Search this Site

Showing posts with label Data Security. Show all posts
Showing posts with label Data Security. Show all posts

Saturday, May 14, 2011

Michaels Stores' Checkout Terminals Hacked

A typical Michaels retail store

Another credit card security breach again. If you happened to shop at any of the Michaels local stores recently that are located at the following states, your credit transactions may have been compromised:

Illinois, Colorado, Delaware, Gerogia, Iowa, Massachussets, Maryland, North Carolina, New Hampshire, New Jersey, New Mexico, Nevada, New York, Ohio, Pennsylvania, Rhode Islands, Utah, and the State of Washington.

Few days ago, many Michaels' stores have found have been hacked on their PIN readers/Credit Card readers at checkout. The Texas-based arts and crafts supplier has determined that the hacked could have been perpetuated between February 8 through May 6 according to the latest law enforcement investigation. The hack was initiated from PIN pads that are attached to credit card readers where customers use to key in their personal identification numbers upon checkout.

These scam artists were able to steal credit card information including personal PINs. The first discovery of the breach was at a Michael stores in Salt Lake City and Midvale in Utah. As a result, the arts supplier has removed more than 7,200 PIN pads from all its US stores.

I got interested with the story not only because the company is a customer of RGIS LLC, but because I wanted to know how in the world one can hack PIN pads in a busy store at busy checkouts. What is their modus operandi? Was there any collusion between scammers and employees?

Honestly, the trick is quite simple, but with calculated risk. 
A VeriFone PIN pad and Credit Card reader combo.
Image courtesy of VeriFone.

FIRST, there was a careful planning. These criminals pose as legitimate customers of Michaels. At checkout, they then observe several things such as the models/make of Michaels PIN pads, standard cable connectors, etc. Since many Michaels art products sell in less than a dollar range, they can come back as many times as they want and master how the plan works, how many seconds would it take to deinstall and reinstall a new PIN reader, when is the best time to to do it, and how to do it clandestinely without much effort and detection.

SECOND, scheduled activity. Scammers come back in packs of two or three posing as customers not knowing each other. The first act as the customer/installer, the second as a legitimate buyer, the third as customer/distractor. While the second or third scammer busy distracting the unsuspecting cashier with questions related to their purchase, it will take no more than 10 seconds for the first buyer to unplug the old PIN reader and replace it with a reprogrammable RFID chip when the PIN pad is not in use.

THIRD, leave without a trace. After a successful installation, scammers leave the store. Since many newer PIN reader models have built-in RF chips (meaning, it can read your RF-enabled credit card), scammers can easily install PIN readers with a reprogrammed chip. But just outside the store, with the use of a laptop, high frequency RF proximity scanner, and a customized software, they were able to monitor/ skim credit card transactions complete with PIN numbers for the installed compromised PIN reader from a vehicle within dozens feet away from the store.


A typical PIN Reader with a bult-in RF
technology. Photo Courtesy of VeriFone.
The idea that these scammers pose as repairmen may not be suitable in this case because to be able to that you need to appear as repairmen which include having tools and equipment, with uniforms and all that, not mentioning the fact that they need to obtain a clearance from the Store manager FIRST before any repair can be initiated which is not a good idea. Because the lesser people detect your activity, the better your chances.

That is the basic idea of a detectionless PIN reader skimming. But you know it is illegal, right?

Poor Michaels. But how many times I've heard from credit card companies, from POS solutions providers and software vendors that their systems are secured, and reliable. But when things are happening on the contrary, you realized that they themselves need some serious reality check.

The arts supplier is closely monitoring fraudulent transactions with credit card companies while advising all their customers to take precautionary measures. So, if you live in the States I just mentioned, and need to buy your next quilting, embroidery, or arts projects for yourself or for your kids from your local Michaels store, I suggest that you use cash for payment transactions...for now.

For more information on RF-enabled smart cards, read my previous post on RF technology and The ABC of Hacking


Cheers!



You May Like These:

First Data FD-10C PIN Pad w/ Card Reader Verifone Omni 3750 Credit Card Processing Terminal & Pin Pad Combo Ingenico, Inc. i3070 Pin Pad with Smart Card, Magnetic Stripe Reader and USB Cable

Sunday, January 30, 2011

Will Smartphones Replace Your Credit Cards?

A BlackBerry smartphone
Updated January 31, 2011

One of the hottest trends in technology right now, at least in the US (although it has been ongoing in Europe, and some Asian countries such as Japan, South Korea) is the adoption of NFC-enabled chips into smartphones and mobile phones to act as your contactless mobile payment or contactless credit card.

Some of you may have heard rumors about Apple is contemplating to adopting the technology with its latest version of iPhone or iPad by developing the software side that runs NFC which enables these devices as a mobile wallet. Once enabled, your phone can be used at POS as opposed to making online credit payments.

Some even have predicted that NFC payments may surpass contactless cards in 5 years.

An iPhone being used in payment transaction.
NFC, or Near Field Communication is a short range high frequency wireless communication technology which enables the exchange of data between devices between 4 to 10 centimeters in distance. It is an extension of the ISO/IEC 14443 proximity-card standard which runs using radio frequency. An NFC-compliant mobile phone/smartphone can emulate or behave like a contactless card which can communicate to a standard ISO/IEC 14443 smart card reader. In short, you wave your mobile phone/smartphone close to a contactless reader at checkout to pay for your coffee, or shopping items just like how you wave your contactless credit card.

If you can wave your mobile phone to an NFC-enabled card reader then your device is NFC enabled. In the US, there are only few smartphones or mobile phones that do that. Some newer models of Blackberry is NFC-compliant. Newer iPhone models and the Nokia C7 have built-in NFC chips but are not enabled yet. Windows Mobile and the Android based smarphones/mobile phones do not support NFC at this moment.

But here's my take: One of the greatest drawbacks about using your smartphone as medium for payment transaction is the security of your personal information. Recently, the current RF-enabled swipeless credit has been demonstrated hundred of times how easily to skim or hack the information from these credit cards via cheap card readers. Because technology is neutral and it can be utilized by both the criminal and the innocent, no one can ascertain the extent of benefits or harm it can bring.

This Nokia C7-00 is an NFC compliant mobile phone. This and other mobile phones can be available at Amazon
and some retail stores in the US. Image from Nokia.
When your standard credit card is stolen, you can always report immediately to your card issuer and disable it immediately, then request for a replacement. You can always "regain" your previous credit status back at that instant. Besides, credit card replacement is free or at least with few dollars only. But how about an NFC-enabled mobile phone or smartphone (like the picture above), when it is stolen, how much information can be lost?

A loaded smartphone can have tons of information such as but not limited to, your important emails, saved voicemails, your online purchase transactions, your personal data, possibly your bank information, your personal or business activities, important people from your phonebook. Your personal and family pictures that you cherished. Or even your intimate videos with your significant other that you happened to record are also there.

Virtually your life and your identity ARE at risk and even becomes irreparable after it is gone. Therefore the question that must be addressed will be: Are you willing or are you ready to risk these much information in the name of convenience to be used and abused by other people once your smartphone is gone or stolen? Would you?

No doubt, NFC-enabled smartphones are smart alternatives to credit payments and therefore they create more options for shoppers like you and me. But it won't replace the latter even in the next 15 or 20 years. Contactless credit cards will evolve to more sophisticated smartcards but they won't be replaced by mobile phones. I am not saying it is impossible. They are theoretically possible. All I am saying is that it is unlikely to happen. 

There is no question that NFC-enabled smartphones can simplify your life. Their ease of use and the convenience they bring are functionally and economically irresistible. But convenience, or ease of use has always a price to pay. And that price could be the very life you have.

Wednesday, December 22, 2010

Smart Cards: The ABC of Hacking and 5 Tested Ways to Protect Your Cards: Part 3

RF-blocking leather passport and credit card wallets. Although a tinfoil or an aluminum foil can 
block radio wave frequency, and probably the most inexpensive way to protect your ePassports
contactless credit cards, or any smart cards, a leather-coated tinfoil may be a better and
more fashionable alternative. Image courtesy from IDStronghold


Last Updated: December 23,2010 10:20AM

Credit card fraud is billions of dollar business. In US alone,the Boston-based research firm Aite Group LLC has issued a report recently that it costs about $8.6 billion annually. Among these card fraud include in different forms such as cards not present, counterfeit cards, lost/stolen card fraud and first party fraud.

Trustwave company also released a study thru SpiderLabs, which shows that over 38% of credit card hacking-related crimes last year involved hotels than other industries. Other sectors that were cited in the study that were involved with credit card fraud include: the restaurants and bars industry, 13%; the retailing industry, 14.2%; and the financial service industry, 19%.

For this last installment series on contactless smart card, I would like to focus more on how smart cards can be counterfeited or hacked and practical yet effective ways to protect them. It is not a question whether credit cards in general can be hacked or not, but how and when. There are numerous ways, but I will just mention at least 6 for this post:

Corporate and financial database hack.
Compromising corporate secured system and stealing customers' database of sensitive information are harder tasks to perform compared to other forms of hacking, but once successful, it would be very devastating and could cost the company's entire business, customers lost of confidence, or even the entire credit card industry.

Just 3 years ago, at least 45.7 million credit and debit card users are at risk following a security breach with the TJ Maxx database. Another example of database hack was 2 years ago: The Best Western hotel chain has suffered one of the world's largest credit card hacks which compromised at least 8 million customers. Just last year, 7 Eleven chain of stores, Heartland, etc. suffered customer data theft from hackers who broke into the database's firewall and stole at least 130 million credit cards information. The company has paid 12 million to cards issuers already.

Just few days ago, 100,000 credit cards were compromised due to database breach.

Stolen or Lost Cards.
Every credit card transaction, online or offline, is assumed valid until it is proven otherwise. Although you may have zero liability for fraudulent purchases against your card, you are still liable for transactions if you do not report an incident promptly. If you do not report any stolen or lost card immediately to your card issuer, you are putting a greater risk for fraudulent purchases against your account.

CNP (Card Not Present) Transactions
These types of transactions are anything done thru online shopping, mail-orders, and phone orders. Merchants are not fully aware of the identity of the shopper. They simply rely on the information based on the card information being provided. Sure there are countermeasures and safeguards, but since online payment systems vary from merchant to merchant, credit fraud creates a lot of opportunities and has a lot of real estate to offer for hackers.

How does a merchant spot that the credit card an online buyer uses a legitimate or cloned when all the information the buyer have provided are true and accurate? Honestly, a merchant does not concern about it. But the real card holder may only determine it AFTER a fraudulent purchase has been done AND recognized that it was a counterfeit. It is even harder to spot a fraudulent transaction when the counterfeit user analyze and mimic the card holder's spending patterns and shopping behavior.

It is not hard to perform online purchases using a counterfeit credit information. Because such information needed to complete a transaction can be obtained easily from an RF reader, or from a Chip and PIN reader (if you happened to live in UK), or from a skimmed credit cards that card holders use for payment at bars and restaurants.

Peer-to-Peer network credit card theft.
Some of you may have used a peer-to-peer client software such as BitTorrent, LimeWire, etc., at some point. This is probably one of the easiest ways to steal credit cards numbers and information stored in computers connected to a P2P network or uses a file-sharing client software.

You do not have to google "credit card numbers free" to get results. Even if you do, chances are those numbers could either have been expired, recycled, or already have been blocked. Millions of users use P2P to share audio, video, and image files. But many do not realize that you may use this client to search and browse another peer's default folders directly accessing all files imaginable that are present including document files in that computer. And you would be surprised how easy to search others' files for credit card numbers and passwords.

Script Kiddies and Injection Attacks
This only applies when searching for URL vulnerabilities on websites which may yield a good chance to obtain credit card information including contactless cards. If you are familiar to programming using Perl, Python, C/C++, SQL, or Java etc. you can easily create your own "vulnerability scanner" application, or a hacking script. Better yet, you can search perl-based scripts from the internet like most script kiddies would do. Legacy systems are still being used by some merchants online and therefore easier to spot vulnerabilities.  Remember that 7/11 credit card heist I just mentioned? Hackers used SQL Injection to compromise database.

Electronic Pickpocketing
This is an RF reader model from Motorola XR400 series used
by Chris Paget in his RF hacking demo in New York.
Thieves do not need to snatch your bags or wallet to use your credit card, Online scammers do not need to phis you via counterfeit websites just to lure you to "update" your credit information and other personal data. Hackers do not need to infiltrate bank's secured web servers and compromise millions of credit card data and use them fraudulently. Anybody with the right scanning device, you can steal a contactless credit card in as easy as 1-2-3. 

This is electronic pickpocketing. With the help of a cheap card reader either concealed in your body, or in a small netbook bag., a software, a wireless device, that receives the captured data, AND a few minutes walk at a crowded downtown area (although you can do it with your own contactless credit card for experimental purposes), you can be an electronic snatcher in no time.

When the first generation of RF-based credit cards were introduced in 2006, the first hack was sponsored by RSA labs at University of Massachussets. The hack was documented and outlined with this paper.






One of the best case of an RF-enabled contactless cards was the Oyster's MiFare Classic hack. The Oyster is an RF technology and is compatible with ISO 14443A and ISO 14443B architectures at 13.56MHz frequency. The hack has prompted the Greater London Transportation authority to halt the system on January 2010 after it was hacked in December 2008. Later, it was upgraded to MiFAREDesfire last February this year. There is an excellent paper on how MiFare Classic was hacked.

But you may ask, "So what's the use of those 3DES, AES, RSA, SSL, and other encryption methodologies in the first place if a mere $8 RF credit card reader can easily scan and lay bare my credit information?"


Because these methodologies can only protect your credit card information at a certain degree when you make online and offline transactions and also to protect credit cards information stored in a secured database. They encrypt/decrypt data AND communications coming from your credit card to the merchant's electronic paying system and vice versa. They CAN protect data coming from your web browser to the merchant's web server and make sure the transaction is secured using an SSL certificates or similar security features.

But, they DO NOT protect your credit card from any RF-enabled scanning devices. In fact, almost ALL commercially available RF-enabled scanner in the market can be used to hack any contactless credit card. That is how open and unprotected the RF-enabled smart cards are!

So, If I were a quickie hacker, why should I spend my time and effort trying to force my way in into a secured database or electronic paying system (although I must admit that the result may be overwhelmingly rewarding), if I can do it in a crowded area in a city using a cheap RF-enabled credit card scanner with a higher success rate?

Chris Paget, Director of R&D will certainly agree with my assessment. He demonstrated how easy to steal information from an RF-enabled smart cards form his speech at a 2009 Shmoocon Convention:






Technology is neither good or bad. It can be used to benefit the majority or use it to cause harm. It always boils down to how responsible we are. I wish to continue more, but I thought that this article is beyond the usual length of an article. So, I hope my readers will forgive me if I will deal with the second part of this article, "5 Tested Ways to Protect Your Cards" on my incoming articles.

A word from the author: All information written here are for educational purposes only. No warranty is implied and written in AS IS basis. The author is a technology professional. He does not encourage anyone to perform hacks and breaches or perform illegal access to any system, device, or computer. The author shall not be responsible for any damage, incident, or any punitive act as a result, or arising from a direct or indirect use or abuse of the information herein. 

This link may help you:



Friday, December 17, 2010

Smart Cards: Are the benefits of contactless smart cards outweigh the risks? Part 2



Convenient. Fast. Secure.

These are the exact choice of words that best describe the latest smart card innovations from credit card companies. For many of us, these are not new stuff, in fact some of you may wonder why these RF miniatures in your cards are being advertised as secured, despite the truth on the contrary.

When the magnetic stripe cards were initially introduced, credit card issuers assured card holders that they were convenient, fast, and secured. This, despite millions and millions of credit cards that had been hacked and sensitive data had been compromised since their introduction more than 50 years ago. When the contact chip cards were introduced, the same security and privacy issues were reported and the same slogan were used: Convenient. Fast. and Secure. Now that we have this latest generation of contactless credit cards,  what do credit cards companies will have to say again?

There is no need to play as devil's advocate because everybody knows, or at least many of us know that there have been security issues associated with the use of credit cards irregardless of their state of the art technologies. But that is technology, it is neutral. But sometimes we have to face the fact that we utilize what technology offers us. And it is up to us to protect our own identity. So, for the interest of the newer cardholders, I will list some benefits of RF-enabled contactless credit cards according to credit card companies, and the potential security risks that go with them then you decide.

Convenience.
Why wait in line to pay a cashier when you can checkout yourself faster? Likewise, why cope with swiping, signing and entering numbers if you can just wave and go? This is probable the best argument for using a contactless credit card. And I won't even argue with it.

This swipeless technology doesn’t have to be limited on the form of a traditional card. Many card issuers are making contactless technology available in other forms, such as mini cards, stickers that can adhere to mobile phones or chips with the size of a SIM card. They also come in fobs that can be used without searching through one’s wallet or purse. Now you can even process a contactless transaction using your smartphone.
iPhone turns contactless credit card. Image courtesy from Mobile Crunch

Faster Transaction.
Under normal transaction process, contactless transaction is relatively faster than the rest of payment methods. Consumers and cardholders prefer shopping at stores that accept faster and more efficient payment methods. I mean, how many times you have been denied from stores that only accept cash and not credit card.
  • According to American Express, tests have shown that contactless transactions with its proprietary ExpressPay cards are 63 percent faster than cash transactions. 
  • According to Aite Group, also have observed that "contactless payments are relatively faster than other forms of payment transactions; on average twice as fast as cash transactions.” Here are the tender times calculated in seconds for different payment modes: 
    • Checks   64
    • Credit/Debit   48.4
    • PIN Debit   44.4
    • Cash   28.5
    • Biometrics   15.6
    • Contactless    12.5
  • According to Visa, the average tender times for the following transactions are:
    • average cash transaction takes 34 seconds, 
    • average magnetic stripe credit card transaction takes 24 seconds. 
    • average contactless payment transactions takes 15 seconds, since there is no need to hand the card over to the cashier and there is no signature required for purchases under $25. 
Although American Express and Visa may have slight difference with their reports, but the consistency remains: contactless are faster. Now, if we translate this speed and convenience in terms of non-monetary values, they tell us that a significant reduction in transaction time can create the following benefits: increased revenue, improved customer service, enhanced operational efficiency.


Secure Transaction.
Contactless credit cards implement either one or both of the following industry-standard protocols, such as AES, 3DES, RSA, ECC, etc. They form the core standard of data encryption. Experts also say that contactless card can verify that the reader is authentic prior to any transaction. When making an online purchase, smart cards utilize SSL cryptographic protocols to establish an encrypted link between web server and a browser and provide secure communications technology between transaction to prevent eavesdropping.

For a more technical detail on 128-bit AES and 256-bit AES encryption, there is an excellent technology paper produced by Seagate Corporation (PDF only).

The EFF's US$250,000 DES cracking machine contained over
1,800  custom chips and could brute force a DES key in
a matter of days.
Cryptography experts say that AES and other forms of algorithms is nearly impossible to break. Among cryptographers, a successful break is anything faster than an exhaustive search. So far, the largest successful publicly-known brute force attack was against a 64-bit RC5 key by distributed.net. There have been several attacks on AES-128 on 2009 but nobody has successfully broke it yet.


Do you want to help somebody to break an AES encryption? You may join this small forum and see if you can help. Or if you think you are an expert hacker, maybe you can participate the elliptic curve cryptography challenge by Certicom which offers nearly $1Million to anyone who can break a large file encrypted with AES-256. Woud you accept the challenge?


But this does not mean that it is impossible to decrypt or break these algorithms, but it may take a while. You have to understand that these protocols are primarily used for protecting you from eavesdropping by cyber criminals thru ONLINE transaction and securing databases that are accessible via corporate or LAN networks. 


But will you be protected from these security measures when somebody scans your contactless cards using a concealed RF card reader close enough to skim all your credit card data without your knowledge while walking in a busy downtown area? Nothing. None of them! Hackers knew that eavesdropping via online transaction is a bit challenge or breaking a system could take a lot of resources including time. Now, some of them are changing their modus operandi by scanning the busy streets in your city. In my last episode, I will show you how easily to hack somebody's credit card. This is where the money is folks. Because they know that the air is an unprotected area to explore and to make money.


Zero Liability Protection.
Most if not all credit card companies and banks offer a Zero Liability Protection (ZLP) to credit card holders and that include your contactless credit card. Zero Liability simply means that you as a card holder is or will not be responsible for unauthorized purchases or fraudulent transactions charged to your account as long as you report the incident promptly. To read MasterCard cardholder policy on ZLP, proceed to this page. For Visa also offers Zero Liability for its cardholders, here is the link for you. 


Note that this Liability will only be provided under the following conditions:
  • Your account is in good standing. 
  • You have exercised reasonable care in safeguarding your card. 
  • You have not reported two or more unauthorized events in the past 12 months. 
These are the benefits of having a contactless credit cards. Also some of these benefits also apply to a standard contact credit cards. I can go on and on but I think I need to pause here for now. I will be back for the last part of this series.

Wednesday, December 15, 2010

Smart Cards: How cards are classified Part 1

Cards differ in symbologies and standards

This is the first of the 3-part series on Smart Cards:
  • Smart Cards Part 1: How cards are classified
  • Smart Cards Part 2: Are the benefits of contactless cards outweigh the risks? 
  • Smart Cards part 3: The ABC of Hacking and the XYZ of Protecting your cards 
Cards are classified based on the standards they bear or represent. These standards among others, are part of the International Standardization which govern cards' physical properties, electronic frequencies they carry, type of data and data structures they accept or recognize,  how data is stored and secured, and how information are read or interrogated.

The reason why I brought this information is to provide an idea how smart cards came to be AND to demonstrate the nature or extent of data AND data security these cards carry. So that card users like you and me may be aware of which card technology represents a better option in choosing the right card for your present needs. Here are the general classifications of cards according to the standard they represent:

Barcoded Cards. 
The current international barcode specification is ISO/IEC 15416 for linear barcodes and ISO/IEC 15415 for 2D barcodes, ISO/IEC 15426-1 for linear barcode verifier compliance standard, or ISO/IEC 15426-2 for 2D barcode verifier compliance standard. Barcode specifications are currently governed by at least 22 standards which covers 14 barcode symbologies.

Examples of 2D barcodes include Data Matrix
and QRCodes, among others.
Those lines and dots that you see among barcode cards (see above image) represent information we call symbologies.  They are optical machine-readable representation of data or information. Some barcoded cards are hybrid cards because they carry more than one type of data storage capability. But the standard barcode cards do not contain any form digital security enhancements and they are the least secured among all card types.

They do not contain any ciphered information other than the lines and dot they represent. But once you are able to manually decipher a symbology, you will know exactly what information they contain. They are not smart cards. For starters, here is a simple tutorial to decode the meaning of a UPC barcode.

Some barcode symbologies can be complex and hold more data. These are the 2D barcodes. Example of 2D barcodes are the PDF417, Data Matrix, and QRCodes. These barcodes are ideal for drivers' licenses, company ID's,  supply chain management, and many other applications around the world.  

Magnetic Stripe Cards.
Magstripe cards are based on the following standards most notably ISO/IEC 7811, 7813, which defines properties of magnetic stripes and magnetic data structures. Magnetic stripes reading and processing date back in 1960 and invented by IBM. These stripe cards can typically be read by most point-of-sale hardware, ATM machines, security access, transportation services, etc. 
The back of a credit card showing the magnetic stripe

Examples of cards adhering to these standards include ATM cards, bank cards (credit and debit cards including VISA, MasterCard, American Express, etc), telephone cards, gift cards, loyalty cards, driver's licenses, membership cards, food stamps cards, and nearly any application in which value or secure information is not stored on the card itself. A typical credit card uses a magnetic strip to store account information, which is only retrieved when swiped through a swipe machine. 

The strips of the cards are made of Mylar, the same material use in the production of the obsolete 1.44 floppy disks, magnetic audio and video tapes, capacitor dielectrics. Like any material with magnetic field, they can lost their magnetic properties when contact with greater magnetic field, when they are exposed to heat that past Curie point, when they are constantly being rub or made friction against the surface material. When it happens, it loses the stored data and render them unreadable and useless.

That is why credit card companies need to replace your card at regular intervals not only because they are nearing the expiration date but most importantly because of wear of the magnetic field of the striped card. They are good source of data storage but they are not secured nor reliable.

The most common information encrypted into the magstripe are cardholder number, cardholder name, name of the company if it is a corporate card, expiry date and the validation security code. It is true that these information are encrypted, but with the use of a credit card catcher or a portable reader, and a little bit of ingenuity, you can easily steal these information. Yes, there is a certain level of security, but not smart enough.

Contact Smart Cards.
These smart cards are made under ISO/IEC 7816 standard particularly Parts 4 and above. They are have built in chips like ISO/IEC 14443 proximity cards. One cool feature of these of cards is that they can act both as contact and contactless cards using 13.56MHz frequency. Some bank cards and security cards are made with this standards. Companies that issue these cards are AMEX, CCETT, ECBS, Ecma International, IATA, ICAO, ICMA, ILO, MasterCard, UNECE, VISA.

Proximity Cards.
Credit cards with the wave icon as shown
above are contactless and use the
"wave and go" technology
These are the contactless or swipeless smart cards. They are governed by ISO/IEC 14443 set of international standards covering proximity smart cards. Unlike barcode cards and magstripe cards, proximity cards operate using radio frequency (RF) via the miniature IC, capacitor, and thin coiled antenna embedded within the them. They are called proximity cards because the information built into them can only be read within 3 inches distance.  Older proximity cards operate using a low frequency mode at 125KHz while the newer ones operate at 13.56MHz. 

A common internal architecture of a
smart card showing the embedded IC,
capacitor, and antenna coiled around it.
This is the reason why you need to wave your contactless smart card over a smart card reader close enough to excite the coiled antenna from your card and fires up the capacitor, which in turn energizes the IC to proceed with the process. Some common example of proximity cards are the RF-based credit cards. 

As early as 2002, MasterCard had tested RF cards know as Paypass and it was later offered to card users thereafter. All other credit card companies also have endorsed ISO 14443 as the most appropriate interface protocol for contactless payments because it supports encryption and a very short read range between the card and reader, both of which allow for secure transactions. 

There are other form factors of ISO 14443 aside from the standard 3.375x2.125 cards. These are the key fobs and SIM cards for mobile phones. More examples of proximity cards aside from credit cards are the HID access cards, the Oyster cards that are used for public transportation access within Greater London Area.
This card is a contactless credit card bearing the wave icon.

Credit Card companies tell us that contactless card are more secure than ever. They said that information being transmitted are subject to 128-bit encryption, that the card would never leave from your hands when making a transaction, that these cards do not transmit your credit card number, that even if it get intercepted by fraudulent means, issuers normally extend fraud protection to their users. Well, in a way, yes. But that is according to them. In reality one can easily hack these RF-based credit cards using an under $50 gadget that you can buy from eBay or Craigslit, a software and some inventiveness.

Vicinity Cards.
This is the ISO/IEC 15693 standard. They are also RF-based cards and operate on 13.56 MHz frequency. They are called vicinity cards because their reading distance is within 1 to 1.5 meters or 4.3 feet. They are very appropriate in applications such as National ID system, e-Passport card, e-drivers license, etc. The US used RF-based passport in 2006 but it was only the year after when it became available to the public. It is more secured in the sense that it was designed to incorporate a thin metal lining to make it more difficult for fraudulent skimming when the passport is closed. RF-based e-Passports are sometimes called biometric passports.



The image on the left is an example of a biometric passport. The image on the top right shows the embedded
RFID  of a British passport. The enlarged image bottom right is the logo of an RFID-based passport.
There are 2 types of  security standards currently implemented for e-Passports booklet: BAC and EAC. The BAC (Basic Access Control) is a first-generation ePassport RF chip which contain simple biometric information of the passport holder. The EAC is the enhanced version of BAC which allows a stronger biometric information that makes impersonation or forgery of a legitimate passport holder nearly impossible.

But, the electronic passport card version use to cross a border, say US to Canada, have found serious security vulnerabilities. In fact you can clone it in less than $250.00.

Q&A:
Is contactless smart card technology the same as RFID technology?

NO. Although both technologies are radio frequency enabled, each technology uses different operational parameters, uses different frequencies, and level of security and privacy features. The most common use of RFID technology is product identification for manufacturing, shipping, and merchandise tracking in supply chain. Contactless smart cards use RF technology but they operate a very short range frequency, with read/write capabilities and can contain multiple security features and they are mainly use with cards that contain secured information and sensitive identification.

So, what are the benefits of contactless smart cards and the security risks associated with them? Well, that would be the next topic for the Smart Card Series.

Related Posts Plugin for WordPress, Blogger...