Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Your understanding is incorrect. This is just one example [0] there are many ways to skim Chip & Pin (EMV[1]) cards, even if you build a card which cannot be cloned through active or passive monitoring of the ICC component you can still perform at least 1 illicit transaction by proxying to it.

The same holds for NFC skimmers which are now becoming more and more relevant and popular especially with the commercial availability of ultra-low-power and ultra-compact wireless SOC's.

If some one was wondering what are things like ESP8266[2] that give you WiFi connectivity with less than 1mW standby draw while being the size of a quarter are good for; if nothing less they are a pretty damn good platform for real time NFC or ICC skimming.

[0]http://sec.cs.ucl.ac.uk/users/smurdoch/papers/oakland14chipa...

[1]https://en.wikipedia.org/wiki/EMV

[2]https://www.sparkfun.com/products/13678



I stand corrected. Thank you for the information.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: