Hacker News new | ask | show | jobs
by dgoujard 3685 days ago
contactless card are less secure than an tokenized mobile app because contactless card send you credit card number with NFC without encryption.

Tokenized app send one time credit card number.

http://www.planetbiometrics.com/creo_files/upload/article-fi...

http://arstechnica.com/business/2015/05/android-pay-will-emb...

http://www.telegraph.co.uk/finance/newsbysector/retailandcon...

2 comments

> contactless card are less secure than an tokenized mobile app because contactless card send you credit card number with NFC without encryption.

Only in the United States. In mainland Europe NFC has always used EMV authentication between terminal. Also as an aside: a european credit card's number alone is kinda useless.

I'm not quite sure that's the case. Using an NFC app on my phone, I was able to get my credit card's number without any issue. Also had the expiry date and a list of transactions.

https://twitter.com/edent/status/724639270284189696

True, it didn't have the CV2(?) number on the back - or my address - but enough to make me buy an NFC shielded wallet.

> I'm not quite sure that's the case. Using an NFC app on my phone, I was able to get my credit card's number without any issue. Also had the expiry date and a list of transactions.

If your card speaks MSD over NFC then it will provide that information. That's up for your bank. My cards not do it and as such I cannot use NFC in many places in the US.

is that info stored inside the card?
On some, yes. My MasterCard had a list of previous transactions. I wasn't able to get anything out of my Amex.
but from a consumer perspective who cares? you're protected either way. i prefer to carry a single card vs my phone if i'm running in the rain and want to stop for a drink. other times if i forget my wallet the phone is great, but it's totally equal as a user.
If you got an credit card number you can brutforce the CVV number (just 3 digits). Some online merchant didn't enabled 3-D secure.