Fear the reaper: characterization and fast detection of card skimmers
blog.acolyer.org
blog.acolyer.org
You open your mobile bank app, click BLIK icon and a 6-digit code is generated. You enter the code in ATM and you choose amount to withdraw. You accept the amount on your mobile phone and money comes out.
This is how it looks: https://www.mbank.pl/indywidualny/uslugi/uslugi/blik/
This seems to me to be a detective control which relies a bit too heavily on obscurity, obscurity which is now blown. Having knowledge of how this works, ATM skimming gangs who's devices might be found by local authorities with this device can now take the active counter-measure of placing a piece of Kapton tape over the read-head.
It should be possible to build this into a credit card sized device that you could just swipe with and have it illuminate a red or green LED when it detects a skimmer.
Might I ask what purpose would it serve?
For small transactions it makes no sense, but for anything above a user defined limit we should have this option. e.g. I only withdraw more than £50 in unusual circumstances.
But I don't see why 2-factor pre-authentication shouldn't work? Before purchasing, just authorize a larger charge on your card than a limit you or your bank previously set. If it works, then great. Worst case is it doesn't work (app breaks, phone out of juice, whatever), in which case you're back to the current situation.
I don't know what you mean by "ordinary" 2FA, but it's pretty common in Thailand when making online payments to have an SMS sent to you, and in the UK my Amex card has been known to require SMS/email codes for online purchases.
This excludes anything with a magnetic strip from being any part of the 2FA scheme.
Will be phased out soon due to regulation (PSD2) as it doesn't meet the requirement for 2 factors.
Some banks also allow you to confirm the transaction inside their mobile app, which is pretty convenient.
Nordea Bank Finland ceased providing code cards earlier this year. Logging on to online banking even warns that the code card you already have may stop working soon. Everything has moved to the mobile app or, available as a special order for the elderly and luddites, an electronic keypad.
Took a second, but that sound is just so satisfying.
Now, if Apple would allow me to nickname the damn cards so I could tell which is which, that would be grand. sigh
They got rid of those years ago in Europe.
We are only now starting to catch up to where they were in about 1998. I know, because I moved to Europe in 1998, and I remember how huge of a change it felt like to me. I moved back to the US in 2006, and with regards to credit cards it felt like going back in time at least a couple of decades.
Curious if there's an easy way to make my stripe unreadable with my most used credit card, especially for dining where your card can disappear for several minutes at a time.
Inserting the whole card is also a security measure to be able to take the card away if an incorrect pin is entered 3 times, or if the card is left in the device after leaving the ATM.
Countries that have completed EMV roll out still issue cards with mag stripes. It's maybe worth briefly explaining why this might not matter at all:
The payment card networks have two _entirely separate_ mechanisms in play. To a Hacker News reader it may seem insane to not tie them together, but this is how they evolved and apparently banks would rather eat fraud and error costs than spend whatever it would cost to fix.
1. Authorisation. This mechanism is in charge of deciding whether all the parties are OK with a transaction, e.g. "Mike Smith pays Example Co. $145". Cryptographic security can be used to verify that this was really Mike Smith's authentic card, he entered his PIN, Example Co asked for exactly $145 and Mike's bank said that was OK.
2. Payment. This operates entirely on the honour system between banks and retailers. Example Co. says Mike Smith agreed to pay $145 and the backend systems automatically give $145 of Mike Smith's money to Example Co. Done.
Because these two systems aren't tied together at all, even though the authorisation system guarantees the exact amounts, is strongly replay resistant, and so on, none of those properties apply to actually paying your money to some retailer. So regardless of whether it's tricky to get past authorisation it doesn't matter to big fraudsters, they can just take whatever they want and ignore the Authorisation step altogether.
When you realise somebody took your money you will call your bank. They may try to give you the run around (after all, it's easier) but ultimately - perhaps after some notice period - they'll probably agree to reverse that clearly fraudulent charge and if you live in a country with actual consumer protection they may even have to pay back any fees or other financial penalties you incurred as a result of them accepting the fraudulent payment request.
What's the point of keeping a tab then? Why not pay the full amount each night? Also, there's nothing preventing you from giving them a card, then reporting it lost/stolen
It must be a well known paradox, the more you expect people to trust you, the more they will be inclined to trust you.
There is not much point in damaging the magnetic stripe but leaving wireless functionality... they are exactly the same thing only wireless works from a greater distance.
It's there, in plain text, any normal NFC-reader will get you everything (there even are android-apps that does it in the play-store).
If you mean the CVV it isn't required to make a transaction.
that's incorrect. there's a cvv1 on the magstripe that's needed for magstripe transactions, and there's cvv2 that's on the back of the card that's mostly required (depends on merchant policy) for card not present transactions. for EMV transactions, you need a payment terminal because the card will refuse to communicate unless the other side has a valid certificate. even then, the card only returns a signed response, which you can't use elsewhere.
No? You just said so yourself? "depends on merchant policy" Why would an attacker choose a merchant whose policy denies their use case?
Why would an attacker opt for a magstripe transaction or a contactless transaction?
it's not as easy as you think. nearly all merchants require some sort of additional information (cvv, billing address, cardholder name) in addition to card number + expiration date. reason being, for card not present transactions (eg. online), the merchant is liable for fraud (the purchase amount + ~$25 chargeback fee), so they have a strong financial incentive to collect/verify as many pieces of information to reduce their losses. it would be insane to not collect any of those (only requiring card number + expiry date), because the chargebacks will bankrupt you. the reason i said "depends on merchant policy" is because some merchants (iirc amazon) don't collect cvv2 (but they do collect billing address + cardholder name), which I presume is for convenience/conversion rate reasons. I don't actually know of any merchants that only collects card number + expiry date.
But name is the only additional information you need to make a legitimate purchase, and that information isn't a secret (if you, under any circumstance, ask for someones CVV they will tell you to fuck off. Ask for their name is another thing (maybe even present on a name tag or in many cases trivial in a certain context)). It will make it slightly harder to just randomly scan peoples pockets on the subway but still an absolute security nightmare.
Just disable NFC altogether, no reason not to.
where did you get the impression that there are merchants (worth stealing from) that only accepts card number + expiry + name? the example I gave was with amazon, and they take name AND address. even if you're able to find a merchant with lax security and is worth stealing from, how long can you keep the scam up for? maybe a week or two before the fraud reports start pouring in? then they'll patch up their systems and you're back to square one. you're better off installing skimmers and using the card numbers at any merchant that accepts credit (at least in the US).
>will make it slightly harder to just randomly scan peoples pockets on the subway but still an absolute security nightmare.
considering that you have to be pretty close for NFC to work, whoever is doing it is going to look pretty suspicious as he's bumping into everyone walking endlessly through the train.
>Just disable NFC altogether, no reason not to.
I can think of one: convenience. wave your card in front of the reader vs insert card, wait, type in, wait some more, then taking out your card.
I've heard poker and gaming sites are popular to extract funds (and simultaneously launder them), don't expect them to have much security no.
> considering that you have to be pretty close for NFC to work, whoever is doing it is going to look pretty suspicious as he's bumping into everyone walking endlessly through the train.
Seriously? Just go during rush hour and you can basically stand still, the victims will practically bump into you for you. I don't expect anyone to attempt sprinting a carriage at a time...
For initial orders, yes. Amazon has a very advanced fraud detection system that builds up trust with your account over a while.
Amazon is very difficult to card.
>I've heard poker and gaming sites are popular to extract funds (and simultaneously launder them), don't expect them to have much security no.
All of those will require you to pass VBV. You will not get the information necessary to pass VBV without phishing.
You make it sound like this is difficult or rare, yet banks have a very lax attitude about this and consequently funds thieves with billions upon billions every year. Somehow it is worth it, relying on the victims to scan their transaction history for errors (talk about convenient!).
https://www.nytimes.com/2016/10/31/technology/how-to-protect...
In Britain, where people have arguably embraced contactless cards to a greater extent than individuals in other countries, researchers have routinely been able to copy the financial details of some cards, including the 16-digit card number and expiration date, by merely passing their own N.F.C. reader close to a person’s wallet.
There have been numerous other demonstrations of this as well.
Another demonstration (site is in Swedish https://www.svt.se/nyheter/lokalt/uppsala/sa-kan-tjuven-skim... ).
I think this is the key. The implementation of each card may differ leading to inconsistent results.
As a general rule I suggest covering up the CVV or scratching it off if you're sure you have it somewhere safe. An option is to also erase the magnetic strip. It might lead to a less useful card (in cases where only magstrip would work) but definitely a more secure one. And for any NFC card an RFID shield sleeve does wonders.
You could also get this data by... seeing the card ?
NFC though has the advantage to be read from a distance, easily through a pocket and wallet (if the wallet doesn't have an rfid shield). Surely open up that attack vector isn't helping?
If you are paying attention you can detect someone trying to photograph your card (they shouldn't even be handling it in the first place). But through your pocket? Practically impossible to detect.
edit: The fact that we still print everything needed to make a purchase on the card itself isn't particularly flattering for our species.
Nobody actually does this. Name+card#+cvv+expiry just isn’t worth the hassle, easier to get 1000s at a time via phishing or hacking web shops.
Stripe dumps are an entirely different market, with ATM pins increasing the value of a single dump up to 100x.
I bet there is zero overlap between those that does it and those that have the slightest clue how to perform a phishing or web shop attack.
They simply wouldn't achieve anything. They wouldn't get enough cards to be able to sell them, nor would they be able to cash out this information.
I'm sure there is zero overlap between people doing this and people actually profiting from (or causing losses with) credit card fraud.
If they actually knew what to do with such information, they'd just be buying it for a couple of dollars a piece.
Often enough, the chip or the reader is dirty and fails to read, the terminal will prompt you to swipe the card through the mag-reader instead. Usually, it will prompt you to try the card reader again, then back to the mag-reader for a final swipe before continuing.
I'm pretty sure the swipe-style is aggresively deprecated by the banks. I talked to a vendor who had an older terminal that would not accept NFC, and he mentioned that within 2 years, he'd have to get a terminal that would process NFC payments.
The idea is, if there's fraud and the real account holder gets their money back (a chargeback in payment industry terms) somebody has to eat that loss. The liability shift rules say if you didn't do EMV, that's you. For a bank that decided they wouldn't issue EMV cards, they pay when there's fraud on their non-EMV cards - so the merchant still gets their money. But for a merchant if the customer has an EMV card but they swipe it, if that comes back as fraud they're not getting their money.
If the terminals suck, and your business has very low fraud rates or your markup is so enormous you can eat plenty of fraud and not care, it could make sense to ignore liability shift. Especially at first when customers know they could go elsewhere. But as terminals improve, and everybody else is forcing them to use the chip anyway, offering swipe is pretty much a sign "Commit fraud here, ask us how".
For NFC I don't know, it's hard to imagine them trying liability shift. "Use this less secure option or, we'll stick you with fraud costs for the uh, more secure option?" maybe they're just doing the usual thing where they raise fees for everybody who doesn't want to go along with their latest craze :/
I don't know the details of the technological differences in transaction communication between the two, but in the UK chip and pin is noticeably and consistently faster to perform transactions in my experience, often to the the point that it's perceptibly instant... although it has been quite some years since i've used magnetic ones so that's from memory.
I suppose one way to protect yourself if you are never going to use your card in the US, is by destroying the magnetic strip (magnetically).
Most of the machines were replaced inside of the first year and things have improved substantially since then.
* many places moved from offline magstripe authorisation to online chip-and-pin authorisation (while still often using card terminals that use dialup connections, and connect per transaction)
* many US banks have really slow authorisation servers (for whatever reasons!); I remember some sales staff being really surprised at my card going through in about a second (and that verification probably involved a network roundtrip to the UK!)
I don't think the percieved speed is simply due to offline mode.
Just swipe it three or five or more times, and it might work anyway.
Welcome to the 21st Century.
When I'm at O'Reilly Auto Parts, the pinpad is beeping at me to remove my card almost the moment I've inserted it. It's shockingly fast. (Then their neolithic-age printer takes 8 more seconds to generate a receipt, but... baby steps!)
I wish whoever set up their system could go show some others how it's done. Because yes, on average, most retailers have abominably slow processing for chip cards.
Also, I don't think there are any places left where you swipe the magnetic stripe. If for some reason you don't use contactless, it's a chip transaction. I believe it's pretty much the same all across Europe?
The video is 3 years old now but still worth a watch discussing the attacks they have seen on Chip and Pin - https://www.youtube.com/watch?v=Ks0SOn8hjG8
It makes a much more recently deployed system in my area of the US look like a total embarrassment: seconds per processed tap, a much higher tap failure rate (regularly see tap failures for myself and others), etc.
But then again trains and a lot more really work in Japan. Supermarket? No waiting for payment (card or otherwise) - they're using double-buffering.
An example I know about with one of those flaws was the "Yes card" which MITMs a real (presumably stolen) card and arranges that the conversation goes like this:
* Legitimate terminal "Hi, I'm a Legitimate terminal, who are you?"
* Real card: "Hi, I'm Sizzle's Real Payment Card from Real Bank"
* Legitimate terminal "OK, let's do an offline transaction. I want Sizzle to authorise payment of 24.50. They entered PIN 1234, is that OK?"
MITM Yes card blocks this and tells the card instead:
"OK, let's do an offline transaction. I want Sizzle to authorize payment of 24.50, but I can't be bothered with a PIN so let's skip that"
* Real card: "OK, yes, payment of 24.50 sounds fine" (cryptographically signed message)
So this way you don't need the correct PIN, since the card never realises you entered a PIN, and so the transaction OK simply never mentions the PIN at all. You don't clone the card though, you need a real card, you're just using something like a Confused Deputy attack where the card and terminal misunderstand the situation.
A _smart_ backend at the bank could identify this fraud when the offline transactions are processed, hours or days later, but many did not, and even if they did spot it the fraudsters got away with their transaction meanwhile. The permanent "fix" for this was to roll out new cards and terminals, given this costs money it was probably not done widely or quickly.
As a result, the ATM's read head might pass over the detection spot multiple times.
Maybe you can force the measurement device to move only in one direction, but if I were to design the ATM, it would detect inconsistent, physical card movement.
That would be very prone to false positives. Weather variations (temperature, humidity), card types, dirt (grease , dust) and foreign objects (stickers on the card) etc etc would all make the card movement inconsistent.
If they [the ATMs] do this and can read the card, then they can also check that the measured movement matches what the controller sent to the motor driver. Heck, depending on the driver they could just let it measure back EMF (e.g. some Trinamic stepper drivers can do that).
Sure the data wouldn't be immediately available and require some post processing but unless the skimmer only recorded a fixed length I can see that method of protection bypassed very quickly and easily.
I know your posting about the skim detection tool but it just seems to me like a bad method of trying to defeat skimmers. I would guess such systems are used for trying to detect a "Lebanese loop" which traps the card when it tries to eject.
However, once a year seems optimistic for card replacement, if you use them at a lot of POS (gas stations). I've seen replacements at once a week (every time they filled up) and the gas station attendent doesn't care either.
next up: skimmers with "undetectable" read heads (lined with plastic)
I've seen cashiers sandwich cards between pieces of paper to get problematic cards to read, which makes think that while the read head must be metal, it doesn't have to be in contact with the card to work.
What's the point of wiretapping the emv chip? Isn't EMV supposed to be immune to skimming?
> External devices can be attached as card reader overlays, deep-inserts inside the magnetic stripe slot, those that fit in the EMV slot (chip reader) and those that wiretap the physical communication line.
I believe the "those that fit into the EMV slot" and "those that wiretap the physical communication line" are two different types.
A skimmer in the EMV slot can still skim the mag-stripe. Wiretapping the communication line is used when the ATM/Payment terminal uses poor security between it and what ever its connected too.
Now, if they don't need the full mag stripe, then you've got a problem. But I don't think that mechanism would work for most skimmers.
The whole concept of chip+pin is pretty pathetic considering that the magnetic stripe is still there for backwards compatibility.
And now with wireless cards it is even less secure than a magnetic stripe.
I have never seen a card without magnetic stripe, that is awesome. I even have some trouble getting a card without wireless...
At least whole card number + expiration is on the magnetic stripe. You don't need CVV as it is optional. Everything is written in clear-text and by definition that text must contain everything needed to perform a purchase.
But for the Authorization a PIN absolutely can be required for online card transactions using a mag stripe. And this was routinely done in countries which had PINs for debit cards years before EMV. The terminal calls the bank and says I have this card, and here's the PIN entered by the customer, is that OK?
Unlike the mag stripe you can't clone a card using the "wireless" EMV mode, the chip isn't just playing back a fixed data stream, it's an active component.
[ It might be instructive to expand here, so I shall ]
A part of an EMV transaction the terminal and card are supposed to pick random ("unpredictable") numbers each time. If this is done correctly it presents a significant security feature. For example, suppose tomorrow I plan to tell a jewellery store's payment terminal that your card, which I was able to access briefly today when you were in the same elevator as me, authorises purchase of a $500 watch, then I'll pawn the watch and keep the cash. Well, I need the cryptographically signed message from your card saying this is authorized. But, that message needs the unpredictable number that the jewellery store terminal will choose tomorrow, which I don't know yet, so I can't do it.
Now, in practice researchers found some terminals and cards are crap and e.g. the numbers they use aren't truly unpredictable. But that's an implementation flaw that can be fixed, just the same as if your bank has a habit of leaving the back door open and the vault unlocked. It's something your defence attorney should know if the bank accuses you of fraud for someone else's transaction, but it's not an inherent problem in "wireless" EMV.
Making the whole endeavor pointless.
To the extent that Authorization isn't mandatory before the Payment step, sure, everything about payment cards is "pointless". Banks have decided they don't care about fraud and will just pass that cost on to you. shrug
Anyway, it is pretty immoral to rely on reimbursements - actively funding and making thievery profitable.
If the terminal does not have a chip reader (or doesn't parse that information) it will allow the purchase. If you are cloning the magnetic stripe you would of course reset that bit and you would be all good.
Certainly, using rather basic NFC smart card technology, all but on-line attacks could be eliminated. My question is then, what kind of low-protection protocol do they use in practice to make this so insecure.
Specifically, I am asking about an offline attack that allows an actual spend the bank would accept. I am also only interested in debit cards (because that is what I have) so just reading a CC number from NFC doesn't bother me.
I would say to a friend "I bet I can buy the next round using your card, if I can you buy the round if not I'll buy the round" Get them to place their wallet with their card in it on the table with one of my phones near the wallet and I would present my other phone to the reader at the bar.
At the time the bar I did it at had public wifi without Wireless Isolation so I could use the bar's wifi as a low latency connection between the two phones but back then the tolerances on the timings would allow you do do it with a decent mobile connection. (At one point you could just get a NexusS custom rom already set up for this replay attack).
It was more of a party trick as you had to have close proximity to the payment card as it was just a relay attack and the banks limited NFC transactions to a max of £20 which the banks would cover (its been bumped upto £30 these days or more if you auth with biometrics like with Apple Pay if the store permits the transaction).
I believe NFC payment terminals these days have tightened up the timings of card reads to make such relay attacks more difficult.
It amazes me how timing makes it possible to detect this kind of stuff.
I believe that after so many NFC payments (without reseting the count) or try and make a purchase over £30 they ask for a pin and my bank will cover any NFC payments on a lost card as long as you make them aware of the loss within a reasonable time period. So personally I'm not too worried about losing my NFC card. They know its not a perfect system (is anything perfect?) so limit their loss by restricting the amounts used on such cards.
EDIT: Esp as a lost card could be used for online transactions as they have the CVV (as they have the card) and losing your card prob means losing your wallet and prob your driving license with your address on it (almost everything a bad actor needs to make an online purchase, just got to hope that Verified by Visa / Mastercard SecureCode kicks in).
(Now I've said it I bet the next time I use NFC it will pester me for a pin :-p)
I was discussing with colleagues how smart the interval is. Perhaps the bank is doing some anomaly detection to inform whether a PIN is needed.
Note that I am coming at this from the perspective "Is payment in my country done well". So I only care about attacks against my card, and the cards of people I know.
It does seem stupid to me to have a CC number and expiration date available in plain text. But honestly, I am more amazed by that information being sufficient to authorize payment. That said, it amazes that 'upgrades' both neglect to fix the underlying issue, and fail to take it into account in their implementation.
Besides this entire story, there is an interesting issue of PIN-less tap-and-pay, which scares me more (from the dutch perspective) than plaintext data on my NFC card. It doesn't scare me enough to disable it though.
I totally agree that the requirements to authorize a transaction is laughable. Even more so that the information is printed on the card itself, insane.
Notably, every time I've used it on-line, it forwarded me to my banks website, where I needed to do a 2 factor thing. I'd guess that is vendor-dependent though. I can't imagine US webshops are setup for that. (Most of my usage is amazon.de)
Where I travel I don't run into those anymore. Because if I did it wouldn't work - I've found that with enough magnetic stripe cards in the wallet they effectively de-magnetize each other. I currently have exactly one (very new) VISA debet card with a functioning magnetic stripe, which I use for parking only, as there are still a few very old magnetic stripe machines around. The other cards can't be read. (Someone could put a pinhole camera on the parking lot reader.. doesn't matter, as no pin is entered. Cost is up to ~a dollar or so, so they don't bother with the pin.)