Hacker News new | ask | show | jobs
by yedawg 2950 days ago
Aren't most mifare carding systems hooked up so transactions are logged, so to detect fraud? Like the australian gocard system for example, isn't every legitimate transaction on the card recorded on an online database somewhere? To exploit a gocard, or similar technology, wouldn't you also need to hack their system database? Eg. taps on to pay; records total transaction value and balance on card; taps off records total transaction value and balance; user rewrites card data; balance on the database isnt updated because a direct payment wasn't recorded; fraudulent card detected; idk correct me HN if I missed anything
1 comments

The chief advantage of the more expensive cards over the ID-only MIFARE cards is that you can store data securely on the card, so it can be used without a network connection. This helps if there's a network outage and reduces transaction time.

That said, it's super common to see recording done on both the card and on the network -- as you note for GoCard and Opal.

I believe it’s the same here in Auckland for our AT Hop card.