How contactless cards are still vulnerable to relay attack
benthamsgaze.org
benthamsgaze.org
The pile of hacks we have today is just a result of the fact that the networks don't want to operate the PKI.
Edit: fare gate is a special class of problem. I don't expect TfL to be screwing with me, whereas I may be highly suspicious of the point-of-sale system down at the corner bodega.
- Simple arithmetic on an occasional basis
Things a NFC card implementing the system you describe:
- Radio
- Public key crypto
- ASN.1 DER X.509 parsing to validate the signed transaction from the terminal. The terminal would need to send a cert chain to the card and the card follow the chain to the network root to correctly verify the terminal signature.
- Parsing OCSP responses, which the terminal would have to staple to its cert because the card has no other way of knowing the revocation status of the terminal cert.
- Conform to ISO 7816 for interoperability with legacy equipment.
- Fit in a wallet/purse/pocket
- Be a reasonable cost
Producer: https://www.nidsecurity.com/products/solution-financial.html
The cost of the card wouldn't be much, perhaps enough to pass it to the customer, but not outrageous.
[0]http://newsroom.mastercard.com/press-releases/mastercard-int...
I don't believe this has been ever implemented, or anyone knows how to do this really. How do you imagine it would work? Every card preloaded with every bank's CA? Cards connecting back to the issuer for updates? Something else?
Basically a) signed with what, and b) what does "inspect" mean?
"Inspect" means you get to see the amount you're going to be charged.
Revokation of CAs or intermediates would mean that many cards suddenly stop working before the expiry date. Can you imagine the PR fallout if that happens?
> "Inspect" means you get to see the amount you're going to be charged.
You still don't know who you're charged by. It could be another transaction relayed to you. It makes it less practical (synchronised payment / compromised terminal), but not impossible considering how many hoops we have to jump through for this class of attack in general.
Revocation shouldn't make cards stop working, as long as certs are still signed with some valid chain. And new CAs can be cross-signed. The only thing that has to get updated is the merchant terminal config.
Just have an app that allows the user to review transactions after they have happened. If there is a double charge, dispute and win easily, if charged too much, dispute and win easily, etc etc
This already exists too
The fraud resolution on my Visa card[1] required me to:
1. call the merchant that charged the fraudulent charge, and attempt to get them to void it. This was literally as pointless as it sounds.
2. Receive a specific form that could only be sent by snail mail or fax. The sending end absolutely refused to send it over email. Thankfully my building has a fax machine, and my building manager has common sense, and allowed me to borrow it. The fax service we use (because who uses fax?) turns faxes into — you guessed it — emails. Of course, at the bottom of the received fax is "H:\SharedDocs\Stuff\More Stuff\TheForm.pdf".
3. Fill it out, scan it back into a computer, fax the PDF back. (I could have also snail mailed it back.)
4. Receive a confirmation over snail mail, noting that it will be resolved sometime in the next 6 months.
I never lost possession of my card, and the merchant who charged the card was able to confirm that the "card" was presented at the time of purchase (it was made physically, in a store) — while the real card rested in my wallet, thousands of miles away.
I was issued a new card, of course, and the old one voided. The new card is still not chip and pin, despite me explicitly asking for it.
I'd love to take on the "hassle" of public-key crypto.
[1] This was a debit card that works as either a credit card or a debit card (though the latter mode requires a pin, but the former mode requires nothing … because … waves hand); I am told credit cards are supposedly less of a pain.
A credit card is effectively the exact same as a debit card (for what uses I would be using it for), it's just more hassle (again) on my part to get it to be backed by cold hard cash, and requires me to agree to an agreement that, should I ever slip up, has some exceedingly nasty clauses.
For any merchant who knows what they're doing, this is FAR from pointless. It's much cheaper for them to just go ahead and refund you than to get a chargeback. They should only refuse to refund you if they believe that the charge is legitimate and that they can successfully represent the chargeback.
The usual way it works is this:
- I discover something is wrong when my card is declined. I pay with my other credit card instead.
- I call the card issuer that evening. Within 5 minutes I'm talking to their fraud department.
- They inform me of suspicious transactions (often preemptively declined) and I confirm I did not authorise them. I'm done within 15 minutes.
- I use my secondary credit card for a week while they mail me a new one.
You just need better bank.
I dunno if it's an issuer thing or a credit card thing.
The article does point out, though, that this might well be "too little too late" as the MasterCard specification is only one of many and it will take years For new cards to actually end up in the hands of consumers. I guess this is what the title refers too, but I have to admit that at least I was surprised to learn that something is being done at all about this...
This will probably break the "fix" though, as the "card" may take up to tens of seconds to "respond", awaiting for owner granting permission. And won't work for stores that can't handle NFC.
Non-chip cards are by far the bigger liability. The levels of fraud on contactless cards have been so low that the banks put the limit up from £10 to £30 recently here, and take full liability themselves.
There's a demo for a quick PoC here https://www.youtube.com/watch?v=ZsOzeELdjxM . It makes me sad that they're closing this, the fraud potential was really small (as the article implies).
Or is this assuming the bank allows a $2000 purchase using only tap?
The attack is possible on all current electronic chip payment forms (contacted/contactless, with & without PIN).
For contactless without PIN, transactions are limited (in my country to €25 per transaction and €50 total before a PIN is required). Contactless without PIN is much easier to attack (for obvious reasons), but cannot break this limit. Contacted with PIN is fully vulnerable, but also a lot harder to pull off.
The 600km limit is also highly deceptive, as it doesn't take into account latency introduced by electronics. E.g. a typical good wifi connection has a much higher ping than 2ms.
Edit: For this to work the card itself would have to have it's own display. Another commenter suggested e-ink.
NFC uses magnetic antennas/coupling meaning that shielding from one side is enough to block signal.
My solution is to laminate strip of aluminium foil in card form factor.
As well as testing an active jammer that's for sale https://www.youtube.com/watch?v=rnOuEFR6qoM