Contactless 'charging errors' at Marks and Spencer
bbc.co.uk
bbc.co.uk
This system was pretty much designed to be abused.
http://www.idstronghold.com/RFID-Blocking-Secure-Wallet-Bi-F...
I have no affiliation with this company. The linked story and my need for a new wallet and google did the trick.
The first customer was able to obtain a refund after demonstrating the problem to the store manager.
Outside those, I agree, there's quite a large possibility for issues, though this seems weird that it seems to be happening from significantly larger distances than it's designed to work under. To such an extent that I suspect some / all of these people are simply not remembering correctly - they swung their purse between hands, bringing it near the reader, or something. People are forgetful, and this is way way outside what anyone else can replicate that I've seen.
isn't it then just cash that you can take without touching?
The security measures are pretty good actually:
- Can't pay for things costing more than £20 via contactless (have to use chip and pin, the 'normal'/old method)
- After a certain number of continuous contactless payments, it will ask you for your PIN to verify the cardholder is still in possession of the card. This 'counter' is reset to 0 every time you pay for using Chip and PIN. E.g. if you alternate between contactless and Chip and PIN, you'll never have to enter your PIN for the contactless payment.
- If your card does get skimmed, your bank will cover you for any losses.
Skimming is possible yes, but you really have to be pretty close (the article is the exception here, not the norm). Within a few cm of the card, which it's certainly possible to skim someone's card - the person would almost certainly notice.
(serious question)
If you manage to get a proper shop terminal(which are only given to proper registered businesses) then yes, you could theoretically skim peoples' cards in a bus or any other public place. The only problem with that is, that you can only charge at most 15 quid, and you cannot get the card details back, so you can't use it for internet payments. And because the bank has your details they can very very quickly track the payments back to you and stop you from stealing money(and not even pay out any money to your account). So yes, the trouble is completely not worth it, which is why probably no one will do that.
http://www.v3.co.uk/v3-uk/news/2163404/researchers-punch-hol...
I don't know how serious this problem is, but since this is the first we're hearing about it it must be pretty rare, as contactless cards are much more widely used in, say, Hong Kong.
We're designing an easy method of paying for small items, not arming nuclear weapons. We'll accept 1 in 1e6 errors.
It scares me that they could charge any amount and you wouldn't know.
Why, yes, I've been the receiving end of a similar scam. It was Visa Electron and PIN-less purchases, then a new opt-out feature. The math was more like 5 customers, but 10,000 euro limit. (No, I did not lose that, or even close, by being lucky.)
The card readers rarely function adequately if at all. On occasions when they do work, the screen is broken meaning the customer can't identify whether payment has been requested, the amount requested, whether payment has been made, how much you are being charged, or even whether you are paying the bill of the correct till.
The cards interfere with each other and in particular with Oyster transport card in London - people use their Oyster card frequently and therefore have that in primary location: still have to pull out whichever other card they want to pay with.
In practice, people don't often use contactless cards and most customers I've observed attempting to use them express fear and wish to revert to traditional method.
The receipt is still the final part of the transaction, which customers are more inclined to wait for because they have no other way of confirming what just happened.
I've seen a broken screen on a contactless reader once, however I've also seen lots of broken Chip and Pin readers -- doesn't make the system faulty.
All contactless systems I've seen are either built-in to the same unit as the Chip and Pin device (which has a display) -- or a separate reader, which also has a display. Both clearly state when payment has been requested, and how much you are being charged. The problem of '[..] or even whether you are paying the bill of the correct till.' is rarely ever a problem at all. With the vast, vast, vast majority of readers, it's instantly obvious which reader you should use (because it's right in front of you!). Besides, if it's not immediately 100% obvious which reader you should use, the cashier will point it out to you, but again, this 'problem' is not a regression on chip and pin, which suffers from this.
Contactless payment is a hugely popular choice of payment in central London. Take a look at a Pret or Eat (or indeed, M&S) at lunchtime. Consumers aren't in the least bit scared about contactless, nor do they 'express fear'. Everyone I've spoken to about contactless has absolutely loved it. It's unbelievably convenient for consumers and a huge win for businesses too.
Agree with the interference though, that is annoying. That said, anyone with any sense doesn't keep their Oyster in their wallet :). Having to hold your wallet out in your hand and place it on the sensor is just asking for someone to grab your wallet (keep oyster in separate pocket during journey, replace during wallet upon arrival at destination).
And you are completely wrong to say that the customers don't know if the transaction was approved or not - the terminal definitely shows "Transaction Approved" when using a contacless card.
exactly - the fact that the cashier doesn't know this payment type exists shows how often it's being used.
I've had a MIFARE card crack starting from an edge, sectioning the loop antenna. I couldn't get it to work again even if pressing the two sides together, and it wasn't visible unless pulling the two sides apart, so this seems like a better approach.
If so, presumably someone could make a targetted aerial which would allow functioning over greater distance (like the 'pringle can wifi' approach). If I understand correctly, you will still increase the distance with only one end using a directional antennae.
If so, couldn't someone walk through a crowd and skim passers-by fairly easily?
Install this app and start stealing credit cards today! http://sourceforge.net/p/nfcproxy/wiki/Home/
[i.e. someone with a auth key can basically choose to charge people what they want (by using modified aerials), it's up the the people charged to complain sufficiently to get that auth key revoked]
I'd imagine that there might be a low bar of complaints to get a key revoked, but perhaps a higher bar to start legal proceedings?