Ultrasonic Payments
charliegerard.dev
charliegerard.dev
Tone also came with the unfortunate side effect of Google software having constant access to your microphone.
0: https://chrome.google.com/webstore/detail/google-tone/nnckeh...
The basic problem is, the wifi password needs to be shared with a device without an interface.
The traditional method at the time was the device boots with an unsecured wireless network. And an app on the phone is used to connect to the network, and share the wifi password, and then rendezvous on the wifi network to continue provisioning. I think there are some protocols for this that I don't fully remember now. There's lots to consider in this method, such as can someone sniff the transfer, how is that protected, what is the range to pick up, etc. Can someone trick the app into connecting to some other device, etc, etc. If you put mitigations in, how can those be countered.
With sound / ultrasound based provisioning (the device I'm talking about already had a microphone and speaker), the range is more limited to who can hear the device. The signal strength is much weaker, an eavesdropper might need to be in the same room. This might allow weaknesses in the overall model of key exchange to be less of a concern, as the properties change to something a lot harder to intercept.
When considering robustness of support, one nice thing about the WIFI approach is in theory you can fall back to just a web browser. So basically any device could be used for provisioning.
And the audio method, would probably support a great set of devices. We didn't actually consider ultrasonic, just an audio codec that was in use at the time and doesn't sound awful.
I feel like Apple’s ‘Find my’ tech could work to get positional data and make it possible. You’d need whitelists and the like of course.
The issue at play here is that most devices have no concept of locality or relative positioning. They may know (at best) approximate distance between itself and another device based on the type of transmission, signal level, noise levels, etc.
Phones also can't understand intent. How does it know whether it doesn't mean the person sitting behind your friend or your friend?
I think there would still be a quick confirmation button listing who owns what phone you're sending it to, and it could default to people you know in vague situations - but generally whoever is closer.
In today's world, most phones or "smart" devices are also constantly listening; I want to believe they don't listen until the trigger phrase is uttered, which could also be implemented for these ultrasonic applications, but I'm not entirely convinced and them always listening is but a silent over-the-air update or setting change away.
They can't know whether the phrase was uttered unless they constantly listen.
The microphone is active and "listening" all the time.
The firmware that detects the wake word compares the constant input stream against waveforms that are designated "wake words". Firmware can be sometimes updated for custom or trained words, but it doesn't hold a large dictionary.
If a reasonable match is found, it kicks the full recording/recognition/streaming code, squirts any buffered audio at it (to catch words that come directly after the wake word and before the full handler is ready), and then things proceed according to plan. Depending on the device and service, recognition might happen locally or in the cloud.
I really wanna use tech like this sometimes in future, but I also wanna care about accessiblity.
Phone lines have (or at least had) narrow frequency ranges. I'm not an expert but I'd assume this is just normal sound like any old modem.
Well it's not ultra I'd say, that screeching is quite audible. Very similar in sound to an old phone modem.
I think the system it uses is the same as for Moneta, which can be used in much the same way but gets billed to the sim account instead. I'm sure other countries also use the same principle for some services.
Jokes aside, I'm sure Clinkle had something working in a demo form but obviously the problem is sound as a digital communication medium is terrible outside of specific use cases (air gap attacks?).
Clinkle is up there in the who's who of blow ups.
unfortunately coffee grinders and such would mess with transmission. the sound engineer working on it also left shortly before I started so the feature never got fixed and eventually killed.
The moment I saw the headline, I was incredulous. The actual project implementation in the article is a rather cool hack, so props to the author. I dread the day someone actually picks this up, assuming someone does actually choose to.
2) Type in a charge like $50
3) Discretely wave the device at your targets wallet
4) Repeat steps 2-3 as much as possible in a short amount of time.
5) Hope you can withdraw the funds before anyone notices.
I don't think this is a wildly plausible attack and also at least here in the UK your targets card issuer takes 100% liability for fraudulent charges.
Getting a payments terminal is not easy, this would requires ID verification and working business bank account (acquirer), this terminals are highly regulated. Someone doing this can get caught easily by just a couple of customers reporting the fraudulent transactions. This is very small risk and is rarely seen.
Phone payments generally require the phone to be unlocked.
Also, it's a credit card transaction: the user will complain later, attacker will get into legal trouble, and user will be refunded fully.
And it has completely transformed how payments happen. paymets happen directly from bank account to bank account regardlessof what app you're using (Samsung Pay, PhonePe, GPay, your bank's app). You can use QR codes or simple username@bank to make payments.
I am not aware of any payment systems that support the use of NFC, (NFC is not that commonplace for anything except cards, and I have had trouble setting up cards in google pay). One of the biggest benefits of QR based payments have been is it does not require any special hardware. Just a mobile and Internet (Which is very common and accessible here). And it has little to no transaction fees. So it has been quickly adopted by literally everyone.
[1] https://en.m.wikipedia.org/wiki/Unified_Payments_Interface
I basically lumped the whole of Asia into a melting pot, whoops. While you're correct that India's UPI doesn't have an NFC mode, other countries do (NETS of Singapore and various systems in Japan for example).
Seems like an interesting way to start a transaction without needing to buy any specialized equipment.
(If some one knows more, please step in and comment.) I’m guessing some of these could be issues with NFC too but from what I have skimmed online it seems both the tag and receiver would need to be modified to work at larger than normal distances of “1-5cm”[1]. Also much more power is needed to extend the range of NFC than sound since sound strength diminishes with the square of the distance and, from what I have skimmed, magnetic induction used by nearfield NFC diminishes with the cube of the distance [2][3].
1: https://seritag.com/learn/using-nfc/nfc-tag-scan-distance-ex...
2: https://www.physicsforums.com/threads/magnetic-field-strengt...
3: https://physics.stackexchange.com/questions/44037/why-is-nea...
Recommended.
Seems going nowhere
It also looks like one of the key components is the `quiet.js` library [1] which itself is an emscriptem port of `libquiet` [2].
[0] https://github.com/charliegerard/ultrasonic-payments
*full disclosure I worked there 2019 - 2020
And I believe how Cisco teleconfernce allow wireless configuration of a screen share.
https://www.intechopen.com/chapters/66562
Some packets may get lost, but thanks to checksums we can detect and try some other clear channels/methods/etc.
A while ago Alipay had this ultrasonic payment method, I queued for a vending machine, opened Alipay in advance because I never used this "ultrasonic payment" feature before, then just when the guy before me pressed the button, my alipay accidentally payed for him. Luckily he and I wanted the drink of the same price, so he payed for mine instead.
Using QR-code or NFC for payment won't mess up like this. And later Alipay completely canceled ultrasonic payment feature. I guess many people encountered the same problem. You can't control omnidirectional ultrasound broadcast. It's very insecure.
It should be easy to send packages wirelessly across devices of different platforms in 2022.