View Full Version : RFID Credit Cards, are they safe?
schalicto
11-03-2006, 08:28 PM
No. They arn't safe. What do you think?
-Josh
tokenuser
11-03-2006, 08:46 PM
Yes, they are safe. Have you seen a report stating otherwise? Or is this tin hat paranoia???
sevver
11-03-2006, 09:38 PM
What is wrong with tinfoil hats?
Personally, I would not trust RFID at all, I plan on avoiding it as much as possible, I think that the potential uses for it are a bit more than I wish to be involved in. Besides that, credit cards are bad, you should save money and pay cash for anything you need/want.
splat
11-04-2006, 06:45 AM
Believe it or not, the transmission sent are unencryped data.
http://www.theregister.co.uk/2006/10/24/rfid_credit_card_hack/
Thequestion
11-04-2006, 10:37 PM
I think that they are less safe. Because it's one more way to be hacked and abused.
I agree with sevver, the best way is the save up and use cash.
schalicto
11-04-2006, 11:11 PM
I think they are one of the biggest mistakes that Visa has ever made and RFID is the future of credit card fraud. I'm taking my tin hat and putting my wallet in it.
-Josh
tokenuser
11-05-2006, 01:49 AM
Believe it or not, the transmission sent are unencryped data.
http://www.theregister.co.uk/2006/10/24/rfid_credit_card_hack/What the report shows is that the cards they used for testing were unencrypted. RFID has an encryption layer that WAS NOT implemented on the cards tested. Despite the fact the Visa and AMEX were mentioned in the report, there was NO mention of if these are commerically issued cards or test cards/devices.
This taking The Register as a legit news source is risky. The RFID debate is about as relevant as the Diebold voting machines debate - the cards were tested in dubious circumstances using pre-production cards that HADN'T HAD SECURITY ENABLED.
I deal with banking software on a daily basis (yeah - more than just accessing an ATM ;) ), and they would not let this happen to live client data - their liability insurance would be worth nothing if they did.
schalicto
11-05-2006, 03:13 AM
What the report shows is that the cards they used for testing were unencrypted. RFID has an encryption layer that WAS NOT implemented on the cards tested. Despite the fact the Visa and AMEX were mentioned in the report, there was NO mention of if these are commerically issued cards or test cards/devices.
This taking The Register as a legit news source is risky. The RFID debate is about as relevant as the Diebold voting machines debate - the cards were tested in dubious circumstances using pre-production cards that HADN'T HAD SECURITY ENABLED.
I deal with banking software on a daily basis (yeah - more than just accessing an ATM ;) ), and they would not let this happen to live client data - their liability insurance would be worth nothing if they did.
I can't talk about the detail at which I deal with banking software on a daily basis. But if it is secure, then why doesn't Visa release a report about the security so that us security minded people will know that it is safe.
-Josh
sevver
11-05-2006, 05:30 AM
I deal with ATM machines almost on a daily basis, I install alot of them, configure them, and set them up on the network. Lots of fun...:rolleyes:
kl0ndike5
11-24-2006, 08:40 PM
i'm going to go clinton on you, define SAFE?
how 'safe' can anything be if i can buy an RFID writer?
http://www.gizmodo.com/gadgets/tag/rfid-readerwriter-sd-card-36051.php
Ringwurm
12-07-2006, 01:49 AM
RFID is fairly safe.
and for those of you who argue that it isn't, think about this: A regular credit card number is availible to anyone within eyeshot each time you take it out.
if you want more information on RFID cards, check out this month's Popular Mechanics