Crazy Thin ‘Deep Insert’ ATM Skimmers
krebsonsecurity.com
krebsonsecurity.com
Who are these businesses? Seriously, stop issuing cards without chips and send new card readers to theses businesses. End of story.
Is it because US businesses use deeply embedded card readers in custom POS machines that aren't modular?
Everywhere I go in South America and Europe, businesses have portable readers. The card companies just sent them new readers and they were accepting chips overnight. Same when NFC was introduced.
The US payment and banking systems are truly maddening.
Here in Alberta, it's the law that you need to pay before you pump[0]. If you're at a modern pump you insert your card, it does a preauth for some amount (you can select common amounts, like $20 of fuel, or "fill up" which is like $125 or $250 depending on the station), then when you're done it does a purchase for the exact amount.
If you're not at a modern pump, or you're paying cash, you have to go into the store, prepay for something that you think will fill your tank, fill your car, then go back into the store and get your change.
[0] https://calgary.ctvnews.ca/station-owners-and-gas-and-dash-v...
She didn't have any problem taking a chipped card but I imagine there are self-serve places that can't. It was only in 2018 that Oregon allowed self-serve in counties with less than 40,000 people. 17 of the 36 counties qualify.
The advice I've seen with credit cards seems to be "always tap if you can" since that's not subject to skimming or stealing a PIN.
Then they continue to be part of the problem (and liability for fraud is on them).
Merchants started getting chip terminals as part of the regular replacement cycle, consumers started getting chip cards as part of that regular replacement cycle, and eventually the terminals started telling users to insert their card.
Interac was the first mover because most people were already familiar with swipe and pin, so the move to chip and pin was a virtual non-event. When the credit card companies moved the issuing banks had to issue PINs, but everyone already knew the mechanics of using it.
The most interesting part is that the US already has the infrastructure to support this. I went to a Walmart in the US and paying with my Canadian credit card worked EXACTLY like it does in Canada - insert card, confirm amount, enter PIN, done. The cashier was a little confused that I didn't need to sign for it, but ultimately they just went with it.
The introduction of NFC was a similar non-event.
I want to call out this country wide edict. I've seen this done in both the United States and Canada. I do not know your personal situation, but I'm fairly sure it wasn't across the entire country of Canada.
Based on my experience both the United States and Canada are usually moving financial tech through different regions and social groups in phases and at different paces.
I'm trying to think of specific examples occurring nation wide and credit card technology just doesn't register. Maybe the removal of the Canadian penny, or paper dollar?
Yes, every card in Canada is chip and PIN except possibly some prepaid gift cards. The same is the case across Europe and Australia and has been for the better part of two decades now.
Speak not from whence you know not.
While all cards in Canada may have chip and PIN, no such event occurred where across the nation everyone started using it for every purchase, like there was no transition, nor different options to use with the same card. Consider contactless-enabled card payments as an example (like the original post did).
The assertion that the United States is somehow behind Canada in payment technology because all credit card issuers do not issue cards with chip and PIN seems invalid to me. Additionally the surprise at not requiring signatures. Merchants have been accepting contact-less enabled card payments in the United States, requiring no signature, for quite awhile.
The $1 and the $2 notes stopped being issued in 1989 and 1996 respectively. They are not demonetized and you can still exchange such money at any bank in Canada, or the Bank of Canada, for its face value.
https://www.bankofcanada.ca/banknotes/about-legal-tender/
>While all cards in Canada may have chip and PIN, no such event occurred where across the nation everyone started using it for every purchase, like there was no transition
What the hell is this supposed to mean? EMV-enabled cards were rolled out as each bank got onboard, replacing cards at expiry with EMV-enabled ones. Eventually no further non-chip cards were issued.
After a while, the same thing happened for contactless as well.
>nor different options to use with the same card.
EMV supports multiple applets per card, so you can absolutely have a debit and a credit card in the same physical card, choosing which you want to use after you insert it into the reader. These are unusual, perhaps because most people seem to prefer separate cards.
>The assertion that the United States is somehow behind Canada in payment technology because all credit card issuers do not issue cards with chip and PIN seems invalid to me.
The United States isn't just behind Canada, it's behind Europe, Australia, and most of Asia, as well.
I can send money from one European country to another in a regulated maximum of 15 seconds 24/7/365 (look up "SCT INST"), but the Americans can't get it from one bank to another in the same country quicker than a day or two (or sometimes three, apparently). Never mind consumers trying to punch in someone's ABA routing and account numbers to pay them... lol nope, hence the mess of insecure third-party services like Zelle, CashApp, etc.
Skimmers aren't really a thing in Europe because everything is EMV, and I don't mean the abortion which is chip-and-signature (although that still proves possession of the original card).
>Additionally the surprise at not requiring signatures. Merchants have been accepting contact-less enabled card payments in the United States, requiring no signature, for quite awhile.
Again you speak from whence you know not. Google Pay and Apple Pay use a different CVM, referred to as CDCVM, for which there is no PIN as user authentication is handled by the device (hence the need for a fingerprint or face scan before they can be used). For small transactions plastic cards are permitted to perform contactless transactions without a PIN in most countries for convenience as the risk of fraud is low given the maximum cumulative cap of perhaps €50/$50, configurable by the issuer, before a PIN becomes required, which caps the bank's liability in case of theft (since the cardholder is not on the hook for it).
>The $1 and the $2 notes stopped being issued in 1989 and 1996 respectively. They are not demonetized and you can still exchange such money at any bank in Canada, or the Bank of Canada, for its face value.
>https://www.bankofcanada.ca/banknotes/about-legal-tender/
Keep reading and you'll find they they do not meet the definition of legal tender. Like I said. Here's a quote from their site (https://www.bankofcanada.ca/banknotes/bank-note-redemption-s...)
=== Bank notes that are no longer legal tender
Since January 1, 2021, the Canadian $1, $2, $25, $500 and $1,000 bank notes are no longer considered legal tender. Essentially, this means that you may not be able to use them in cash transactions. ===
>> While all cards in Canada may have chip and PIN, no such event occurred where across the nation everyone started using it for every purchase, like there was no transition
> What the hell is this supposed to mean? EMV-enabled cards were rolled out as each bank got onboard, replacing cards at expiry with EMV-enabled ones. Eventually no further non-chip cards were issued.
> After a while, the same thing happened for contactless as well.
Again, I am explicitly making the claim that it is misleading to suggest Canada was ahead of the United States by mandating all credit cards have chip and PIN, because by then you could do the same thing with contactless (signatureless transations, with a benefit of not using a pin) just like in the United States.
>> nor different options to use with the same card.
> EMV supports multiple applets per card, so you can absolutely have a debit and a credit card in the same physical card, choosing which you want to use after you insert it into the reader. These are unusual, perhaps because most people seem to prefer separate cards.
I'm aware. I've had one.
>> The assertion that the United States is somehow behind Canada in payment technology because all credit card issuers do not issue cards with chip and PIN seems invalid to me.
> The United States isn't just behind Canada, it's behind Europe, Australia, and most of Asia, as well.
I kindly reject your assertion, because you are basing it on Canada requiring all cards have chip and PIN, but not enforcing its usage at all terminals.
> I can send money from one European country to another in a regulated maximum of 15 seconds 24/7/365 (look up "SCT INST"), but the Americans can't get it from one bank to another in the same country quicker than a day or two (or sometimes three, apparently). Never mind consumers trying to punch in someone's ABA routing and account numbers to pay them... lol nope, hence the mess of insecure third-party services like Zelle, CashApp, etc.
> Skimmers aren't really a thing in Europe because everything is EMV, and I don't mean the abortion which is chip-and-signature (although that still proves possession of the original card).
>> Additionally the surprise at not requiring signatures. Merchants have been accepting contact-less enabled card payments in the United States, requiring no signature, for quite awhile.
> Again you speak from whence you know not. Google Pay and Apple Pay use a different CVM, referred to as CDCVM, for which there is no PIN as user authentication is handled by the device (hence the need for a fingerprint or face scan before they can be used). For small transactions plastic cards are permitted to perform contactless transactions without a PIN in most countries for convenience as the risk of fraud is low given the maximum cumulative cap of perhaps €50/$50, configurable by the issuer, before a PIN becomes required, which caps the bank's liability in case of theft (since the cardholder is not on the hook for it).
I think we're done talking now, given you keep telling me I don't know what I'm saying, and you are obviously just ignoring the fact that I've been completing contactless, signatureless transactions with my credit card for a significant amount of my purchases made in the United States and Canada since 2008.
So most people dont write PIN.
Of course, since it’s the 2020s and not the 1990s we don’t need either since NFC is widely supported and an Apple/Google device transaction secured by biometrics on the client is far better and already widely supported.
For example, if the contactless limit is £100 and it only allows four contactless transactions in a row, the worst damage that can be done is £400, so banks and card issuers only need to manage the liability for fraudulent contactless transactions up to that amount (Visa and Mastercard call it "Zero Liability" protection).
You have to remember not one, not two, not three, but several digits. Not only that. You have to look at a keypad. Oh, and you have to push buttons. Not once, not twice, but several times! Pity the poor fool who accidentally pushes the wrong button. More looking at a keypad and button pushing!
Yeah, I don't get it either. My only guess is the customer support calls for forgotten pins are more expensive to deal with than dealing with the incidents of fraud the pin would prevent.
My debit card and its PIN are used for a few different things - in-store payments, using the ATM, and authenticating when in-person at a bank. The last one is interesting - each desk at the bank, both the tellers and the offices where you talk to someone, has a terminal and every interaction starts with putting in your debit card and entering your PIN.
Extending this to credit card is no big deal - my main bank syncs the PIN between the debit and credit cards. I only have a credit card with the other bank that I use and I haven't set foot in one of their branches in 20 years, so I have no idea whether they sync the PINs or use their cards for in-person authentication.
They've been presenting a credit card and making a squiggle with a pen for years and never remembered a PIN at all. Their credit card bill is paid electronically online somehow, either automatically because of a direct debit configuration setup years before or via an interactive banking website. These were authenticated with a web password and perhaps archaic knowledge of a routing number and checking account nunber. No PIN in sight there either...
Banks? A chargeback goes to the business.
And the public eat the inconvenience of having fraud transacted on their behalf.
Why merchants don't insist on C&P isn't clear, though I suspect that distributed liability, ignorance, disaggregated political voice (see Mancur Olson's "Logic of Collective Action" <https://www.thoughtco.com/the-logic-of-collective-action-114...>), as well as asymmetric cost/benefit incentives between specific retail points-of-presence (store managers and franchise owners) vs. corporate purchasing and policy (see the McDonalds ice cream machine fraud <https://www.wired.com/story/they-hacked-mcdonalds-ice-cream-...>. Multiple HN discussions: <https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...>.
Maybe it's because the prevalence of Interac already trained us to deal with PINs.
https://www.globalpaymentsintegrated.com/en-us/blog/2020/09/...
I'm unable to measure how "common" it was across two giant land masses with very different populations sizes. My personal story was paying by credit card via tap and requiring no signature, with a card issued in the United States while in Canada, and having people be very surprised at its use.
Over here they just moved the burden of fraudulent transactions to the merchant if they still swiped instead of using the chip.
Shops upgraded their equipment real f'n fast.
Gas stations, parking meters, and ticket dispensers at most train/bus stations. They should replace them but I figure the problem is that they are built in to giant kiosks
Airline ticket counters…
Replacing is not as simple as sending a new terminal. Then you’d have to integrate it with the legacy software workflow and modify the existing furniture at the airport to support a pin pad.
Also, we have your ID and you are going to be cleaning security, so we’re pretty certain you say who you are. Regardless of the physical security of the credit card.
> Airline ticket counters…
> Replacing is not as simple as sending a new terminal. Then you’d have to integrate it with the legacy software workflow and modify the existing furniture at the airport to support a pin pad.
The rest of the world figured this out long ago; this is already a solved problem.
The whole situation smells like it involves a lot of vendor lock-in, too (which I always hate to see).
I moved on and found a different lot.
Anyone who didn't think of providing a forward-compatible reader at any point in the last 10 yrs was driving into obsolence
I use my app, not my card, for this reason.
There is a huge difference between this kind of attack and what an attacker can do with the old scheme of magnetic swipe data over RFID. With the former, the only thing an attacker can do is perform a real transaction in that moment; this transaction leaves behind an audit trail tied to a real merchant (the operator of the terminal) and their bank account. An attacker cannot, however, initiate additional payments without accessing the payment card again, and without access to the cryptographic secrets held by the payment service provider, they cannot extract the card number to use for online transactions.
With the latter, it's equivalent to skimming a the magnetic stripe: an attacker can clone the card and reuse it for transactions as often as they'd like for whatever amounts they can authorize. In addition, they will have access to the plaintext card number, which would allow them to use it for online transactions. And absolutely none of this leaves behind an audit trail of how the attacker got your card.
Sucks that everything else about smart watches sucks tho. Thanks to Apple making the "pretty" Apple watch, other brands have forgone things like eink/mip displays that get better battery life. :/
Alternatively - do what Monzo does in the UK and issue cards with a magnetic stripe that is disabled in the backend by default.
If you try to use the magnetic stripe, it sends you an alert that says "Someone (possibly you) tried to pay using the magnetic stripe. Do you want to allow the magnetic stripe for the next hour?"
Then if you travel to a country that relies on magnetic stripe, similarly it sends you a message saying "You have travelled to X - sometimes you may need to enable the magnetic stripe in order to use an ATM. Do you want to temporarily enable the magnetic stripe?"
In Europe you can buy card terminals for €30 with no monthly fee, and you don't even have to be a registered business entity.
Now that I check, that same company exists in the US too:
Exactly the type of company that should be getting one of those portable card readers that can be easily replaced.
It can't be harder to enter an amount in the device and ask the customer to insert card and type pin than typing numbers or swiping many times, getting signatures, etc.
From the POV of these small business owners that Sumup terminal doesn't do anything to help them and if anything makes their life harder. It won't integrate with their business management software (our product) and most likely will have higher transaction fees than their current payment processor. The company I was with offered EMV terminals that were fully integrated with the management software (I helped write the integration), but there wasn't a lot of interest in them outside of larger companies. The small guys in general don't have a lot of incentive to care about information security. One of the other projects I worked on was migrating the management software from using encrypted CC numbers stored in its database to using tokens. When we took away the ability for users to unmask and view the full CC number some of them started saving saving card numbers in the plain text customer info fields (address, etc.).
"You won't be able to accept cards for payment unless you use an EMV terminal or tokenized card for recurrent CNP transactions."
Problem solved.
The deal with processors is this:
if you use chip + PIN or sig and there is fraud, it's on the processor (Visa/Mastercard, etc)
if you use swipe, it's on the retailer directly.
Also how is magnetic strip still a thing? I thought this was replaced with chip and tap years ago...
I admire your uncomplicated, predictable life.
Sometimes I want to buy something from a guy with the ice cream cart at the park. Sometimes I need to tip a valet, a doorman, a hotel maid, or another service worker. Sometimes I want to buy Girl Scout cookies from the girl with the table on the corner. Sometimes I want to buy something from one of the 35 million Americans without a bank account. Sometimes tow truck drivers take cash only. Many of the late-night restaurants and food carts in my city are cash only.
Some day I'll go cash-free. But my life is not yet that simple.
>Sometimes I want to buy Girl Scout cookies from the girl with the table on the corner
I have seen a lot of them carry Square dongles or accept Venmo payments. I guess they got tired of people telling them they do not have cash.
You can still count on old gas pumps and pay parking kiosks using mag stripes.
As for parent claiming my life is “uncomplicated” and “predictable” I won’t say they’re wrong. I have a pretty boring yet comfortable life.
Cash-only is far more prevalent than card swiping, and even that is incredibly rare.
2) In non-business "mode" it's still not your choice if the sender tags it as 'goods or service.'
3) Customers and Workers may be wary to potentially violate ToS by defrauding Venmo and/or the IRS by falsely tagging a transaction that there is an easily electronically auditable record of. Venmo ToS explains your account may be terminated and funds 'held' if you do this, and tons of random people sending you money on a regular schedule is easily identifiable as not 'friends and family.' This is far easier to trace than someone spending putting $200 in singles in a drawer at the end of the night and spending $20 x 10 at the grocery store.
4) Your 'pass-through' rent situation is far less falsely identifiable as goods and services income. 2000x people sending $5 over a year is far more identifiable to a computer than the exact same few people sending you $1k a month or whatever. A very large number (high hundreds to thousands) of nodes sending small amounts over the course of the year easily 'sniffs out' someone providing goods/services and can be bet on to be found out by Venmo compliance sooner or later.
0. https://help.venmo.com/hc/en-us/articles/4407389460499-2022-...
> Sometimes I want to buy something from a guy with the ice cream cart at the park.
The ice cream van that comes past our house is contactless card-only.
> Sometimes I need to tip ...
Ugh, tip culture!
> Sometimes I want to buy Girl Scout cookies from the girl with the table on the corner
She's probably got Square.
> Many of the late-night restaurants and food carts in my city are cash only.
Where they exist, they're more often card-only here.
This is not to say one is superior to the other, but it is very geographically and culturally dependent. If I had to choose to leave the house with either my Apple/Android-pay enabled phone or a pile of cash, the phone would get me a lot further in this country.
To be fair though, after seeing physical Canadian money (got some bills and coins for my son), US money isn't nearly as cool.
I think (in the UK), raising the contactless pay limit, and then all the places that just moved to fully cashless over covid accelerated everything.
I know it's a priveledged position to say it, but contactless is great and I absolutely don't miss cash and coins.
Sometimes I don't when my local ATM is down (which seems to happen so often...), but when I can it feels much better to me. No digital records, no potential for this type of skimmer or other scam, don't have to give up my ATM pin, no worrying about my phone running out of charge, able to give it away freely to anyone in need without setting up a digital transfer, the old taco truck still only takes cash, etc.
I will be sad when cash starts to be less accepted. Already there are a (small) number of modern restaurants that don't accept cash in my area.
Is that even legal?
[1]: https://legistar.council.nyc.gov/LegislationDetail.aspx?ID=3...
[2]: https://nypost.com/2021/12/04/nyc-businesses-told-to-pay-up-...
"There is no federal statute mandating that a private business, a person, or an organization must accept currency or coins as payment for goods or services. Private businesses are free to develop their own policies on whether to accept cash unless there is a state law that says otherwise."
https://www.federalreserve.gov/faqs/currency_12772.htm
It may be illegal to refuse cash as payment for an existing debt but businesses are free to choose how (and with whom) they conduct business, including which forms of payment they accept.
They can be mad about it, but I don't think I'm breaking any laws by not having their preferred payment method to pay that debt, right? They can even ban me from the restaurant but—for that meal—I can't get charged with theft of services (or whatever the innkeeper laws are that relate to this situation)
"All debts, public or private"
I don't understand. How are you not exposed to this type of skimmer when it only attacks those who use cash ATMs, like what you do?
Not exactly a grocery story, but it wasn't a single skimmer either.
Wow. This year in my area, a lot of the restaurants started charging 3% extra if you DON'T use cash.
And generally, in my state of Montana, there are still restaurants that won't accept credit cards at all.
Is it really no digital records, or just fewer/obfuscated digital records? I would think that the ATM keeps tracks of the serial numbers of the notes it gave you?
It would have been nice to have a backup.
The impetus to get retailers to start using the chip was "Liability shift". The payment networks gradually changed the rules (I think in the US pay-at-pump gasoline purchases were last to get this, while big retail stores were earlier) so that the liability if a transaction is latterly discovered to be fraudulent is with the retailer who accepted the dodgy transaction, not the payment network if the retailer didn't use the chip.
But I imagine if you're a little store in the country, maybe you do six card transactions per day, almost all of them with customers you know personally who just find the card more convenient, liability shift isn't a huge worry for you, while the cost of a new payment terminal is a significant issue.
The actual payment infrastructure doesn't care about any of this. Those old impression machines? Mag stripe? Put the card in manually? Tap your iPhone? In all cases the actual transaction which moves money, "Settlement", just needs the account number to take money from and amount to transfer. These different methods have different "Authorization" behaviour but Authorization is about mitigating risk for the retailer, and the bank, and only very tangentially intended to have any benefit for you to customer, it doesn't move money, and it isn't mandatory.
Good point. Not only do I still have cards with mag stripes, I still have some with embossed numbers. And probably half of the people with credit cards are younger than the date when that was obsoleted.
Maybe 50% of places around me accept Apple Pay but I haven’t personally had a card impressed in ~22 years.
And the fancy Amex tap card barely works -- Apple Pay is more reliable.
That's my use case.
But it does seem like the more secure these systems are getting, the less robust they are. Perhaps that's just one of the tradeoffs we have to accept. The college football season started with a game between Nebraska and Illinois in Dublin, Ireland. The beer at the game was free because there was a technical issue with the payment provider. Being a "cashless stadium", they simply had no way of accepting payment.
My recent cards (and not only mine, I saw that happen with others people cards too) just tell the terminal they can't be used by a mag stripe at all. I assume what the terminal without a smartcard/payless should allow a mag strip read, but I haven't seen them for like... 10 years? But I'm not in the US of A, for that matter.
And it means everything you buy is associated with you and recorded forever to be sold to endless advertisers (and worse) and the transaction may be blocked by third parties.
If you pay cash it works without a depending on anything external (no internet, no electricity), it is not traced, it can't be blocked by third parties.
Cash is the optimal payment mechanism for nearly everything. It only is inconvenient for very large payments, but for anything day-to-day, opt for cash.
If my credit card is stolen, I get my money back (so long as I reported it in time, and didn’t surrender to them my pin). Not so with cash.
Cards take a second or two to process payments on average. Not so wish cash.
My bank account / credit card limits always have enough to cover my purchases, whereas my physical wallet might be low/empty and require a trip to the ATM / bank for a withdrawal.
Re internet/electricity outages, this is so rare enough to not be a concern. POS can also do offline transactions just fine if you have power but no internet. And a lot of retail and critical infrastructure places have both wired and cellular Internet links for high availability.
There is definitely still a place for cash, but it’s not a big thing for a lot of people anymore.
The last time I used cash it was because my kid threw up in a taxi and I needed to quickly make it up to the driver. Yes I could have paid card as well, but seeing the physical cash was likely more meaningful to de-escalating the situation.
Security == privacy. And cash certainly wins availability by a long shot, it can't be blocked by any kind of outage. Convenience is arguable I suppose. I'd rather hand over cash than deal with anything electronic that can fail.
> If my credit card is stolen, I get my money back (so long as I reported it in time, and didn’t surrender to them my pin)
Credit cards don't have a PIN, that's a debit card. But yes, you get the money back from fraud with a credit card, that's true.
> Re internet/electricity outages, this is so rare enough to not be a concern.
Depends where you live I suppose. In many areas electricity outages are a daily occurrence.
They do in most countries.
Debit cards, however, are downright nazis about PINs.
I wasn't aware that Chip+Signature cards even exist in europe.
Whereas the US is all over the place with different methods for different cards, and mag stripes still in use, sometimes requiring you to enter a PIN alongside that, all largely driven by retailer reticence to update their hardware.
I’ve lived in 4 continents, never had daily, weekly, or even monthly outages.
> Security == privacy. And cash certainly wins availability by a long shot, it can't be blocked by any kind of outage.
If you don’t have enough cash in your wallet then you don’t have any availability. If you have a internet outage your debit/credit cards still work offline.
Also security does not equal privacy. If you are living in a state where this is true, you have bigger issues with the entire system than ATM skimmers.
> Credit cards don't have a PIN, that's a debit card.
Everywhere I have lived bar the US has PINs on all card types. It’s only a matter of time before it becomes ubiquitous in the US too.
Not when the store is offline.
The convenience store just up the street from here every now and then goes cash-only whenever their connectivity is down.
This is definitely not true in my part of the US. Internet outages are not common, but they're also not rare. I see it happen 3 or 4 times per month.
FYI, you don't need internet connectivity to pay using apple/android pay.
And waving my phone at a payment device is massively more convenient than having to go to an ATM to withdraw cash, and then pay with said cash.
There are also quite a few payment terminals that still do dial-on-demand to get authorisation from the merchant service provider (Chip&PIN/NFC Contactless).
I still see those in the UK especially at independent fuel stations. The additional delay waiting for the terminal to dial and connect sometimes makes me think it has failed - had a few occasions where the line was busy and the terminal redialled several times before it finally made it!
https://en.wikipedia.org/wiki/Fiscalization
If you want to sell anything to anyone, and you're in the VAT system, you have to be online at all times.
Personally I default to chipped credit cards but carry a few bucks with me too.
Also in general I don’t like to be utterly dependent on my phone especially if I’m traveling.
Merchants not having connectivity is a rather small problem in this day and age really, with ubiquitous mobile data connections. (Yes, I am aware someone will be along shortly to tell me they have yet-another-edge case where it doesn't work for them. I don't really care, for the vast majority it is a massively convenient way to conduct business.)
So I have no risk of some company unrelated to my banking erasing my digital existence and making me unable to pay.
Anyway, I have a few of these I use for pentests / audits https://electroniccats.com/store/huntercat/
I've caught and reported two pumps at fuel stations near where I live. One of them I watcheded when the police showed up and with the fuel station employee removed the ble module storing the data.
I think though for gas pump skimmers, there are devices that plug into the pins of the OEM card reader and just copy the data straight from the OEM card reader. (The thieves just get a universal gas pump key to open up the cover and install their device inside the pump, which is why you see those tamper stickers.)
- Those tap targets on CC readers sometimes aren't where the antenna is, and you have to rub your card all over the reader to get it to work?
- Chip transactions take way longer than tap transactions, like 10 seconds? Why?
Fraud clearly hasn't had a deleterious effect on the entire system, and the penalties for fraud align incentives to fight fraud properly. It's not such a large problem that I'm willing to take steps backwards in terms of functionality and privacy to digitize my purchasing.
And mobile phone providers over here don't guarantee even two nines of reliability, never mind that even 3½ days of no service per year is already too much for some critical things, like being able to get at your money.
And the local public transport association for example tries to disclaim any responsibility for any sort of problems if you're using their mobile ticketing app – if it doesn't work, though luck, your problem, buy a new ticket or pay a fine. Even if you've bought a monthly season ticket there are no special provisions, and the rules don't even differentiate between technical issues caused by myself [1], those caused by third parties (like the mobile service provider) or those caused by the public transport provider respectively its app developers themselves.
[1] Although while I can take care to keep it sufficiently charged, not letting it fall to the ground or whatever, I still can't prevent it from just randomly dying anyway, or the manufacturer issuing some borked update or whatever
Powered devices like a phone have read/write NFC chips that the device will write data to on demand, usually waiting for some form of user auth to make it secure, e.g. an iPhone keeps the NFC chip empty until you specifically request to pay for something, at which point it authenticates you (e.g. with FaceID) and then writes the data to the chip which can then be read by the terminal to authorize payment. Once payment has been made it wipes the NFC chip again.
But a device can have some payment info written to the NFC chip at all times, which is what iPhones do when you have the "Express Transit Card" option enabled – with certain authorized vendors, that payment data stays on your phones NFC chip indefinitely, so you don't need to auth with FaceID and even when the phone is out of battery it can still be read by those authorized terminals.
I now need a phone that I keep charged, up to date, with cellular connectivity, and logged into some tech behemoth in order to pay for goods?
plus on the bus or train I usually use a book or my kindle so it's easy to forget the phone
I have no issues with the icon for tap. Although they do seem to rub off and I wonder if they are meant to have an accessible braille pattern.
My dislike is tapping the screen, because then you block the visual feedback mechanism that lets you know whether it worked.
I have OP’s problem too. When there’s an icon it’s easy, but some terminals (older ones?) don’t have the icon anywhere but support the functionality so you just have to sort of try to figure out where it is.
It can also be a problem on small terminals. The bigger ones have plenty of room, but sometimes the small ones put it awkwardly on the back where you would never look for it.
This gets me every time
I actually find the "Square" based nfc readers to be the best. There's no real feedback because it's just a tiny, watch sized brick that you pass your card anywhere in the vicinity of and it reads it so fast you basically can't screw it up.
You could also do something like set the PIN for a given card to the security code backwards or to the last two digits of the account number concatenated with the first two digits of the security code.
Either of those should be fine under the threat models applicable to most HN readers.
From a few cursory searches, it seems like 1. people generally build their own skimming tools by following guides; and 2. this isn't organized crime, but usually just some really obsessive individuals thinking they can get rich quick.
(If you think about it, the incentives for selling the skimming tools themselves are all wrong: if someone with sloppy OpSec buys your tool and uses it, and it gets into the bank's hands to be studied, they've now ruined it for all your other customers.)
From [0]:
According to Apple's site, "the leather wallet is shielded so it’s safe for credit cards." That shield protects both Low Coercivity (LoCo) and High Coercivity (HiCo) cards — which is a fancy way of saying how resistant something is from being demagnetized. So, LoCo cards are considered things like hotel keys and gift cards while credit cards fall under HiCo.
[0] https://mashable.com/article/apple-magsafe-iphone-wallet-dem...
Let a thousand blossoms bloom, I guess.
Not that they're even used that often these days either: everything is just tap-and-go NFC payment now.
And I do mean everything!
I've had the chip struggle like once in my life. That was on a card very near it's expiration date. Most people I see in the store have no problems with their payment method, and when I was a cashier in 2012, people seemed to have significantly more problems getting their magstripes to scan.
All of this is SUPER dependent on which flavor/brand of POS is popular around you, the effort your bank put into making a good implementation, and whether your local merchants actually put effort into running their business and keeping equipment maintained. Pretty much nothing in this discussion is generalizeable to all of the US other than "We were late to the party of chip cards"
Here's an example image from a NY Times story about chips wearing down:
https://i.imgur.com/XlKEBsc.jpg
The last card I replaced due to chip wear, the chip looked even worse than that.
As far as I'm concerned, chip cards can get stuffed. They're utter shit in my experience.
I don't think I am. All I do is take it out of my wallet, put in the reader, take it out, put it back in my wallet, lather, rinse, repeat.
or your local merchants use "special" terminals
That would make sense if we were talking about one merchant, or even just two. But I can go to Barnes & Noble, Lowes, Food Lion, the local corner gas station, Ace Hardware, it doesn't matter, I routinely find the chip readers less reliable than the magstripe reader. I can't explain it, but chips are tainted in my worldview at this point.
Here in the UK, many (most?) new payment terminals don't have mag-stripe readers at all. And I expect banks will start issuing new cards without a magnetic strip in the near future, if they haven't done so already.
I agree that chip & pin isn't ideal, not just because of reliability issues but also because of the security risk of PIN disclosure. But thankfully contactless (incl. Apple Pay/Android Pay) has already replaced it for 99% of daily transactions.
But if your card's chip is broken, can't you just get your bank to send out a new one?
Of course I can. But that means I have to stop and take time out of my day to call my bank and dick around with them. And then if the new card comes with a new number (I don't know if it will or not), and/or expiration date (that almost certainly will change), then I have to login to EVERY SINGLE ONE of the places online where I use that card for some kind of automatic payment and change the payment details. I'm extremely loathe to do that, because it's incredibly tedious and painful, and I always miss one anyway and wind up getting scary emails about how my account is about to be closed.
Sure, my hand will probably be forced on this sooner or later. But as it stands, I just haven't cared enough to deal with all of that.
Your new card will have a new number and expiry date, but the old one will remain valid.
In any case, these days my web browser remembers card numbers and fills them in automatically, so it’s really not such a big deal to update card numbers online.
That's a good point. I guess I should call them and see if that's an option. If so, that sounds like the best of both worlds.
I could also buy a phone that has NFC / tap to pay support, and link my card to Google Wallet and use that. An awful lot of the place I shop support that these days...
I’ve had no problems with their readers since I started doing that.
This explains a lot.
Sorry you can’t buy lunch, but the hold will get released in a few days, so it’s ok!
There’s got to be a better way…
I've bought gas in France with a Monzo card and the pump was able to hold and release money immediately - ~150EUR hold initially, as soon as I put the pump down it adjusted to the real amount.
Seems like the tech to make this happen does exist, it's just a matter of not using a shitty bank.
LOL. It's convenient for bar owners. Patrons doesn't give a shit about that.
What a security nightmare.
I really haven't heard of much trouble caused by these systems - of course, they require magnetic stripes in general, which are a massive attack vector, but the bar use case specifically doesn't seem to cause additional issues that I'm aware of. There are so many lower-tech and easy ways to steal magnetic track data, like skimmers, that I don't think compromising bar-back point of sale systems is a particularly high priority for most criminals.
Anyway, this is probably just a small snapshot in time regardless, since once swiped-card transactions finally go away US bars will have to switch to the mobile terminal pay-as-you-go method anyway.
Now you get it.
I understand why Germany, a poorer country which was late to electronic payments, wouldn't do this; I don't understand the hostility to it. But then, I'm American, we've been doing this longer than you've been alive.
But having a clunky thing at home you stick your debit card in is okay too! I guess.
You mean payments between banks that take two to three days within the country instead of a regulated maximum of 15 seconds across borders?
It's a shame you're so salty that the rest of the world has far overtaken the US. You may have been doing it "longer", but you've absolutely failed to iterate and are still stuck with obsolete technology that's rife with fraud, for which a more appropriate feeling than saltiness is shame.
???
Yes you can. At least the bars around me have no problem with holding a tab with chip and/or tap. Maybe they just use newer terminals.
Don't people have wireless terminals in the US like the rest of the world?
Some establishments take your card as collateral, some actually swipe it into their system to keep track, but that's not that common.
I don't remember when I last saw a person not taping with phone or watch.
But they also maintain an internal blacklist of declined cards, so the most you'll get away with is one day's travel around London. Per card.
Not sure why iPhone engineering didn’t anticipate this happening, but the flatulence kept my boss away so everything worked out.
Is it? Numerous people up and down this thread who do use the official one have told you they've not experienced it, so I'm not sure your assumption holds.
> I should say I’m actually not using the official Apple magnetic case but the Popwallet brand
I don't understand why you would start this comment thread with a false statement though.
One, it is a light hearted comment. I’m mostly just having some fun. Two, I suspect that the official wallet would have the same problem. The point is that apple designed a system where the wallet has to have magnets in it. The official apple product documentation states that there are in fact magnets in their wallet. And yes, just like my Popwallet brand, the inside of Apple’s wallet is magnetically shielded. The issue comes when you are handling the small removable wallet and your cards together. If you place your card next to the side of the wallet with magnets, you’re exposing it to the magnet without any shielding to protect your card.
I don’t have an official Apple wallet to test, but Apple repeatedly makes the same claim as the Popwallet - that the inside of the wallet is shielded. I think the problem is that apple designed a system where cards and magnets are close together, and during handling it is easy to expose the card to the unshielded side. This is why I think it is appropriate to jab at apple.
But… it doesn’t.
Thanks, I needed this laugh.
Living in Canada, there's basically no instance where we'd swipe our credit cards, but they've still got mag stripes; and when I visit the US, I sometimes have to swipe my card, and it does work to do so.
I don't know about other countries, but a few days ago I got a new Visa card in France. It still has the magnetic stripe. I'm not sure if I've ever seen it used here, but a few years ago I think they were still in use in German gas stations (at least).
Some banks have a nice feature where they allow you to disable the magnetic strip of the card. I presume the information is still physically on the card, but they can somehow know that the payment was done that way and decline it.
People never complain that tiny devices are too small for their big hands — they correctly conclude that they're made for children or for adults with small hands. But for some reason people expect to be able to use huge phones and phablets with regular-sized hands, rather than accepting that they're intended to be comfortably held by people with huge hands, who find regular-sized phones too small.
That seems like a distinction worth mentioning, especially with the first comment on the article.
While it seems reasonable that Apple's wallet might have the same problem, you dont actually know.
Some sort of one-time verification would be great. An SMS or a push notification would go a long way to making this type of scraping harder.
Or eliminate the card altogether - Cardless Cash.
Absolutely. Here in the Netherlands, magstripe payments are disabled by default. Only if you’re travelling outside Europe do you need to enable them manually (through your bank’s app or website).
Chip and pin and NFC terminals have been a standard in the UK for over a decade now. I wouldn't be surprised if magnetic stripe readers still exist only for US tourists.
> The magnetic stripe will start to disappear in 2024 from Mastercard payment cards in regions, such as Europe, where chip cards are already widely used. Banks in the U.S. will no longer be required to issue chip cards with a magnetic stripe, starting in 2027.
https://www.mastercard.com/news/perspectives/2021/magnetic-s...
I think it has been over a decade since my last magstripe transaction (in a convenience store I frequented that switched to chip readers in 2010).
(Kidding/Not kidding)
I suppose after the stripe goes away, they'll have to improve these machines in a hurry. I just don't understand how they're so shitty and yet the rest of the world seems to be using them without issue.
Not sure I understand what you mean. NFC readers?
Not just one, every merchant bank and payments terminal operator supports NFC.
I haven't seen a terminal that doesn't accept NFC for years.
As a person who was quite amused by a [quite gentry, ie recently entered the workforce afain] Domino's staff who didn't even knew how to handle a magstripe in 2016 I find this is quite baffling.
> Shockingly, few people bother to take this simple, effective step.
I haven't taken cash out of an ATM (or carried cash altogether) for years now, but I never really used to do this as I always assumed it was protecting against the threat of someone looking over your shoulder and then subsequently mugging you.
If I ever end up using a cash machine again, I will be sure to cover the digits. Thanks Krebs!
Yes, more or less. The chip and contactless flows defined by EMV both require the card to generate a nonce for the transaction. The terminal also generates its own nonce[1].
Anyway, the EMV test spec tells them to ensure the numbers are different not that they're random even though the cryptography requires randomness to work. So if you make terminals, the way to ensure you pass is not to use random numbers, as there's a tiny chance a random number fails the test. To pass, just ensure you emit a sequence of different numbers. For example 1, 2, 3, 4, 5. That's not random at all, but it's different and so it passes the test.
As you would expect this is an exploitable bug. Light Blue Touchpaper covered this years back.
There’s ~4e23 _grains of sand_ on Earth. There are more possible values in 128 bits than grains of sand on Earth.
Take it further. There are 10^11 stars in our galaxy. If every star in the Milky Way had a planet identical to Earth orbiting it, there would be ~4e35 grains of sand on all the Earths orbiting all the stars of the Milky Way.[1]
If you assigned each of those grains to its own value, we’d only need 0.11% of the possible values of 2^128.[2]
I think it’s safe to say those bureaucrats are wrong :)
1: https://www.wolframalpha.com/input?i=%28number+of+stars+in+t...
Here are some of the "Unpredictable numbers" from a series of EMV transactions reported in a paper in 2014:
F1246E04, F1241354, F1244328, F1247348
That's a 32-bit value, so not enough to count living humans, never mind grains of sand. And it's not very "Unpredictable", indeed the researchers have more data from the logs which allows them to predict with confidence future values from that same terminal, basically the low 15 bits are a clock which repeats every 32768 cycles, with cycles having a fixed duration of several milliseconds. The high bits, if they change, don't change for a prolonged period.
It certainly can't be done with "pure" unit tests, and it would be difficult to ensure sufficient entropy even with "impure" tests that examine multiple nonces generated in sequence.
Do you happen to have a link to the paper you mentioned?
... mentions these values and links a paper they wrote, I suspect it isn't the 2014 paper I was thinking about but it's on the same topic.
The good news is that in the years after this work, I believe the rules were tightened up, there's a good chance if you buy a brand new EMV terminal the people testing it wouldn't have accepted 1, 2, 3, 4, 5 as a series of "Unpredictable numbers", so crooks today are less likely to be able to exploit this, and more likely to get caught.
The bad news is that courts remain very easily persuaded that banks know what they're doing, and expert witnesses who can make it clear that the bank have no idea what they're doing and shouldn't be trusted more than a typical citizen are expensive. If it ends up being your word against a bank, the court is probably going to believe the bank.
Also there are transaction counters involved. So even if you could overcome that the processor would see that your card had two transactions with counter 268753 and reject the second. The terminal also has its own transactions counter mixed in too.
And even if you could overcome those I’m almost positive that timestamps are involved too. So even if you could replay the transaction to the same exact terminal and get around the transaction counter issue the time would be different and I think that would cause it to fail.
It really is a well designed system. It follows that software law that people can know absolutely everything about the process and it’s still secure as long as the private keys aren’t given away.
The skimmers here have a passthrough hole for the chip which means the mag-stripe only exists to feed the skimmers. So even this use case that gets skimmed isn't even using the mag-stripe itself!
Fuck it. Where's my magnet.
In my county you literally get messages for every transaction. And you also have to add in otp for every transaction online.
I believe this difference is because in the US merchants are on the hook for fraudulent transactions and in the rest of the world the customer is on the hook.
So if someone steals my card and makes a bad transaction, I just go into the app, flag it as fraud/not me and no money comes out of my bank account. The merchant ends up eating the cost because it's better for them to eat a small fraud percentage than to add more friction to the checkout process.
Most of my cards offer an email notification option rather than SMS or in-app. Much less intrusive.
Limit interruptions with Do Not Disturb on Android: https://support.google.com/android/answer/9069335?hl=en
Lastly but most importantly, covering the PIN pad with your hand defeats one key component of most skimmer scams: The spy camera that thieves typically hide somewhere on or near the compromised ATM to capture customers entering their PINs.
So keep your wits about you when you’re at the ATM, and avoid dodgy-looking and standalone cash machines in low-lit areas, if possible. When possible, stick to ATMs that are physically installed at a bank. And be especially vigilant when withdrawing cash on the weekends; thieves tend to install skimming devices on Saturdays after business hours — when they know the bank won’t be open again for more than 24 hours.
Lastly but most importantly, covering the PIN pad with your hand defeats one key component of most skimmer scams: The spy camera that thieves typically hide somewhere on or near the compromised ATM to capture customers entering their PINs.
The point I'm trying to make is that technology introduces risks that cannot really be quantified - you won't even know that someone has stolen from you for a while by cloning your card (a few hours/days) - with cash if it is stolen it is obvious immediately. This lack of access and ability to get an accurate picture of your finances is not going to get better with crypto.
>> most importantly, covering the PIN pad with your hand defeats one key component of most skimmer scams: The spy camera that thieves typically hide somewhere on or near the compromised ATM to capture customers entering their PINs.
>>Shockingly, few people bother to take this simple, effective step. Or at least, that’s what KrebsOnSecurity found in this skimmer tale from 2012, wherein we obtained hours worth of video seized from two ATM skimming operations and saw customer after customer walk up, insert their cards and punch in their digits — all in the clear.
That's why you usually need an external push to advance security. Manufacturers/businesses didn't drop CFC, lead, asbestos,... voluntarily, usually there's fierce resistance. Wireless tap payment terminals run for less than 50 bucks in retail stores, it's a negligible expense for any business (that's why you even see them among street vendors, restaurants where each waiter has their own terminal...).
I suppose you could get an “associate card” and destructively disable the chip and magstripe to accomplish your goal.
Since they don’t serve a purpose anymore since absolutely no one uses the old carbon copy system… I’m a little surprised they lasted this long.
Since we are talking about payment card skimmers, "contactless" feels appropriate here too.
I would love it if my bank would let me use my virtual debit card with a contactless flow to withdraw cash. I'd imagine that's much harder to replay or otherwise manipulate. I've seen some ATMs (mostly Chase?) with the contactless symbol on them, but I've never been able to get them to work.
(The bank I use does actually use JPMC as their customer bank, so I was hoping that Chase ATMs would see my card as a "whitelabeled" Chase card. But no such luck.)
I haven't looked into it, but I would guess that there's a key exchange with the reader that binds the contactless payment to that reader in such a way that the card produces a signed unique identity that proves it is the card without leaking the actual card numbers to the reader. Just a guess, but that's how I would want to build something like this. You don't have that much room on a chip but way more than a magstripe. (Security pattern: something you have that is time/merchant delimited)
I believe that in magstripe they just have a strip magnetized to produce some digits + your pin (Security pattern: something you know + something you have).
(Actually I haven't done this. But really, shouldn't it be that simple?)
The large local bank in my city doesn’t support it. Their ATMs only started using EMV as few years ago. I’ve seen contactless on national chain bank ATMs once or twice but I don’t think it worked for me for some reason.
If I ever actually need it (very rare) I can just pull the tape off.
Or erase your stripe.
How? I thought all ATMs ignore the magstripe and just read the chip nowadays.
a) You can still run transactions as magstripe-only transactions (without any PIN or even signature required) or
b) copy the security code (which on most American cards are also encoded on the magstripe) and use it online (CNP transactions). If you're familiar with 3D secure, most American banks and merchants don't require 3D secure to buy.
Honestly I didn’t start seeing EMV/contactless available on gas pumps until about 18 months ago.
The larger the installed base, the higher the likelihood it is lagging behind the current patch revision.
Magstripes and internal combustion engine ground vehicles are probably the two biggest examples outside of sociology/government.
The cards are very insecure and primitive and have been replaced by smart phones in most areas.
One core way they are insecure is based on the main concept of the money which fails to utilize cryptography. Any money that uses cryptography to prevent the need for sharing secrets to execute transactions is a cryptocurrency. Any currency that does not use cryptography is obsolete.
Using physical pieces of paper is also ridiculous at this point. The only real utility is to avoid any kind of taxation, and the only reason that is needed by people is because governmental structures are also horrible and obsolescent.
#1) cash works without power, #2) cash has different security and privacy pros and cons, compared to cryptocurrencies
People like to use this type of rhetoric around crypto and crypto-maximalism, but you absolutely cannot function day to day using purely crypto at this point in time.
The only thing it compares favorably (and I’m being generous) to in terms of payment security is magstripes, which is a 1960s technology.
QR codes have basically no inherent security. They are just barcodes in two dimensions. You can do physical MITM attacks on them very easily.
For instance: https://www.techinasia.com/fake-qr-code-scams-china
Eg the whole class of vulnerabilities from card theft and card skimming disappears with QRs
Edit: I mean you could have a computer screen display the QR. How are you going to MITM between the screen and your phone?
Smart cards at least can at least implement public/private keys.