Shmoocon Demo Shows Easy, Wireless Credit Card Fraud 273
Sparrowvsrevolution writes with this excerpt from a Forbes piece recounting a scary demo at the just-ended Shmoocon: "[Security researcher Kristin] Paget aimed to indisputably prove what hackers have long known and the payment card industry has repeatedly downplayed and denied: That RFID-enabled credit card data can be easily, cheaply, and undetectably stolen and used for fraudulent transactions. With a Vivotech RFID credit card reader she bought on eBay for $50, Paget wirelessly read a volunteer's credit card onstage and obtained the card's number and expiration date, along with the one-time CVV number used by contactless cards to authenticate payments. A second later, she used a $300 card-magnetizing tool to encode that data onto a blank card. And then, with a Square attachment for the iPhone that allows anyone to swipe a card and receive payments, she paid herself $15 of the volunteer's money with the counterfeit card she'd just created. (She also handed the volunteer a twenty dollar bill, essentially selling the bill on stage for $15 to avoid any charges of illegal fraud.) ... A stealthy attacker in a crowded public place could easily scan hundreds of cards through wallets or purses."
Use a Faraday Cage wallet (Score:5, Interesting)
I've been using a Faraday Cage wallet and passport holder by DIFRwear: http://difrwear.com/ for several years now. I don't work for them, but with the very cheap wallet prices and sturdy construction I've been very pleased with the products. I can testify that they do work as I have an RFID key card and it won't activate the door if in the wallet.
Re:Aluminum Foil in the Wallet (Score:0, Interesting)
They also discussed in the same presentation that most of the foil coverings you can buy to protect your credit card don't work since unlike faraday cages they are not grounded
Re:Glossing over one problem... (Score:5, Interesting)
"with this attack you MUST be the next person to use the card's credentials." "the cries that people have thrown up that someone could scan an entire room full of people at once are totally off-base"
Because it's impossible to build a rig that fits in a briefcase or backpack that scans cards within a meter or two of the holder and automatically runs scripted transactions as soon as a card is detected in range, right?
Just because it's not AS bad a picture as the doomsayers are painting as a worst-case scenario doesn't mean it isn't ripe for exploitation.
What's the point of these? (Score:5, Interesting)
Re:Aluminum Foil in the Wallet (Score:5, Interesting)
I have a RFID blocking wallet. My security badge for work will not scan when inside the wallet (but it will scan inside all my co-workers wallets and my old wallet).
Same price as a normal wallet and not a bad investment.
Re:Is this news? (Score:3, Interesting)
The CVV used here, I believe, isn't the one printed on the back of the card. I believe that it's a one-time use CVV that changes for the next transaction (think rolling-code garage door opener or http://en.wikipedia.org/wiki/One_time_password [wikipedia.org])
So, someone who steals one can do a single transaction.
false (Score:5, Interesting)
Mythbusters lost episode (Score:5, Interesting)
Re:Is this news? (Score:3, Interesting)
As a non-idiot I knew this was possible. I fight Chase regularly on this, they send a new card with the stupid chip, I call and roast em, they mail me a new one without the chip. But they tell me at the time that it is a one time only deal and sure enough they send another later in the year on a different card. Yes, because of mergermania I now have three credit cards but they are all Chase. They simply refuse to allow you to permanently opt out of this madness.
Same with wanting to move me to a debit card instead of an ATM card. The ATM card requires a PIN for all transactions and has other safeguards which work in my favor. The debit cards can be used in all sorts of places without a PIN and since it isn't a credit card (despite the Visa logo) the stolen money is gone from your account and you are getting to pay NSF fees all over the place while you fight over it. So I just keep cutting those cards every time they send a new one out and keep using my ancient ATM card. When it stops working I'm out of there.
Re:MOD PARENT DOWN! (Score:4, Interesting)
An anisotropic radiator? THE FUCK does directionality have to do with anything?
An "electrostatic charge" is just an electric charge that isn't moving, by the way. Move an electric charge with an AC current and you get... wait for it... EM radiation.
An antenna radiates EM energy by moving charges around. The radiated energy from an antenna, in turn, induces movement of electrons in other conductors. The Faraday cage is a conductor, so the radiated energy causes electrons to move in it. That movement of electrons also radiates energy, as if the Faraday cage were itself an antenna. Hence the Faraday cage might as well be pinned directly (electrically shorted) to the antenna of the transmitter inside it.
I think you're using big words about concepts you don't really understand.