Contactless cards use near field communications (NFC) chips to exchange your payment details with a merchant’s till, and some smartphones also come equipped with NFC chips to let you use them as a wallet. Now security researcher Thomas Skora has written an app that turns any NFC phone into a reader and successfully read card numbers, expiry dates, transactions and merchant IDs from German credit cards.
The app, called paycardreader, was removed from the Google Play store yesterday, but Skora has also placed the source code on GitHub, a code-sharing website, and says the app doesn’t actually save the swiped data, it just displays it.
It is possible that more malicious app developers could use similar methods to actively steal data though – an investigation by Channel 4 television in the UK earlier this year revealed it was possible to swipe details via a phone and use them to make purchases on Amazon.
Blowfish12@2012 blowfish12.tk Author: Sudharsun. P. R.
- Meet paycardreader, the credit card-stealing Android app (news.yahoo.com)
- Meet paycardreader, the credit card-stealing Android app (bgr.com)
- Expert Publishes Android App That Steals Contactless Card Details (news.softpedia.com)
- Android App Lets You Steal Contactless Credit Card Data (it.slashdot.org)
- Android NFC App Reveals Contactless Credit Card Details; Should You Be Worried? (pocketnow.com)
- Swipe Pay preparing mobile virtual wallet (mobile-ent.biz)
- Barclaycard PayTag adds contactless payment to any phone: pictures and hands-on (pocket-lint.com)
- Post Office to introduce contactless payment (guardian.co.uk)
- Contactless pay limit goes to £20 (bbc.co.uk)
- Mobile Payments Still Slow to Catch on in U.S. (pcworld.com)