Уровень 0 · материалов: 3
В кластер входят документы, посвященные техническому анализу уязвимостей и методам взлома бесконтактных платежных систем и карт.
Общие признаки: бесконтактные платежи, анализ протокола EMV, клонирование карт, безопасность NFC
Группа выше: Бесконтактные платежи и NFC
Смысл: The text aims to educate readers on the technical inner workings of EMV contactless payments and illustrate a specific security flaw in the MagStripe emulation mode that allows for potential card cloning through pre-calculation of authentication codes.
A technical guide on how EMV contactless cards work and how to exploit the MagStripe mode to clone MasterCard data using an Android app.
Смысл: The article aims to debunk myths about contactless payment theft by simulating fraud scenarios and analyzing the EMV protocol. It demonstrates that while theoretical vulnerabilities exist, the practical application of such fraud is economically unprofitable and technically difficult, especially when using tokenized systems like Apple Pay.
A technical investigation proving that stealing money via contactless terminals is practically unprofitable and that Apple Pay is significantly safer than physical cards due to tokenization and biometrics.
Смысл: The author demonstrates that the 'Siticard' transport system is insecure because it uses an outdated security configuration, allowing anyone with a basic NFC-enabled smartphone and free software to clone cards and reset their balance.
An IT developer demonstrates how to clone Nizhny Novgorod's Siticard and create 'infinite' rides using basic NFC tools and a replay attack.