations, and this seems to support that theory. Or should I rush out tomorrow and get one? (Australia, so yep, all of them are paywave, whether you want them or not).
- christop 12y agoThat sounds very odd; I compiled the app mentioned here and it took more like 200ms to read the info from my UK contactless VISA card. But this whole attack isn't anything new — this was pretty widely reported back in 2012 in the UK, e.g. http://www.channel4.com/news/millions-of-barclays-card-users-exposed-to-fraud http://www.channel4.com/news/millions-of-barclays-card-users... I wrote essentially the same proof of concept app two years ago after seeing that report pretty much just by reading the specs. From reading the paper mentioned on GitHub, the only real difference to what I wrote is that I didn't check for the CVC3 information (which I think is generally not included, or doesn't correspond to the actual security code on the back of the card). But in any case, just the card number and expiry number are enough — as mentioned in the Channel 4 report — to make purchases from a lot of places.
- blincoln 12y agoIf CVC3 is anything like CVV and CVV2, it's probably intentionally different than what's on the back of the card. Mag-stripe VISA cards have a three-digit code embedded in the stripe (this is the CVV), and a different three-digit code on the back of the card (the CVV2). Different brands of cards use the same model, but they don't always call them CVV/CVV2, and the number of digits may be different. The numbers are different so that use of the card is a magnetic reader can be differentiated from someone typing it in.
- marcosscriven 12y agoI have PayWave too - can you explain why reading would work, but not actually using it to pay for things with your phone?
- ZaneA 12y agoIt may work, just haven't had the opportunity to try it out :)
- deckar01 12y ago- [Turn on NFC](https://github.com/MatusKysel/EMVemulator/blob/master/src/com/kysel/EMVemulator/MainActivity.java#L44 https://github.com/MatusKysel/EMVemulator/blob/master/src/co...) - [Dump card into Downloads](https://github.com/MatusKysel/EMVemulator/blob/master/src/com/kysel/EMVemulator/MainActivity.java#L125 https://github.com/MatusKysel/EMVemulator/blob/master/src/co...) - [Read card from Downloads](https://github.com/MatusKysel/EMVemulator/blob/master/src/com/kysel/EMVemulator/MyHostApduService.java#L78 https://github.com/MatusKysel/EMVemulator/blob/master/src/co...) - [Respond to NFC requests](https://github.com/MatusKysel/EMVemulator/blob/master/src/com/kysel/EMVemulator/MyHostApduService.java#L27 https://github.com/MatusKysel/EMVemulator/blob/master/src/co...)
- bloopletech 12y agoI just tried this. Card: NAB Visa (payWave). Handset: Nexus 5. Merchant: 7-11. The app read the card correctly and gave the card number and expiry. When I tried to use it in store the eftpos terminal returned roughly: Err 226 contactless card not allowed. The terminal fell back to swipe/insert mode and the merchant told me 'contactless not allowed'. Inserted the (same) card and paid successfully. I was disappointed because for me, being able to carry just mmy phone for day to day would be awesome, and NAB has no phone solution yet.
- mappu 12y agoShould be worryingly easy to piggyback this onto popular android apps. Good time to start keeping your phone and wallet in separate pockets...
- voltagex_ 12y agoI use XPrivacy. I realise that's out of reach for most users but it's been very very useful for me to allow/deny use of NFC/GPS/connectivity. (Yes I know about the new bypass trick)
- zmanian 12y agoIt would be great to see something that does what Firesheep did for SSL in payment security.
- deleted 12y ago[deleted]
- dmix 12y agoThis is why people should invest in an RF-blocking cellphone case for when you're in public, for example: http://silent-pocket.com/ http://silent-pocket.com/ http://www.amazon.com/HideCell-Cell-Protection-Bag-Standard/dp/B00GSZI24M/ http://www.amazon.com/HideCell-Cell-Protection-Bag-Standard/... This is the only thing that can really stop wireless snooping. Even pervasive location tracking.
- lstamour 12y agoI've used Umbra's Bungee Card holders for years now, RF-protection is just an added bonus: http://www.umbra.com/usd/catalogsearch/result/?q=bungee http://www.umbra.com/usd/catalogsearch/result/?q=bungee I haven't tested it, but it's better than nothing, right? And much cheaper. I've a few cards, so I bought two (different colors). For those also in Toronto, you can pick them up at the Umbra showroom off Queen and John. For everyone else, there's Amazon, local stores... That said, when I looked at this project, I saw it as something I wanted -- not for fraud, for personal convenience. I'm sick of carrying so many cards. I was like, crap, I only have Visa in my wallet, I wonder how hard it'd be to add PayWave support? Right now my hopes lie in rumoured iPhone 6 support of NFC which might in turn encourage global adoption of phones for payment ... and perhaps with one-time credit card numbers, right? One can dream...
- dmix 12y agoSilentPocket-style cases also blocks wifi/3G/4G, it's much better privacy than simply blocking RFID/NFC. Preventing pervasive monitoring of cell phones is their target.
- lstamour 12y agoYes, but I like receiving phone calls ;-) I do understand though -- they look nicer too.
- oxplot 12y agoThe transmission power of your phone is adjusted based on how well your phone can talk to the cell tower. The harder you make it for the phone, the harder it tries. That translates into a sizzling hot phone in your pocket that has a battery life of one hour.
- withinthreshold 12y agoOk, I am a complete noob in this regard. I have a VISA Gold card with a chip and payWave, what should I do to protect myself from this?
- lstamour 12y agoFirst, this doesn't affect PayWave yet, just PayPass. But to continue: (1) Don't put your phone in the same pocket as your card, (2) Get either a metal or protected wallet for NFC-enabled cards, (3) Review card usage and don't worry about it. You aren't responsible for card fraud with credit cards. The chances of this being used against you are incredibly slim. It's also less useful as an avenue to commit fraud since payment with NFC is usually limited to under $25 by merchant agreements. Besides, duplicated cards are old hat, what with programmable chips and magnetic strips already. What's neat here is the proof-of-concept demo involving phones without the need for specialized SIM cards or approved phone handsets. Not 100% sure myself, but maybe it only works because PayPass allows for stickers on your phone case to emulate a credit card? Oh and if you go to pay for something on a website and enter your 3-digit code plus the card number, well, spyware could have your card already. So NFC as an attack vector is slower and less useful. Watch out for those custom keyboards ;-)
- deleted 12y ago[deleted]
- marcosscriven 12y agoI'm not clear from your comment whether HCE means I could in fact use it for PayWave (rather than just PayPass), despite the title? Would it work with Opal too for instance?
- deleted 12y ago[deleted]
- tonteldoos 12y agoI haven't tried myself (I have PayWave, and this is now on my todo list for tomorrow), but I imagine that they maybe hadn't tested it on Paywave when they wrote the title? The standard(s) seem pretty pervasive, and I've often had PayWave work where there is only a PayPass sign... On your last question - I'm not familiar with Opal at all. Any links/information?
- georgebarnett 12y agoOne workaround (instead of buying an rf shielded wallet) I've heard of in the past is to put two cards next to each other because it causes signal interference. I have no idea if it works (I use an iphone) so ymmv.
- praseodym 12y agoActually some RFID card standards (Mifare for example) have card selection and anti collision built in, so it would still be possible to read the correct card without interference.
- ikari_pl 12y agoIt works perfectly with my cards. I can't open the office door if my paypass is too close. My city card (basically a fancy name for a long-term bus ticket) also interferes with both of these two.
- abritishguy 12y agoThat just means your office doors aren't configured properly and don't know which card to talk to and choose to do nothing in this case. The reader could very well talk to one card (or both) without interference.
- abritishguy 12y agoHaving two cards next to each other may well make the illusion of preventing the cards from working as quite a lot of readers will refuse to communicate with a card if there is more than one in range (sensible for some applications). This does not mean, however, that they are not capable of doing so - the first thing a reader does is get all the cards in range to broadcast their UID - it then uses this UID to select a card to talk to. When I was cracking mifare cards (used as authentication in many buildings) I found that it was significantly quicker to crack several cards at the same time than to crack them individually - this is because the attack that I was using required demagnetising the card hundreds of times which takes a lot longer than any communication with the card. I could crack a single mifare card in 5 seconds, I could crack 5 in 6 seconds (and for most applications cracking one card is all you need - all cards use the same encryption key).
- chias 12y agoIs this different from NFC Proxy in a significant way? http://sourceforge.net/projects/nfcproxy/ http://sourceforge.net/projects/nfcproxy/