How Apple’s Lightning-Plug Guru Reinvented Square’s Card Reader
wired.com
wired.com
The magnetic stripe on your credit card stores data in two separate bands. The old Reader grabbed from just one. With their new custom read head, Square can grab both, which makes every swipe more accurate, and more likely to work on one try.
There are three tracks on a magnetic stripe (IATA, ABA and THRIFT), the first two are used in banking. The first track stores alphanumeric data such as your name; the second track stores numerical data, namely the card number. Reading both tracks doesn't make the swipe "more accurate" at all, since there is no redundancy there.
On one level, developing a custom chip gave Square total control over the processes at the heart of the product: Decoding the magnetic signal from the credit card, encoding the electrical signal being sent to the smartphone, and all the encryption that happens in between.
First, the decoding of the swipe does not happen on the reader. The first version of Square sent the entire audio clip to their servers for decoding; this new version may do it on the phone. Secondly, there is absolutely no encryption between the reader and the phone, any encryption is between the phone and their servers.
The old version relied on a coin cell, which added around two millimeters to the overall thickness of the device. With their own chip, though, Square was able to be much more efficient in their use of power, to the point that they could draw all they needed from the smartphone via the audio jack.
An audio jack provides no power. The signal is created by electromagnetic induction. The previous version of Square used a battery to amplify that signal.
Edit: Square claims their new readers do some sort of "encryption." I am skeptical, but I had only tested the first version of the reader.
Huh? I thought that you could get a limited amount of power from the audio jack by playing a tone through it while something's connected. http://stackoverflow.com/questions/5560867/how-to-get-electr... seems to agree.
This is like using a side effect in software to initialize a variable. Clever but not durably so.
Explain? Even if we ignore losses, the 'audio out' signal does work when it drives headphones.
I understand that an AC signal does not perform work when the current and voltage are perfectly out of phase, but that does not describe audio or else there would be no power transfer to drive the transducer.
Something designed to supply power will deliver its rated power continuously.
So the audio out signal is designed to drive headphones without distortion between a lower and upper frequency. It also has a power dissipation limit based on what the guy designing it figured you might be listening too and for how long and at what volume. If you guess wrong (as some of the imported "external speakers" for the iPhone did), you risk damaging the headphone amplifier permanently.
So "Yes" there is going to be power available in the audio out signal, how much over what time period, is not part of the externally visible specification. If you damage your phone by attempting to draw too much power they don't fix it because "technically" you were not using it in an approved way.
Does that help?
Converting magnetic signal to audio is a decoding and conversion. There may be more down the line, but it is still one step that can be called that.
Similarly, there are plenty of pet projects out there that harvest the audio jack for power, like running an IR LED. You are just plain wrong on that point. There isn't any issue playing sound out while recording in.
Your comment would match the first generations of readers, but they've iterated on them quite a bit since then.
Track 1 and 2 both contain the account number (PAN) on credit cards. This article matches up what I saw when I worked in the payment industry:
http://blog.opensecurityresearch.com/2012/02/deconstructing-...
Also, if the reader manages to grab two error free tracks, it could compare them for accuracy.
http://web.eecs.umich.edu/~prabal/pubs/papers/kuo10hijack.pd...
Really? It seems it's inarguably a crappy power supply but these people were able to extract over ten mW continuously from an iPhone 3GS's headphone jack, more than enough to run i.e. a commodity RFID chip.
https://origin.bankrate.com/finance/credit-cards/are-chip-an...
Supposedly the big motivator behind the chip and PIN push in other countries is that liability for fraudulent transactions could be pushed onto the cardholder. ("You didn't guard your PIN and your money was stolen, sucks for you.") That article says that Regulation E of the Electronic Funds Transfer Act of 1978 in the United States prohibits such a shift by US banks. Without the motivation, banks in the US haven't invested in the infrastructure because it doesn't get them anything. Swiping a card "just works," people are used to it, it's a solved problem, and doesn't require any new outlays of money (not just for the cards and readers, also advertising about how it works, increased call center staff for confused customers, more livery for merchants, and so on) so I guess they're letting sleeping dogs lie.
I think this is Square's biggest problem when it comes to global expansion. It's relatively easy for a company like Stripe to launch in Europe: fundamentally the problem is one of paperwork, negotiation, and contracts. For Square, it's all this plus hardware - EMV hardware that needs to be certified by the card issuers, and that's considerably more complex and probably can't be given away for free.
I wonder how close Square are to having an EMV solution that's cost effective and can work for them...
The perpetual auto-loop is not quite perfect, but I can't think of a better alternative. I wonder it's hardware accelerated on most phones or if its sucking battery. I assume the browser is definitely smart enough not to render it when it's off screen, but the loop is too tight to try to 'test' that by timing it while scrolling.
I'm not at home but I'm curious what the bitrate is, what tools are used to produce it. I know anigif is popular on reddit and tumblr, nice to see it getting used in this way.
> You have to make the swipe feel satisfying; you have to make it ready [sic] accurately enough that it works the first, every time.
I don't think you have to do this. I've used a number of card readers that didn't read my card the first time (or the second, or the third), and that didn't feel good at all. They still collected my money successfully :)
So they may not successfully collect money from people at the end of the line.