Jump to content
Sign in to follow this  
*Glenn*

RFID Security

Recommended Posts

FYI

The use of RFID embedded on credit/debit cards raises concerns about security and theft.

NB: The issuers maintain they are safe especially as other security measures apply. But the hackers show how easy it can be done. Circulated not to raise alarm, but fyi/general awareness only.

http://youtube.googleapis.com/v/lLAFhTjsQHw%26sns=em

http://www.stuff.co.nz/technology/digital-...dit-card-threat

http://www.pcworld.com/article/249138/rfid...demo_shows.html

What next... touch & steal

Share this post


Link to post
Share on other sites

Interesting article Glenn. Thanks for sharing !!!

Share this post


Link to post
Share on other sites

never been a fan of that technooogy for exactly the reasonthat has just been shown here

Share this post


Link to post
Share on other sites

Like it or not its coming - repco is amongst the early adopters that have been rolling out contactless capabilities for a while now, more corporates rolling it out Q1 next year. Any new merchant who wants to accept visa/MasterCard from April 2013 will be required to have a contactless capable Eftpos - surprise, surprise the merchant wears more cost on transacting contactless.. More fees loaded by Aussie banks on Nz business - <_<

Share this post


Link to post
Share on other sites

K-Mart has those contactless terminal for a while now. So much faster than using the chip-card slot.

Back to topic, there are now RFID blocking wallets for the paranoid types.

What gets me now is that we now have multiple RFID capable cards in our wallet and some are interfering with each other when placed on a reader. e.g. my AirNZ FlyBuys card is affecting the Snapper card when both are in the wallet. Defeats the purpose of "Just wave your wallet to pay", I still have to take the right card out.

Share this post


Link to post
Share on other sites

Contactless is awesome!

I'd like to use my phone for NFC Payments, since it has this enabled.

You could also drill out the NFC chip in your credit card, as it's not the big gold chip that does this. - and as you noticed, they have to be bloody close, 1-5cm to read the details.

Share this post


Link to post
Share on other sites

Yeah I wouldnt worry too much, Credit cards / wallets are on the way out .. NFC will be main stream before long.

RFID is nothing new and is used in the security sector for door swipe and other access methods. Even your BMW key uses a format of RFID.

Skimming data has been used by hackers for a long time, including wifi router ARP poisoning for intercepting traffic. It shows why it is important for developers of technology to use strong encryption on the transport layer.

Share this post


Link to post
Share on other sites

Err, Ok, I'll pretend to understand that last bit, and just go with Josh said it's ok and not to panic.

But still thanks for the heads up Glenn, another reason for me to stick to cash...!

Share this post


Link to post
Share on other sites

Have copied RFID access cards before, but that is a lot different to credit cards etc as they are a lot more secure.

Share this post


Link to post
Share on other sites

I'd like to use my phone for NFC Payments, since it has this enabled.

Payment networks estimate another 3 years for this in NZ - still a massive lack of compliance standards.

NFC mobile gift cards/loyalty cards will be first - BIG step towards the wallet-less society

Share this post


Link to post
Share on other sites

at the end of the day.

If your credit card company forces a type of card on you. That has a proven security flaw.

You dispute the fraudulent charge, and the it's the credit card company's problem.

I pay everything with my credit card. The consumer protection that goes with them is excellent.

You get robbed with cash good luck asking the bank for your money back.

Edited by M5V8

Share this post


Link to post
Share on other sites

also there is a payment limit on pin-less payments. about $40-80

and that's what the banks will reimburse.

Share this post


Link to post
Share on other sites

You dispute the fraudulent charge, and the it's the credit card company's problem.

I pay everything with my credit card. The consumer protection that goes with them is excellent.

You get robbed with cash good luck asking the bank for your money back.

What he said ... i use CC anywhere and everywhere i can. CC companies are generally good at identifying fraud, regardless they will reimburse you anyway!

Share this post


Link to post
Share on other sites

Good read! Thanks for the post. Where is Paywave used? I have personally never come across a Paywave terminal before?

Share this post


Link to post
Share on other sites

Good read! Thanks for the post. Where is Paywave used? I have personally never come across a Paywave terminal before?

PayWave is visas advertised branding for contactless. Mastercards is Paypass.

Keep an eye out for those logos they'll start popping up.

Share this post


Link to post
Share on other sites

also there is a payment limit on pin-less payments. about $40-80

and that's what the banks will reimburse.

Yeah but it's the fact the numbers can be obtained.

My gold card has this technology, I've never used it though.

Share this post


Link to post
Share on other sites

Yeah but it's the fact the numbers can be obtained.

My gold card has this technology, I've never used it though.

If you are really worried about contactless, go here (https://www.pcisecuritystandards.org/security_standards/) and try to stay awake.

Banks and card schemes are NOT in the business of rolling out payment systems that are not fully tested, or that have any known security flaws. The media can make up whatever scary nightmare scenario that they think might see fraudulent transactions occur, but I can assure you that the security specialists who work for the likes of Visa and MasterCard get paid a shitload of money to do their job right, and they are considering potential risks which the media will never hear anything about (for obvious reasons).

NFC in phones is currently being trialled in NZ (I've used a couple of Galaxy S3s for it already), and more and more merchants are choosing (or being forced by the card schemes) to update to NFC/contactless PIN pads.

Enough with the scaremongering people - there is far less risk associated with NFC than there is with carrying cash.

Reminder - we are now in the 21st century. Anyone want to go back to swapping potatoes for oats?!

Edited by Mungous

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
Sign in to follow this  

×
×
  • Create New...