<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>point of sale &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/tag/point-of-sale/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Fri, 25 Jun 2021 13:55:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>NFC Flaws in POS Devices and ATMs</title>
		<link>https://noise.getoto.net/2021/06/28/nfc-flaws-in-pos-devices-and-atms/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Mon, 28 Jun 2021 11:53:45 +0000</pubDate>
				<category><![CDATA[atms]]></category>
		<category><![CDATA[point of sale]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=63401</guid>

					<description><![CDATA[<p>It’s a <a href="https://www.wired.com/story/atm-hack-nfc-bugs-point-of-sale/">series of vulnerabilities</a>:</p>
<blockquote><p>Josep Rodriguez, a researcher and consultant at security firm IOActive, has spent the last year digging up and reporting vulnerabilities in the so-called near-field communications reader chips used in millions of ATMs and point-of-sale systems worldwide. NFC systems are what let you wave a credit card over a reader — rather than swipe or insert it — to make a payment or extract money from a cash machine. You can find them on countless retail store and restaurant counters, vending machines, taxis, and parking meters around the globe...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Interesting Attack on the EMV Smartcard Payment Standard</title>
		<link>https://noise.getoto.net/2020/09/14/interesting-attack-on-the-emv-smartcard-payment-standard/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Mon, 14 Sep 2020 11:21:36 +0000</pubDate>
				<category><![CDATA[academic papers]]></category>
		<category><![CDATA[credit cards]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[man-in-the-middle attacks]]></category>
		<category><![CDATA[pins]]></category>
		<category><![CDATA[point of sale]]></category>
		<category><![CDATA[smart cards]]></category>
		<category><![CDATA[smartphones]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=60190</guid>

					<description><![CDATA[<p>It&#8217;s <a href="https://arxiv.org/pdf/2006.08249.pdf">complicated</a>, but it&#8217;s basically a man-in-the-middle attack that involves two smartphones. The first phone reads the actual smartcard, and then forwards the required information to a second phone. That second phone actually conducts the transaction on the POS terminal. That second phone is able to convince the POS terminal to conduct the transaction without requiring the normally required PIN.</p>
<p>From a <a href="https://techxplore.com/news/2020-09-outsmarting-pin-code.html">news article</a>:</p>
<blockquote><p>The researchers were able to demonstrate that it is possible to exploit the vulnerability in practice, although it is a fairly complex process. They first developed an Android app and installed it on two NFC-enabled mobile phones. This allowed the two devices to read data from the credit card chip and exchange information with payment terminals. Incidentally, the researchers did not have to bypass any special security features in the Android operating system to install the app...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 29/71 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2025-12-09 22:56:05 by W3 Total Cache
-->