Hacker News new | ask | show | jobs
by rglullis 858 days ago
It says right in the first paragraph it was crypto.

Still, if you think the problem doesn't apply to "real money": there was this story in Brazil some years ago of thieves going around to Carnival parties with NFC-enabled payment machines. They got away with hundreds of thousands of BRL just by walking in the middle of the crowd with the machine set to collect a small payment.

IOW, people were getting robbed because we've become too lazy to type a PIN code.

3 comments

US passports have a cover that makes it hard to read the chip unless opened. I don’t know how well it works, but it seems like something similar would be useful for payment cards, even if there’s no PIN.
I didn't say it doesn't apply to real money. I said there is a lot more logging so you have a better chance of finding where the money went, catching them, and getting your money back. It isn't perfect, and it does depend on Brazil's courts. It also depends on someone going through a lot of effort, it isn't automatic.
Still, we are now being forced to spend an uncountable amount of time and resources to create a system that can mitigate an issue brought by some technology which was supposed to save us what, 10 seconds of each in-person transaction? It makes no sense.
There is no way to set Apple Pay to activate without user input, is this not true in Android?
Tap-to-pay NFC credit cards

Chip and pin or even chip and signature is just too much effort to pay for something

To do this, are they using some kind of modified payment terminal with extended range somehow? My understanding is that the NFC coils have to be very close, like single-digit cm to get any kind of power or data through.
At carnival in Bazil, you bump into people; Like, when they talk packed streets, they're talking body to body contact filling the street for blocks and blocks. All you'd have to do is put a terminal around your waist and you'd get close enough to activate NFC for hundreds of people just pushing through the crowd.

https://en.wikipedia.org/wiki/Brazilian_Carnival#/media/File...

If I remember correctly, yes, they had a modified terminal that picked up cards more than a meter away. But the other comment is overestimating the damage, there is no way they took 'hundreds of thousands', more like thousands in total. Especially since contactless payments usually have a very low transaction limit (something around R$100 in Brazil).
(Reply depth reached) I guess if you're filtering through a big crowd then indeed you could get really close to people and their wallets. I thought GP was saying you could immediately skim every person in a crowd at once.
Have you been to a Carnival party in Brazil? Most of the time, you won't have "single-digit cm" between you and the next closest to you.
Chip and pin can be unreliable because of bad contacts