Hacker News new | ask | show | jobs
by Unoeufisenough 5027 days ago
The vector is the same as for QR codes, paste a different tag overtop of a legitimate tag that takes the user to a URI with a browser or other application exploit. Or physical world version of phishing. Again it is the application that is the root of the vulnerability. NFC would be no worse than a QR code or even a malicious URL printed in plain english on a poster.

The only unique theoretical option would be to hack a very highpowered antenna and transmitter to try and pick up blast out RFID-compatible signals to/from the very weak NFC radios of handsets from further away.