Go homepage(回首页)
Upload pictures (上传图片)
Write articles (发文字帖)

The author:(作者)qq
published in(发表于) 2014/6/12 4:53:46
NFC mobile phone really makes it easy to read credit card information? ,

NFC mobile phone really makes it easy to read credit card information?
-NFC,NFC near field payment and NFC mobile phones-IT news NFC mobile phone really makes it easy to read credit card information?

Summary: NFC mobile phones can easily read bank card numbers and transaction? How to achieve this? Threats I funds safe?

NFC-enabled phones and chip cards

Media journalists experimented with BOC, CCB, ICBC and Bank of IC chip card, as well as the CCB's credit card and found them to be NFC-enabled phones (and have a PayPal plugin) read out the transactions on the card. NFC phone can easily read chip cards card number and transaction? How is this achieved? Threats I funds safe?

So-called experts believe thatNFC mobile phone has the potential to become a hacker "cash dispenser"; some analysts think cell phones only cling to the bank card can read a limited amount of information in the ID card, also can not transfer operation, so there is little risk, users don't have to worry too much. Truth is what then? A safe manufacturer in Taiwan has conducted a series of tests, one by one, the answers to these questions.

What is NFC?

NFC (near-field communication, NearFieldCommunication), also known as the short-distance wireless communication, is a short-range high frequency wireless communication technology allows contactless electronic devices point-to-point data transfer to Exchange data.

This technology was developed by contactless radio frequency identification (RFID) evolved from Philips Semiconductors (now NXP semiconductors), Nokia and Sony jointly developed, which is based on RFID and interconnection technologies.

And we currently employ more than Bluetooth, NFC is more convenient to use, lower-cost, lower power consumption, establish a connection faster, just 0.1 seconds. But the NFC's use a much shorter distance than Bluetooth, only 10CM, the transmission rate is much lower than Bluetooth.

NFC and Bluetooth technology to repair, so cell phones, access control, card, card also became widely used in the field.

What kind of phone support?

Not all phones have NFC modules. However, since the beginning of 2006, Nokia launched its first NFC mobile phone, now more and more smart phone has support for NFC technology.

For example, Nokia Lumia, Samsung Galaxy and Note series, Sony's Xperia series, HTCOne series, as well as domestic phone 3, oppo, Meizu, part mobile phone, were already supportive of NFC technology. IPhone does not currently support, but there are rumors iPhone6 will add this feature.

What bank cards can be read?

Bank cards that can be read by NFC mobile phone information for the IC chip bank cards, traditional magnetic stripe card cannot be read.

Card, IC card chip bank cards, usually with the Flash logo. In cafés, restaurants use this chip bank cards at the checkout simply have the card close to the card reader, without a password to complete small payments.

Tests found that reads the chip card information, in addition to mobile phone needs to support NFC function, also need to use the appropriate software installed on the phone, such as phone PayPal.

What information can be read?

Different cards can read information varies, tested several bank cards of different banks, results are as follows:

Bank card reader results summary

NFC phone can read the card number and the latest transactions, transfers are not supposed to. As shown in the following figure, after reading the information, showing "opening fast pay", but due to the opening of fast pay only support real-name account number and bank cards belonging to the same person, so there is no need to worry about your card account numbers bindings by others.

NFC mobile phone scanning results of the bank card

4NFC scan results of bank card

Last 10 transactions

How close can the distance readout?

NFC mobile phones to be able to read information from, directly determines the access the ease of credit card numbers. In order to directly test the feasible distance read NFC, after repeated tests:

First, the bank card to be placed on the back of the phone can be read in a particular area, as shown below. Now most of the Smartphone screen is very large, and NFC modules are small, the card is more closer and easier to read.

Start scanning interface

Test, the IC chip bank cards directly affixed to the back of the phone, of course most easily read.

Cards with a phone display scan results

Test, cell phone and bank card placed in the middle of a ballpoint pen, about 2cm in diameter, still successfully read information.

Scan results after pad pen

Three mobile phones and bank cards put a wallet in the Middle, about 5cm, has been unable to read card information on distance is really harsh.

Pad a wallet after the scan results

Testing, closer to the real world, new mobile reading is most likely to occur is a crowded subway or bus, NFC mobile phones to be able to read the stranger's Pocket bank card information?

Tucked into a wallet in the pocket of the bank card and mobile phones posted on each other's pockets, transform when testing a variety of positions and angles, the final result was read failed.

If a bank card into your wallet and placed directly in the Pocket (although the possibility is low), NFC mobile phone sticker, look at the pictures, after several angles in the transform, the read out information's phone!

Single sheet card Pocket close to the results of the scan

Can also be seen from the above, information on NFC mobile phones to read distance is extremely sensitive, 5cm read out the probability of significantly reduced, so as long as the bank card in your wallet, by strange phone it is very difficult to read. Even in the photos of people crowding into the subway, strange cell phone really wants to read your bank card, you need to transform a variety of positions and angles, its difficulty is even higher than the direct stealing a purse number. Thus, Internet users to not have to worry about this.

What are the security implications?

If the chip card by unauthorized people using NFC mobile phones to read information, could lead to credit card numbers, social security number, last 10 times consumer bills, cell phone wallet balance to be read. This information belongs to the individual's privacy, but does not directly lead to stolen bank card funds.

Also, some people worry that some fake paid software or implantation of an infected cell phone using NFC functionality of the program reads the card information, only that this is possible in theory, actually is not necessary. A Security Lab detected last month hundreds of fake APP by phishing fraud personal information, an attacker don't need to increase the complexity of theft: in addition to using software methods, necessary hardware requirement is met by an attacker.

Of course if you IC chip bank cards in your husband (wife) in his hand, you do not need a bank card password, TA can easily see if your recent transaction records, probably facing troubles there. This hidden danger is enormous and complex.

Whether the traditional magnetic stripe cards more secure? Instead, the old magnetic stripe cards more easily replicated, security is worse.

Safety recommendations

1.NFC provides a non-contact method of communication, after all, though relatively close, personal information has been obtained illegally. Recommended cardholders take care of bank cards, do not let the card out of your sight.

2. you can use a thick wallet, wallet into the bag.

3. mobile phone poisoning hazards than the NFC mobile phone scanning cards a higher probability of losing information, mobile phone antivirus is relatively more important.




If you have any requirements, please contact webmaster。(如果有什么要求,请联系站长)





QQ:154298438
QQ:417480759