← Back to context

Comment by tialaramex

6 hours ago

Physical connection doesn't matter. This isn't a Hollywood movie, there isn't some mega-virus which magically seizes controls of trivial objects by passing through a connector.

All three modern technologies ("original" Chip & PIN, wireless or a phone) are basically the EMV protocol, which is a fairly crap protocol which wasn't reviewed by experts before deployment - but is at least designed by people who have heard about cryptographic security and wanted to do that.

The original credit cards are just numbers written on a card. Clerk sees your number, memorizes it, now they can make arbitrary transactions indistinguishable from yours. Basically no security.

Magnetic stripe cards look more sophisticated but the stripe is basically the same numbers again but in a way humans cannot read. "Cloning" is just a matter of a machine copying those numbers onto another card's magnetic stripe. There's no real security improvement, though it is more convenient for the bank...

EMV ("Chip and PIN") is rather more complicated and could in principle be entirely secure - they could make it implausibly expensive to "clone" an EMV card, and require that you actually know your PIN for every transaction, so then crooks would need to learn your PIN and have the actual card, and that's a high bar.

In practice we didn't do much of that because it would be inconvenient, and so there are technical deficiencies, but realistically that XKCD "wrench" thing applies. Difficult technological attacks rarely happen, crooks threaten to stab you if you don't co-operate or they break into your home and steal your stuff, they do not come up with breakthrough cryptanalytic attacks on protocols. Mostly.

There are two forms of wireless. The first was “magstripe emulation” and it’s exactly what you think it is. The card would hand over the exact data on the magstripe.

It’s also exactly as secure as you think: it’s not.

That hasn’t been used for a long time, and I don’t even think people accept it anymore. May not have for years. At least for credit cards. It’s quite possible that’s still how door access cards or maybe gym membership cards work. I don’t really know.

Everything now and for many, many many years, has been EMV over NFC. And you’re right on that one it is essentially identical to sticking your card in the EMV reader.

  • The exact technologies used for "access cards" have varied over the years, but last time I checked most of them still aren't doing anything even vaguely secure. The card says "I'm card 1234-5678" and the access system checks that is on the list, welcome in. Like magnetic stripes it isn't obvious to the human operator, but just like magnetic stripes you can just clone it by listening and reciting the same, "I'm card 1234-5678".

    Now to be fair, you'd often find these systems are so clumsily installed that you don't need to clone a card anyway, the out-of-hours access has an "emergency" generic key you can buy from a hardware store, the controller was placed on the wrong side of the door - that sort of thing. But even a well-installed system is typically vulnerable to a competent intruder.