EEVblog

  Переглядів 129,269

EEVblog

EEVblog

День тому

Do those RFID/NFC shielded wallets and bags actually work to protect your contactless credit cards?
Systems like VISA PayWave and Mastercard PayPass.
Does aluminium foil work?
Dave does some measurements to find out using a H-Field probe
TekBox EMC probe set: amzn.to/1YkCLPO
Teardown video of a 125KHz RFID Tag: • EEVblog #539 - RFID Ta...
Forum: www.eevblog.com/forum/blog/eev...
ISO/IEC 14443 Standard:
en.wikipedia.org/wiki/ISO/IEC...
EEVblog Main Web Site: www.eevblog.com
The 2nd EEVblog Channel: / eevblog2
Support the EEVblog through Patreon!
/ eevblog
EEVblog Amazon Store (Dave gets a cut):
astore.amazon.com/eevblogstore-20
T-Shirts: teespring.com/stores/eevblog
💗 Likecoin - Coins for Likes: likecoin.pro/@eevblog/dil9/hcq3

КОМЕНТАРІ: 426
@iamdarkyoshi
@iamdarkyoshi 7 років тому
I feel like a simple solution to these cards would be a resistive sensor or something (such as two metal contacts that you place your finger over) and without your finger on them, the card doesn't talk.
@Shocker99
@Shocker99 5 років тому
Myself and a couple of friends had the exact same idea in 2012. One of the friends went off and created a security technology company. No doubt they attempted to go with the idea. The company got millions in funding but they still went bankrupt, so i imagine it wasn't a winning idea. I haven't spoken to the friend in quite a few years - grew apart and all that.
@leonkernan
@leonkernan 7 років тому
Yeah right, Mrs EEVBlog's bag.. It's your new manbag isn't it :-)
@EEVblog
@EEVblog 7 років тому
Busted.
@DerPapierfliegernarr
@DerPapierfliegernarr 7 років тому
+EEVblog hey dave, with some effort i think at 15:55 you can read the credit card number... Just a guess.
@EEVblog
@EEVblog 7 років тому
I don't see it.
@DerPapierfliegernarr
@DerPapierfliegernarr 7 років тому
+EEVblog well, i just wanted to let you know ;)
@miawgogo
@miawgogo 7 років тому
+EEVblog ahh he can see the bumps being show by the lights reflecting off the tape
@emuboy85
@emuboy85 7 років тому
Love that DaveCAD works beautifully even on small screens.
@tHaH4x0r
@tHaH4x0r 7 років тому
Reminds me of a few of my student mates. They made a tranceiver and antenna for scanning RFID cards from a distance of up to 10 meters. Worked pretty well, they could scan university cards from people walking below past the window of the lab.
@Garganzuul
@Garganzuul 7 років тому
Do you have documentation? I'm planning an art installation to show that RFID maybe isn't the best idea.
@tHaH4x0r
@tHaH4x0r 7 років тому
No I dont, and if you want to do it you should try to develop it yourself instead of stealing all the work other did. You cant just take something someone else has worked on for two whole years and then make some quick fame by trying to make it art. Especially not without paying them for their work. Also, when encrypted RFID is just fine.
@martinda7446
@martinda7446 7 років тому
Ouch!
@martinda7446
@martinda7446 7 років тому
All this technology is well known, for last 150 years..nobody owns much here..You just make it bigger and more sensitive, but still there is a limit and it will be in region of a meter or two - 10m ? not sure.
@tHaH4x0r
@tHaH4x0r 7 років тому
That is true, but making it long range is still an area that has development. From what I understand one of the main problems is the LNA in the input. Noise overall is the limiting factor in these systems, and i agree, i doubt a system could be effective further than 10m if the encoding used is BASK (which generally has to have a fairly large signal to noise ratio).
@neddyladdy
@neddyladdy 7 років тому
That is RF . RF stands for, wait for it, Radio Frequency. 873 kHz is a frequency that my radio can pick up, is designed to pick up. It is RF !
@EEVblog
@EEVblog 7 років тому
Start by looking up Near Field vs Far Field theory.
@drasiritzbir
@drasiritzbir 7 років тому
Aehm.. No!
@markholm7050
@markholm7050 7 років тому
+EEVblog Either in classical Maxwellian electrodynamics or in the quantum mechanical version, this is a case of electromagnetic radiation. Electromagnetic radiation is produced at the transmitter coil and absorbed at the receiver coil. The difference between near-field and far-field is that in far-field, the math is simplified greatly by making assumptions. Those assumptions break down in the near-field case. The physical phenomenon at work is the same.
@markholm7050
@markholm7050 7 років тому
+Mark Holm Near field-theory is the more nearly "correct" version in either classical or quantum electrodynamics. If one were being picky about theoretical correctness, one would insist on the full, near-field treatment regardless of distance. Of course, you would find that, at larger distances, some terms of the equations calculate to very, very small values, and you would, rightly, question whether there was any purpose to all that extra number crunching.
@markholm7050
@markholm7050 7 років тому
+Proximity Mine Both Maxwell's and quantum electrodynamics make this clear. You can not separate the magnetic and electric field components. NFC is a classical, Maxwellian theory. NFC says that there are aspects of the electromagnetic field that fall off at 1/r and aspects that fall off at 1/r squared. Far field theory simplifies the math by ignoring the components that fall off as 1/r squared. In quantum mechanics it gets wilder, with "real" and "virtual" photons. These are poor choices of names. All the photons are real. The "virtual" ones participate in interactions that are quite real, but counterintuitive. As in the Maxwellian version, the contributions of "virtual" photons fall off as 1/ r squared.
@oneofus7828
@oneofus7828 7 років тому
Thanks for clearing up the misconception and highlighting the technology.
@ElectricGears
@ElectricGears 7 років тому
I really don't understand why they don't just build in a little metal dome switch on the card that must be pressed to allow power to the chip. It's blindingly obvious, super simple and 100% read proof until the exact moment of payment.
@bigwheelsturning
@bigwheelsturning 7 років тому
I've had my card wrapped in "AL-foil" for about a month. Now I know I'm "mostly" safe. Thanks for this video and the knowledge it passes on to the public. My bank couldn't even give me a straight answer about this.
@thekaiser4333
@thekaiser4333 7 років тому
A tap and go skimmer was the first device I built with what I learned on EEVblog. It works like a charm and finances all my subsequent projects. Thank you dave.
@EEVblog
@EEVblog 7 років тому
Cool
@FerroNeoBoron
@FerroNeoBoron 7 років тому
Creating foil card sleeves seems like a much more practical solution than buying entire accessories to solve the problem.
@EEVblog
@EEVblog 7 років тому
Indeed.
@peterjansen5498
@peterjansen5498 7 років тому
I wanted to totally disable the RFID function of my card. The answer was simple. A small notch in the bottom edge of the card, just a few mm, breaks the coil and stops it working.
@Keith_Ward
@Keith_Ward 7 років тому
Thanks for covering some of this Dave. It would be interesting to see more testing, experimentation, and methods of protection and disabling cards in the future. It was too bad that Mythbusters were never able to air their findings due to threats possible lawsuits even relate to talking about it. They are pretty tight lipped about it all to this day.
@DanielVidz
@DanielVidz 7 років тому
From taking screenshots of your lovely scope I'm able to ascertain that your name is Dave.. Joking aside I imagine with even just Al foil the eddy currents would produce enough noise to disguise the AM packets, although they are sent after the circuit is charged but at that freq it probably stops the induction to the receiver coil in the first place.. I love how every second week these card are on the news as a "security risk" but never referring to the RFID technology itself. Anyhow great video mate..
@Neovo.Geesink
@Neovo.Geesink 7 років тому
Thats the REAL PERFECT way to really explain those "RFID" cards! Perfect, and Understandable. Indeed, It is a Inductively coupled system.
@BobDiaz123
@BobDiaz123 7 років тому
The fun thing to do is have a larger coil in the purse that also picks up this magnetic field and outputs random noise in the RFID bands. The best part is that under normal conditions it does nothing, only when you're being scanned by some thief.
@4IN14094
@4IN14094 7 років тому
Mythbusters actually get banned by discovery channel's investors from testing NFC card security, that is now insecure these cards is, saddly, all banks now only issue NFC cards, HUGE mistake IMO
@marianoaldogaston
@marianoaldogaston 7 років тому
yes I hear a reported of that. they say that when was filming a lot of visa lowers come. and they decide not to air that episode
@Th3Su8
@Th3Su8 7 років тому
My bank recently gave me a new card that does not have the NFC technology. It still has the magnetic strip and the new thing on it is a chip.
@foobargorch
@foobargorch 7 років тому
They've got plenty to deal with before they get to NFC... watch?v=VdlKtexIUU8
@TravisStanford
@TravisStanford 7 років тому
Not true just got a new card from my bank a month or so ago. No chip and no NFC. U S A! U S A! lol
@neardood1
@neardood1 7 років тому
Dave Cad... classic :D Also, this technology is very similar to the QI standard for wireless charging for phones & tablets. Instead of sending the credit card data, the device sends information to the pad such as how much current to supply and when to stop by modulating the load on the phone's internal charging coils.
@PaulSteMarie
@PaulSteMarie 7 років тому
Not an RF field? That's exactly what this is! That schematic you drew is equivalent to a good old fashioned crystal radio with a loopstick antenna. Generally, any of the antennas with circular elements work by coupling the magnetic (B) field, while dipoles and related things like yagi arrays couple the electric (E) field.
@DavidLindes
@DavidLindes 3 роки тому
Thanks for this comment... I was wondering about the statement at 1:50, and was going to ask: what’s the difference? I thought antennas we’re basically just strangely shaped (as compared to the coils we’re used to when talking about them as) inductors... though magnetic versus electric coupling definitely sounds like a difference... still, Dave, if you see this, I’d love to hear more about what you see as the differences. (Feel free to point me in the direction of existing videos, of course...)
@ChipGuy
@ChipGuy 7 років тому
With the TI RFID Development kit TRF7970A I managed to read more than 10 cards at the same time. However I have seen tags that use the 125 kHz system for building access control interfer with the theft protection of a Fiat Punto. It took my friend at work several weeks to figure out what was going on and why his car didn't start sometimes. That was before 2006 though.
@EEVblog
@EEVblog 7 років тому
Yes, my 125KHz lab access cards don't work with two in my wallet.
@SproutyPottedPlant
@SproutyPottedPlant 7 років тому
The convenience outweighs the risk apart from when it interferes with my bus pass!
@kaizen9451
@kaizen9451 7 років тому
Informative video Dave. Well done.
@ghammatx
@ghammatx 7 років тому
Great vid and explanation Dave, but could you please also show how you do the measurements, I know most people will argue that the video will take too long, but it can be interesting to learn more about more complex measurements sometimes :)
@MilanKarakas
@MilanKarakas 5 років тому
Good Lord! It works. Just two layers of aluminum foil inserted in my wallet and NFC can't read anything. Thank you very much for that advice!
@bbkr2063
@bbkr2063 7 років тому
Tip: Last NFC transactions history is stored directly in most Visa cards. There are applications to read them also. This video focuses a lot on scanning aspect, but scan is useless without SE response. So the only way to actually steal money is to perform MitM attack with HCE endpoint to emulate SE. As for biometric passports - data is encrypted and key is generated from passport number, date of birth and date of expiration. That's why you have this
@timturner7609
@timturner7609 7 років тому
thanks for sharing your cc# on the scope lol
@gblargg
@gblargg 7 років тому
He also shared it in the reflection of the tape over the numbers near the end.
@deadfreightwest5956
@deadfreightwest5956 7 років тому
More sophisticated than a charcoal rubbing of a pocket to determine the contents.
@timlipinski2571
@timlipinski2571 7 років тому
Been using metallic Christmas foil wrapping paper in my wallet to protect my credit cards. Thank you for the video ! tjl
@stephenmorrish
@stephenmorrish 7 років тому
People have seen skimmers walking the London Tube with handheld Point of Sale devices. Here in the UK the limit is a much more manageable £30. Still spend a few hours walking about London crowds and you could make a decent living. Electronically pickpocketing £30 quid a time.
@steve24822
@steve24822 7 років тому
There is no hope of this working. The owner of the pos device would never receive the money. The financial rules that apply are far too strict. Sounds like a "plausible" myth to me.
@zee-lusay4087
@zee-lusay4087 7 років тому
I'm sure every real business would pay good money to find out ho to get your cash quickly from the ACH.
@mrwonk
@mrwonk 7 років тому
Hey Dave, how about a video on those little security chips. Those look pretty neat to me.
@expertmax32
@expertmax32 7 років тому
If you want to disable your payWave or PayPass chip, simply cut the side of the card where the wire loops around the card. You don't need to cut much, only to rupture the loop.
@nathantron
@nathantron 7 років тому
if people are so concerned, and they don't care to use the touch and go of the card, then I would just say they should exacto the coil and break the circuit.
@theLuigiFan0007Productions
@theLuigiFan0007Productions 7 років тому
Hole punch. Break a single wire and the coil is useless, and a small hole doesn't hurt it's normal use.
@kaizen9451
@kaizen9451 7 років тому
+theLuigiFan0007 Can confirm. I did this with my uni ID card by accident XD.
@smellybox309
@smellybox309 7 років тому
why do i find 'Dave CAD' funny with the smiley face in the D? i do not know but it made me laugh (3:10)
@aerobyrdable
@aerobyrdable 7 років тому
For years now, on my circuit diagrams, I've put a little DaveCAD smiley in the corner, just cuz it makes me chuckle ;)
@dave_archer
@dave_archer 7 років тому
You can get a commercial DaveCAD license from EEVblog so you can use it on the back of more then one envelope lol
@aerobyrdable
@aerobyrdable 7 років тому
heh, yup. Perhaps I should have clarified that these are drawings I was making for myself alone in my room :P.
@edwardecl
@edwardecl 7 років тому
You are using an unauthorised version of Dave CAD.
@johaneriksson433
@johaneriksson433 6 років тому
smelly box "Lets go to DaveCAD" Always gets me
@MartinPHE
@MartinPHE 7 років тому
lol the black tape reminded me of the scraped off ICs, And you thought all along those foil cone hats in the 80's was all for just laughs.
@Elecifun
@Elecifun 7 років тому
Also NFC TagInfo by NXP gives lots of data.
@SomeMorganSomewhere
@SomeMorganSomewhere 7 років тому
I'd say that the reason people think that putting cards together will protect them is that a lot of implementations don't do anti-collision properly. Haven't tested it with Opal, but certainly the MyKi readers in Melbourne don't implement anti-collision, if it sees multiple cards it just gives up. So they've probably seen a message like "multiple cards detected, try again" and assumed that that means that the system can't read them if there are multiple cards there. As far as reading them from a distance, there's an application note, I believe on the TI website which covers building long range antennas for RFID, after a point you end up with something that looks like the anti-theft tag gates in shops. What I'd be more interested in (haven't got around to actually testing it though) is how much of the signal you could passively sniff while a transaction is in progress, because although the system is designed to use magnetic coupling, 13.5MHz propagates reasonably well so you're going to get some degree of RF leakage.
@Giorgist
@Giorgist 6 років тому
You will find that the credit card details can be retrieved. If you had pressed the tag information, you would have seen the credit card number.
@BeerTower
@BeerTower 7 років тому
To clarify: the message that the chip sends to authorise a transaction and prove that it isn't a clone (the cryptogram) is protected by strong cryptography, but information that is also present on the front of the card or on the magstripe, such as the card number, is always transmitted in the clear. So it's possible to skim a card and use the card number to shop online or something, but, in principle, it's not possible to physically clone a skimmed card. In practice, this isn't always true, mainly due to American banks that don't bother checking the cryptogram.
@BeerTower
@BeerTower 7 років тому
+Francois Molinier nope, the cryptogram is the response part of a challenge-response protocol. it's a digital signature of the transaction details and a nonce, so a MITM won't work as these will be different for a different transaction. this is all moot anyway since the card will give you the number if you ask for it, and that's all you really need to make a transaction
@glenwoofit
@glenwoofit 7 років тому
A friend of mine was on the standards committee for the design of all RFID banking cards and he went through the maths regarding theft and RF levels both to activate the card and the RF from the card and the chance of someone stealing your data is very low. Anyway you'll get your money back as it was an unauthorised transaction.
@thenaimis
@thenaimis 7 років тому
I haven't tried taking it apart so I don't know what tech the Tesla key uses, but other metal keys in my pocket sometimes interfere with the car's ability to read the key. That's over a much longer distance though.
@roladun
@roladun 6 років тому
Hey EEVblog, I might not be absolutely correct but it seems RF communication works with the same principle as RFID cause you are still using the same electromagnetic field for TX and RX except that the distance has to be very closed for reception. The current that is oscillating in RF antenna induce the same magnetic field for long distance transmission, and at the destination end you surely do need the antenna where the same signal will be induce except that mechanism for reception is different, but basically the medium is still the same. Thanks for pointing this out.
@Kosmonooit
@Kosmonooit 7 років тому
Beats the paint-drying Lab Re-arranging vid Dave :) Seriously, was insightful. Actually quite simple how it works in terms of coms. But surely the card is read only, so if you could capture the traffic and decode it, one could emulate it? Or perhaps there is some sort of 'key' on board, like SSL
@diogosoaresmendes
@diogosoaresmendes 7 років тому
In Portugal the code is asked every 60€ of purchases and if a single transaction is more than 20€.
@daniels7424
@daniels7424 7 років тому
Soo good, keep it up!
@davidatri2344
@davidatri2344 7 років тому
It was my understanding that RFID referred to card containing actual RF chips which also contained a coil. So when you slid your card through a magnetic field (think hotel room key) the RF chip would be able to send a code in a single RF burst, which was then read by the receiver. Is this technology also employed? Why is this not used in credit cards? Awesome video Dave!
@BoB4jjjjs
@BoB4jjjjs 4 роки тому
"Don't wear it on your head, put it in your pocket" lol.
@terrygoyan3022
@terrygoyan3022 7 років тому
Do the tags put into clothing etc. work on the same principle and iso standard? I'm just curious as to the function expected by the use of these tags. They seem very intrusive.
@afifahahmad4770
@afifahahmad4770 6 років тому
Hi! Where can I find more details on the schematic you've drawn in this video?
@marcelbreiti8473
@marcelbreiti8473 7 років тому
Hagenberg goes EEVBlog ;-)
@TomZ23
@TomZ23 7 років тому
in the USA, I don't think banks issue cards with the RFID chip anymore. As a matter of fact, I remember all my cards being replaced without the RFID symbol. They only contain the chip.
@MadManMarkAu
@MadManMarkAu 7 років тому
Actually, the modulation is ~106KHz. (13.56MHz / 128). It only goes to 847.5KHZ (13.56MHz / 16) after the PPS handshake between the PICC (card) and PCD (reader). The card has to say, "I support these baud rates" during the RATS command, then the reader has to choose the baud rate to use with the PPS command. Otherwise, spot on, mate! I didn't know you did RFID stuff.
@Vliegendehuiskat
@Vliegendehuiskat 7 років тому
Thanks Dave. Just for your information: Skimming like this is already happening in Europe.
@wgm-en2gx
@wgm-en2gx 7 років тому
Hey Dave, would love to see you do something with the keyless "fob in pocket" start auto systems. The rumor is that criminals can place a transceiver near your house say at the front door where a lot of people leave their keys and basically extend the range to get into the car. Don't know what happens if they start it and drive away. Does the engine shutdown when the key is no longer in communication range?
@krisztianszirtes5414
@krisztianszirtes5414 7 років тому
What if they use a few shorted turns in the fabric to keep the induced voltage at ground zero? Can the transmitter get anything if you have shorted turns under it?
@rolaroli
@rolaroli 7 років тому
If you are worried about people stealing your data you could always just disable the RFID functionality. I know that my bank has an option online to just turn the feature off. The same option is there to disable the magnetic strip. What this does is probably just declines any transactions made when using those technologies.
@Purkkaviritys
@Purkkaviritys 7 років тому
I would like to see Dave take a look at the rfid Guardbunny created by Kristin Paget. First featured at schmoocon 2012 and later went openhardware and got an article on Hack a day.
@hanelyp1
@hanelyp1 7 років тому
Such a shield works while the card is in it. Remove the card to use with the RFID scanner at checkout and a black hat behind you in the checkout line doesn't even need to transmit anything to pick up the signal.
@TheGatecrasher53
@TheGatecrasher53 7 років тому
Dave keeps going on about how it's "not an antenna", and that it uses magnetic coupling not "RF fields", but aren't they essentially the same thing, just longer distances? Like all EM waves are composed of Electric and magnetic fields right, so what makes this different?
@sarowie
@sarowie 7 років тому
Look up "Near and far field". In the near field, E-Field (electric) or H-Field (magnetic) can dominate. In the far field, there is a fixed ratio of E- and H-Field which is given by the impedance of air, which is about 377 Ohm. In this application, the H-Field dominates, meaning the impedance is much lower then the air impedance of 377 Ohm. For a radio broad cast transmitter you would aim at matching impedances of transmitter and antenna to increase efficiency.
@MomirPeh
@MomirPeh 7 років тому
My thoughts exactly. Let's take a FM radio broadcast station for example... It is a BIG primary and the receivers are all secondaries in a big imaginary transformer... Magnetic coupling being the magic phrase here.
@TheGatecrasher53
@TheGatecrasher53 7 років тому
+sarowie thanks for the jumping off point. Does this mean the phone is still generating a small far-field RF signal at its MHz carrier frequency when searching for a nearby tag and could u pick that up on a spectrum analyser?
@rownadoherty
@rownadoherty 7 років тому
Yeah, I'm starting to feel like he just does these things on purpose. Saying controversial things like "it's not an antenna", or that "current flows through capacitors". Then he watches the comment numbers mount and the view count climb. Great business model.
@rownadoherty
@rownadoherty 7 років тому
It's an antenna in the near field.
@shadowguidr7042
@shadowguidr7042 7 років тому
I know of someone who used to chat with their victim. They worked in a shop with a card reader that they would put the card in and hand to the customer. They would get in to a surprised sorta reaction, put the card down on their touchless payment machine and and get an easy £30. Somehow it was also untraceable.
@ezquimal
@ezquimal 4 роки тому
I remember in the 90 all the public phone use that chip for cards with credits. And we use a eprom with the software to emulate and call free.
@ejonesss
@ejonesss 6 місяців тому
is it possible to use a jammer to jam the 13.56 mhz to prevent the tap from working at all? the scenario is someone could broadcast a blank 13.56 mhz wave so the terminal cant read so it prevent the transaction to force the use of the chip or swipe so the skimmer could be used. in the past when the chip came out criminals would make the shimmer insert have some tab to block the chip so when you put the card in it would not make connection to the chip at all or it would have some wires to corrupt the signals to the chip to make the transaction fail so it forces the customer to swipe. i am asking because i suspect that a couple gas stations here in the united states may be in on a skimming ring and they say it is a problem with the card or security.
@hereiam2005
@hereiam2005 7 років тому
Can you get the hex dump from the oscilloscope image? :D
@zlac
@zlac 7 років тому
you don't have to put it all around, one layer of foil on any side is enough because it detunes the resonant frequency a lot.
@EwanMarshall
@EwanMarshall 7 років тому
Oh, I have a slight issue with how you are thinking modulating a coil is not a radio? The difference between a transformer and a radio is the radio modulates the electromagnetic field (we call it electromagnetic radiation for a reason). My one transistor AM crystal radio works exactly the same way using the radio signal to provide enough current to run it, admittedly I do ground it rather than ground to the other end of the coil. I bet if I tune a heterodyne receiver to 50Hz I'll be able to here a continuous 50Hz radio signal. With a powerful enough radio signal one can in fact activate one of these cards.
@thanasisathanasi4965
@thanasisathanasi4965 5 років тому
Best video on how NFC works but with wrong title
@scottfirman
@scottfirman 7 років тому
yeah,I guess i would be more converned with the ones they are sticking to the front of gas pumps and at rest stops. seems here in Michigan,theives have targeted the main areas they know people in a hurry to travel stop. they have already hit up several gas stations and rest stop machines.
@jackhowardbourne
@jackhowardbourne 7 років тому
The ISO14443 standard calls for readers to have a minimum of 1.5A/m output. ISO15693 calls for 2.0 A/m. if anyone's interested. ISO10373 is concerned with the measurements of the readers. Your phone will be producing around 1.0A/m at 13.56MHz. the ISO14443A ID1 credentials can sometimes read somewhere around 0.3 to 0.4A/m depending upon the amount of processing involved. Actually you'll find that most cards won't be read over about 15cm with a reader producing 4A/m as the magnetic field just isn't strong enough. You won't find anything portable over 4A/m as you start needing a beefy RF amp It is quite possible for these cards to be read from this distance but like Dave said, it doesn't mean they can actually set the transactions up.
@shadowguidr7042
@shadowguidr7042 7 років тому
In the UK it's just 'touchless payment' and limited to £30 afaik.
@ElectraFlarefire
@ElectraFlarefire 7 років тому
This is why no-one with any technical knowledge should call them 'RFID' cards. These are all NFC(Or near-field-commutation) cards. Dave gets half a break as he's using layman's terms for ease of explanation, but searching for 'NFC' reader and 'RFID' reader gets quite different results. Many public transport cards use the same tech, so they make for great test cards if you don't want your credit card shown on air. :) And if you want a somewhat overpriced(due to postage outside of us) way to see what tech a reader uses: dangerousthings.com/shop/rfid-diagnostic-tool/
@EEVblog
@EEVblog 7 років тому
Yes, true. The term RFID seems to pervade the industry though, although in regards to phones it's usually NFC.
@EEVblog
@EEVblog 7 років тому
BTW, The ISO 1443 standard itself uses the term RFID
@ElectraFlarefire
@ElectraFlarefire 7 років тому
That I didn't know! Shame on the ISO standards! Also, as far as I know, these 'shields' act as much like a shorted turn as magnetic shielding, taking the energy the card requires and turning it into heat. A 'loop' of aluminium sheet works as a great shield, but one with a break in it(Still overlapping, but insulated) doesn't. For photos: goo.gl/photos/nWY5YPL9KhZabgFP9 I believe the more conductive the material the better it works in this application. I wish I had a piece of ferrite large enough to test this further.
@Garganzuul
@Garganzuul 7 років тому
The standard is correct. Maxwell is correct. "NFC is secure" is wrong.
@Schwuuuuup
@Schwuuuuup 7 років тому
To the end the sticky tape sticks more and more against your card and the risen numbers.. you show the card from various angles and with lighting from different sides... bad people could try to read the numbers. CRC could even help them to guess... yes, I know there are still things missing like the security code from the back, but I would have used a thicker tape, blurring the outlines of the numbers more.
@sarowie
@sarowie 7 років тому
They rise the numbers in Australian debit cards?! On debit cards in switzerland and germany, the number is just printed. Same with prepaid credit cards. This even true for prepaid credit cards (which are additionally marked with "online use only"). I have only seen risen numbers on true credit cards.
@CherryDT42
@CherryDT42 7 років тому
+sarowie There are also risen numbers on some prepaid cards, as a "feature" to make the cardholder feel less cheap. (Bullshit of course)
@sarowie
@sarowie 7 років тому
***** The marketing departments of banks seem silly to me. As a costumer, I care for functionally and prices. Maybe I care for the card "not looking like an ugly unprofessional mess", but thats about it. At least in europe, sells personal does not care what type of card you are holding as long as the machine says that the transaction was successful. Those risen numbers only remind me of the old paper transaction system that copied the card details mechanical on to paper. As I grew up in Switzerland, I feel any system other then Chip and Pin as antique and outdated - I hate it, that in Germany I have to hand over my card and sign a slip of paper. Let alone when they take my card and scan the mag-strip. So not having risen numbers feels better for me.
@Schwuuuuup
@Schwuuuuup 7 років тому
I have a German debit card with risen numbers (issued this year), so it is a Swiss thing or depends on the Bank. Maybe they do it because that's what older people expect, it doesn't really hurt and - maybe - you can use it in some less developed countries, that do still use paper transfer... but I Don't know if those exist.
@sarowie
@sarowie 7 років тому
Schwuuuuup Maybe my definition of "risen" varies from yours. On my debit card, the number is ever so slightly risen - there one layer of sticky tape should be enough to make the number unreadable on camera. But on a credit card, the number is really embossed.
@featheredskeptic1301
@featheredskeptic1301 7 років тому
I have an idea or two about a protection features that can be added to these cards. How about if the chip in the card only starts working if it detects the electrical resistance from your fingers on the card? That way the only way the card can work, is if you are holding it. Otherwise it's only going to activate the coil if it is within a 13.56MHz magnetic field but there isn't going to be any data exchange. Something like a metallic grid on the card that should read somewhere between say 10 and 50 koms in order to start the chip. Or have specific finger locations that you need to hold the card at, in order for it to work. And there is even a simpler way to do it, just put a dome switch in the card that should be pressed in order to connect the coil to the electronics inside. Needless to say that it's location must be a bit deeper in the card in order to prevent the button getting pressed while in your purse or pocket. That way you can only activate the card if you are holding at a specific location and apply some relatively significant pressure.
@JesusvonNazaret
@JesusvonNazaret 7 років тому
Cut the handbag open and search that protective layer!
@yakacm
@yakacm 7 років тому
once u have used the app to read your card what's to stop the app squawking all your card details back to whoever wrote the app? This technology is called contactless payment here in the UK BTW.
@KennethScharf
@KennethScharf 7 років тому
Just put the card in an aluminumized envelope, just like you'd do with those toll transponders. I'd have thought that putting the card inside of an aluminum box would shield it because the box should act as a shorted turn in the transformer.
@JimFortune
@JimFortune 7 років тому
So you trade the inconvenience of swiping your card for the inconvenience of wrapping and unwrapping your card in tin foil. (Yes, I know it's not tin.)
@benjaminc1816
@benjaminc1816 6 років тому
A perfect solution to stop these cards being read without the owners permission would be to embed a photo diode into the body of the card that only allows the circuit within the card to activate when it is in ambient light (ie out of a persons wallet) then when it is in the wallet / bag, it would be unreadable.
@bobbym3155
@bobbym3155 7 років тому
could you use some gadgets in your lab to generate a more powerful transmitter? That would have been interesting. And to test the max distance with the phone's power and plot it out
@darainmann8895
@darainmann8895 7 років тому
great video as always, some banks NAB for example, offer a paypass for your phone which basically acts just like your card for transactions. I obviously turn my NFC off, but I wonder if someone didn't could readers do the same thing or would there be some kind of extra security level in it's software?
@EEVblog
@EEVblog 7 років тому
Probably works the same from an authentification point of view. But you need an approved transaction system to do it.
@CherryDT42
@CherryDT42 7 років тому
Normally you get an app where you have to enter a PIN or such.
@darainmann8895
@darainmann8895 7 років тому
***** yeah a pin is optional but not as default
@RomanDvoryadkin
@RomanDvoryadkin 5 років тому
You can expose card by power flashlight and see embedded coil and chip
@OneBiOzZ
@OneBiOzZ 7 років тому
we JUST got chip and pin to be widespread in america ... i got my first one recently 10 more years we might get this RFID :P
@08Ultrasonic
@08Ultrasonic 7 років тому
Does the alignment between the transceiver and the card matter?
@kirknelson156
@kirknelson156 7 років тому
I don't know about Australia but many places in the US they have RFID tags in the cars for toll roads, the readers are over the road at least 16 feet in the air, they can record me passing even at 75mph. now i doubt the protocols are the same but i'm fairly sure the tech is. larger antenna and more power obviously, but since your not a criminal and not equipped with these toys I wouldn't discount the criminal elements ability to procure such devices.
@TheSkogemann
@TheSkogemann 7 років тому
"This is NOT a RF system, it works on magnetic fields instead of RF-fields" o.O Well, what are RF-systems working on ? RF-systems are in theory a transformer system - and yes, they are called antennaes.
@aeroscience9834
@aeroscience9834 6 років тому
SnopFop - TheSkogemann rf (and other EM waves) are composed of electric and magnetic fields, but a pure magnetic field acts differently than an EM wave. That's why transformers and rf antenna/receiver systems follow different equations.
@jonathanseyfert8256
@jonathanseyfert8256 6 років тому
RF systems are NOT transformer systems. Transformers have magnetic coupling across the coils, RF systems do not couple between antennas. If you put a load on the secondary coil of a transformer, that creates a major load on the primary. If you turn on your radio in your car, that doesn't load the broadcast station at all. They have no clue if you are listening or not except with surveys. RF systems use electro-magnetic radiation, not just magnetic fields. Transformers use magnetic fields and don't give a crap about electric fields.
@derek7808
@derek7808 7 років тому
Mrs EEVBlog's bag... TAKE IT APART !!
@kylesenior
@kylesenior 7 років тому
"Not valid unless signed" Nice to see I'm not the only one who doesn't sign their cards. Zero point in doing it.
@EEVblog
@EEVblog 7 років тому
Signatures are not valid any more in Australia, officially phased out.
@kylesenior
@kylesenior 7 років тому
Well yeah, still says the card isn't valid without it though.
@Yeti_
@Yeti_ 7 років тому
I can never even get the ink to stay on there anyway. Not sure what sort of marker / pen it's expecting me to use :(
@EEVblog
@EEVblog 7 років тому
It's a throw-back since before they changed the rules recently. I guess they couldn't be bothered changing their card stock.
@joea3728
@joea3728 7 років тому
Here in the United States, there are some Agencies/companies that will not accept a unsigned card for certain transactions, like the US postal service when purchasing money orders. Although I do not see the point in it, since they normally hand you a pen, and tell you to sign your card. How does this prove that you are who you say you are, it only proves that you may have forged someone else's signature. and by the way, None of my credit cards have the RFID symbol on them. in the US, credit card companies and banks are getting away from the RFID cards. Replacing them with the newer list vulnerable cards. but they still don't require a pin number.
@billysgeo
@billysgeo 7 років тому
I have tested access control RFID at the 125Khz band and even very thin aluminium works as a shield... :-/
@OliverUnderTheMoon
@OliverUnderTheMoon 7 років тому
Those anti-theft systems at stores use an electromagnetic field, right? Would love to see a hack that turns them into a giant skimmer that could be wheeled up to any store front.
@zee-lusay4087
@zee-lusay4087 7 років тому
Where did you get the reader app for your phone??
@kalleguld
@kalleguld 7 років тому
Did you forget some annotations at the end?
@arsk7112
@arsk7112 7 років тому
hi Dave Actually RF's are magnetic waves so why are you bothering yourself to say its different from a typical RF cable that sends off data in form off some modulation of a RF pulse?
@keitmitkeit
@keitmitkeit 7 років тому
a UNI-T brand battery? (at the end of the video in the lower right corner) :D
@Multi-Coder22
@Multi-Coder22 Рік тому
Funny story, my father had one of the early types and I knew the risks and downloaded a card reader app and said "watch this" pinged his card and it displayed the number and everything then I said "is this your card" he replied "yes, that's not good" so the mobile phone app demo that you did I also used to prove that they were easy to read
@justahappyfellow
@justahappyfellow 7 років тому
Is it possible to emulate a NFC tag with the phone? I.e, store a copy of a tag and emulate it?
@MrMegaPussyPlayer
@MrMegaPussyPlayer 7 років тому
I know that the CC had run some experiments and was actually able to read these information from several hundred meters away. (though it were tags in clothes .. and maybe from the official ID cards which are used around here)
@Garganzuul
@Garganzuul 7 років тому
Who is CC? Do you have a link to the source?
@MrMegaPussyPlayer
@MrMegaPussyPlayer 7 років тому
Sorry, that was a typo. I meant CCC (Chaos Computer Club) and it was an report on TV ... in I think 2014 or beginning of 2015. They have shown a test with a concealed reader (in a briefcase) and they have read RFID tags of clothes from people coming out of store while sitting in a coffee shop across and little down the street. And they talked that they had successfully had read common tags from even more afar (one other source I have found while looking for that source said that it is potential possible to read [special] RFID tags from up to 1km) But sorry couldn't find the original source on the fly.
@CherryDT42
@CherryDT42 7 років тому
I'd like to propose two fixes you might want to add before releasing it: 1) It is actually the same chip as the one seen from the outside, not a separate one (Google images "paywave x-ray"), and this way they can also have the same data shared (e.g. some cards count your contactless transactions and allow only X in a row). 2) They are not just data storage like your usual tag, but the are actively negotiating with the terminal and cryptographically sign transactions. The data you can read out from it alone will not help you much (you do get CC number and expiration date, but not name or CVC2 - it's worse to have your card captured by a security camera than having it scanned). To make a transaction, you would need to go around with a terminal, or relay the communication via the Internet to another phone at a rogue merchant's place, and since merchants must be registered, this makes it a lot harder for criminals.
@EEVblog
@EEVblog 7 років тому
Yes, it's not easy, but it's possible and has been done. Risk is pretty low though.
@memadmax69
@memadmax69 7 років тому
I use my iphone to do the equivalent of the tap n go, but the iphone apple pay has extra layers of protection. Like it needs my thumbprint to work, and if I lose the iphone or it gets stolen(which would result in basically the card was also lost or stolen) I can just simply shutdown the phone with Find My Iphone and not worry about it. So now, all I carry is my iphone with me, all the credit cards stay at home.
@MrHack4never
@MrHack4never 7 років тому
For those curios: ESD bags does NOT block the signal
@StuartYoung
@StuartYoung 7 років тому
Have you seen the jamming cards that deliberately jam the RFID frequencies when they detect a field? I've seen a bunch of these on the market (eg: armourcard, which is an Aus company - they sell them at JB). Would be interesting to see whether they're any good using the testing setup you used there. Interesting story is that I see them on the counter near the EFTPOS pinpads, and every time i get a failed card read at JB (and had to insert the card instead) one of these display stands is pretty much next to the pinpad. Tends to lend credibility to the product, but really silly placement by JB!
@toasty4000000
@toasty4000000 7 років тому
Yeah! Test this!
@EEVblog
@EEVblog 7 років тому
Didn't know about these, and JB Hi-Fi, hmm I could just go pick one up.
@StuartYoung
@StuartYoung 7 років тому
EEVblog​ Last I saw I *think* they were $50ish AUD or something, so not very cheap. Price may have changed tho. If need be i might be able to send you the one I have.
@Davi-did
@Davi-did 11 місяців тому
I don't think that I believe your statement that card information can't be stolen, because how would the store's scanner process a payment? My wife's card had not left it's paper sheath since it was issued, and yet it, and every RFID card in her wallet were compromised somehow. The old cards without contactless payment were unaffected. I call BS on the VISA assertion that this is secure.
@Th3Su8
@Th3Su8 7 років тому
Bummer... I downloaded that program on my phone and tried it with a couple of cards I have not really knowing if they were NFC cards or not. None of them are. Even my passport card I have doesn't. Now I can't play around with it. Oh well. Good video though with a good explanation of how this actually works and NOT "RFID" like the news media would tell you it is.
@bland9876
@bland9876 7 років тому
i wonder if you can make an rf id protected duck tape wallet using that foil
EEVblog #895 - BEC Pro Model Airplane Regulator Testing
31:06
EEVblog
Переглядів 97 тис.
Hacking Through the Air | Contactless Payments and NFC
24:14
Sumsub
Переглядів 165 тис.
Секретная разработка КГБ! Волга «Догонялка» на V8…
1:07:10
Мастерская Синдиката
Переглядів 1,9 млн
SMART GADGET FOR COOL PARENTS ☔️
00:30
123 GO! HOUSE
Переглядів 15 млн
NO NO NO YES! (40 MLN SUBSCRIBERS CHALLENGE!) #shorts
00:27
PANDA BOI
Переглядів 64 млн
Credit card cloning is too easy!
9:07
David Bombal
Переглядів 2,9 млн
What's the difference between RFID, NFC and BLE?
15:42
Jennifer Huber
Переглядів 269 тис.
You will NOT believe what's inside this Credit Card.
4:50
Dan The Technology Man
Переглядів 60 тис.
Do THIS If You Hate Your Job
10:08
Adam Savage’s Tested
Переглядів 198 тис.
Apple vs. Banks: The Digital-Wallet War, Explained | WSJ
5:31
The Wall Street Journal
Переглядів 1 млн
EEVblog #890 - ArmourCard Active RFID Jamming Teardown
25:07
EEVblog
Переглядів 89 тис.
[1056] This Black Box Reads RFID Cards in Your Pocket
4:26
LockPickingLawyer
Переглядів 858 тис.
Do RFiD /Contactless credit card blockers work ?
9:03
Quentyn Taylor
Переглядів 19 тис.
The chip was transplanted to the black card
5:14
chen kevin
Переглядів 201 тис.
Game Boy games that did the impossible.
15:33
Modern Vintage Gamer
Переглядів 159 тис.
iPhone 19?
0:16
ARGEN
Переглядів 3,6 млн
All New Atlas | Boston Dynamics
0:40
Boston Dynamics
Переглядів 4,8 млн
The PA042 SAMSUNG S24 Ultra phone cage turns your phone into a pro camera!
0:24
Сомнительно... Ну Окэй... Распаковал Nothing Phone (2a)
16:19
РасПаковка ДваПаковка
Переглядів 48 тис.
Самая редкая видеокарта от SONY
13:51
Nitroxsenys
Переглядів 49 тис.