- [Dump card into Downloads](https://github.com/MatusKysel/EMVemulator/blob/master/src/co...)
- [Read card from Downloads](https://github.com/MatusKysel/EMVemulator/blob/master/src/co...)
- [Respond to NFC requests](https://github.com/MatusKysel/EMVemulator/blob/master/src/co...)
Edit: Reading that is...
You might also be interested in Coin: https://onlycoin.com/
Or should I rush out tomorrow and get one? (Australia, so yep, all of them are paywave, whether you want them or not).
But this whole attack isn't anything new — this was pretty widely reported back in 2012 in the UK, e.g. http://www.channel4.com/news/millions-of-barclays-card-users...
I wrote essentially the same proof of concept app two years ago after seeing that report pretty much just by reading the specs. From reading the paper mentioned on GitHub, the only real difference to what I wrote is that I didn't check for the CVC3 information (which I think is generally not included, or doesn't correspond to the actual security code on the back of the card).
But in any case, just the card number and expiry number are enough — as mentioned in the Channel 4 report — to make purchases from a lot of places.
The app read the card correctly and gave the card number and expiry. When I tried to use it in store the eftpos terminal returned roughly: Err 226 contactless card not allowed. The terminal fell back to swipe/insert mode and the merchant told me 'contactless not allowed'. Inserted the (same) card and paid successfully.
I was disappointed because for me, being able to carry just mmy phone for day to day would be awesome, and NAB has no phone solution yet.