Not insignificant!
Not insignificant!
Good thinking. Works on two of my site passes but not the third. Can't spot an obvious aeriel loop on any of my Visa cards, only one of them is marked contactless enabled. Perhaps it is behind the ferrite stripe or the tamper proof signature strip? One of the two holograms is "blotchy", the other is completely opaque.
It's called "trust" LOL. Some years back someone was pulling from my debit card, 2 or 3K ish. I didn't know until the statement arrived. Phoned the bank, told them which payments weren't made by me and they simply refunded. I maybe had to sign something, can't remember.
I think the boot's on the other foot
I think the reverification policy is actually an issue for the bank, based on the perceived level of risk. They, or the card, might well trigger a verification if there were a smaller number of transactions all very close to the limit, or on a random basis.
In part the amount at risk is chosen to similar to the amount of cash that might be lost to a pick pocket.
Darren
A lot of those materials are not specified at the frequencies used for the cards, which are in the short waves. Most of the materials seem to be designed for microwave use.
Ladies only?
That *is* interesting since Dutch cryptographer at Nijmegen have totally broken the encryption on Oyster and all the cards of that ilk.
On 20/05/2013 17:44, John Rumm wrote: ...
My bank wrote to me to ask if I wanted them and also offered me a sticker to put on my mobile phone that would work as a contactless card. I said no to both and my personal cards from that bank are not contactless, although my business cards from the same bank are.
Colin Bignell
No, not really. It's not a massive issue for Oyster as the best you could do would be to clone a card and use it that day - it would get picked up overnight in the consolidation runs (if not before, they have some rather clever pattern detection software). They have other checks in place that make it tricky.
Mifare Classic cards are compromised now. It's not trivial. They do however carry various sectors that can be used and if what you put in there is encrypted then it's not a lot of use without the key to the encryption.
Got a modern smartphone with NFC built it? You can read a mifare card. Plenty of tools around to crack it. Ebay will supply all the tools and blank cards. It's pretty simple.
As pointed out, Mifare is a brand though - they have many other cards that are not (yet) compromised. Mifare DESFire is common (although IIRC, the original version of those have been broken).
Darren
I've not tried this, but:
X-rays:
Assuming the polymer antenna is in the same place as the copper on other cards, drilling about 5mm in from the long edge of the card should do the trick.
Theo
Something I read earlier today suggested keeping two (or more) cards close together as they interfere and cancel out any accidental transaction. This certainly works for my security passes - the correct card has to be removed from the stack in the card holder to work. A M&S PoS terminal was tested by I can't remember whom and found to have a maximum NFC range of 5cm.
I wouldn't rely on that. I regularly travel in London with both my Oyster card and my word ID card. Both are Mifare classics - if I have them both in my wallet about 75% of the time the oyster readers get it right, 25% of the time I get an error. Removing my id card cures it. Likewise the other way around - word security readers barf around 25% of the time if my oyster card is in my wallet.
So while it does appear to confuse it sometimes, it's far from a reliable method! (might be different for non-mifare classic cards, but I'd not rely on it).
Darren
If you want to use the contactless facility every now and then, store it in your wallet with an oyster card on top. The mifare system cannot differentiate between two co located cards.
Otherwise just disable it by cutting a part or all the way through with a Stanley knife as shown here on my barclaycard
Neither the physical layer nor the discovery protocol depend on the encryption.
That's handled by the discovery protocol, which should try to establish the serial number of the card and address further requests to other cards. In theory it is supposed to be able to detect multiple numbers and abort the transaction, but it sounds like it might not be as good as it might be.
I believe the discovery protocol applies to all the ISO standard cards, on that frequency, not just NXP's Mifare ones.
>Have something to add? Share your thoughts — no account required.
Ask the community — no account required