> You imply that it is possible to clone NFC cards with other means. Is that really possible?
I mean, sure, it's always possible, but probing a secure microcontroller with needles and an electron microscope isn't really what I meant.
I was referring to what the various mobile wallet applications do behind the scenes when they allow you to "import" a plastic card and then use it as a contactless payment source via your phone's NFC radio. They're not actually cloning the private key inside the card, they're using various banking APIs to ask for a new key that, for all intents and purposes, will act exactly like the key on the physical card.
They're supposed to ask for extra info so that they're super ultra sure the person importing the card is the legitimate cardholder, but this is not always very thorough. What kind of info do they typically ask for? Numbers printed on the card that you can acquire wirelessly by accidentally bumping into someone. If you're lucky, they'll try to do two-factor via SMS or email with information that they have on file, but I've seen some that don't bother.
> Regarding replay attacks, do you have a source on that? I would assume that even offline POS terminals would use a nonce to prevent replay attacks. Is that assumption incorrect?
I worked on an EMV contact + contactless implementation several years ago, and at the time contactless replay attacks were easy to demonstrate. Things may have improved since then, but the protocol was not very good (supposedly due to constraints from early NFC cards that were small and anemic), and I think they would need to redo most of it and kill backwards compatibility to mitigate the risk completely.
https://www.youtube.com/watch?v=e023wGfVaE0
https://www.cs.bham.ac.uk/~tpc/Relay/
https://www.hackster.io/news/this-tiny-10-device-can-perform...
https://link.springer.com/chapter/10.1007/978-3-319-39814-3_...
https://en.wikipedia.org/wiki/Contactless_payment#Security
From what I can tell, there was a lot of discourse around these problems around 2015-2018. There were demonstrations and exploits galore. But the standards were already out and none of the banks or card issuers wanted to change anything. Security researchers got bored and moved on. I don't see any evidence that replay and relay attack vectors have been fixed, or that they aren't exploited in the wild, just that the banks seem to consider the risk acceptable.
> And finally, you can extract card holder name and card number from most cards just by looking at them. Claiming that NFC cards are somehow worse than mag stripe cards in that regard is just FUD.
So you'll let me rifle through your wallet and write down the card numbers and expiration dates? Would the average person let me do this? Of course they wouldn't, because basically everybody knows that they need to prevent random people from seeing the various numbers printed on their payment cards.
Is the average person aware that I can capture these markings by "accidentally" bumping into their back pocket on the subway?
It's not FUD, it's a (subtly?) different issue, one that the public largely doesn't understand yet.
What's frustrating about contactless cards is that there isn't even a good solution once you do understand the problem. Metal shields sewn into your wallet only hide the problem. The card will still respond if you shoot enough energy at it, and you'll still be able to pick up the response if you have a sensitive enough receiver.