[access-uk] Re: Contactless payment cards (was Accessible bank card)

  • From: "Steve Nutt" <steve@xxxxxxxxxxxxxx>
  • To: <access-uk@xxxxxxxxxxxxx>
  • Date: Mon, 6 Apr 2015 21:03:36 +0100

Hi Les,

That's a way I hadn't thought of of reading your card number if you forget
it. Thanks for that. And yes, the old tin foil trick certainly works.

All the best

Steve

--
Computer Room Services
77 Exeter Close
Stevenage
Hertfordshire
SG1 4PW
Tel: +44(0)1438-742286
Mob: +44(0)7956-334938
Fax: +44(0)1438-759589
Email: steve@xxxxxxxxxxxxxx
Web: http://www.comproom.co.uk

-----Original Message-----
From: access-uk@xxxxxxxxxxxxx [mailto:access-uk@xxxxxxxxxxxxx] On Behalf Of
lsmithso@xxxxxxxxxxxxxxxx
Sent: 06 April 2015 14:48
To: access uk
Subject: [access-uk] Contactless payment cards (was Accessible bank card)


Hi: A while ago there was a conversation on here about the
accessability and security of contactless payment cards. I received
mine a few weeks ago, and finally got around to testing if I could
read it with a smart phone.

The answer is yes. I can read the card number, the expiry date, card
type, the card issuer and the number of PIN attempts left, and that
was that. The card holders name and the cvv cryptogram are not
readable.

The card has to be held within 1cm of the back of the phone for about
0.5 seconds for it to be read. It could be reliably read when inside
my wallet, in my trouser pocket. Wrapping the card in a single
thickness of cooking foil completely prevented the card from being
read.

Given that less information is exposed by NFC than is available from a
casual glance of the card, and that any eavesdropper would have to get
pretty touchy feely to be able to scan my card without my knowledge,
then I'm pretty relaxed about having this card in my wallet. I feel
no more vulnerable than if I used a non-contactless card.

App details:
Banking card reader NFC (EMV)
https://play.google.com/store/apps/details?id=com.github.devnied.emvnfccard&;
hl=en

Android Nexus 5.

--
Les Smithson
** To leave the list, click on the immediately-following link:-
** [mailto:access-uk-request@xxxxxxxxxxxxx?subject=unsubscribe]
** If this link doesn't work then send a message to:
** access-uk-request@xxxxxxxxxxxxx
** and in the Subject line type
** unsubscribe
** For other list commands such as vacation mode, click on the
** immediately-following link:-
** [mailto:access-uk-request@xxxxxxxxxxxxx?subject=faq]
** or send a message, to
** access-uk-request@xxxxxxxxxxxxx with the Subject:- faq



** To leave the list, click on the immediately-following link:-
** [mailto:access-uk-request@xxxxxxxxxxxxx?subject=unsubscribe]
** If this link doesn't work then send a message to:
** access-uk-request@xxxxxxxxxxxxx
** and in the Subject line type
** unsubscribe
** For other list commands such as vacation mode, click on the
** immediately-following link:-
** [mailto:access-uk-request@xxxxxxxxxxxxx?subject=faq]
** or send a message, to
** access-uk-request@xxxxxxxxxxxxx with the Subject:- faq

Other related posts: