How to hack RFID-enabled Credit Cards for $8 (BBtv)

A number of credit card companies now issue credit cards with embedded RFIDs (radio frequency ID tags), with promises of enhanced security and speedy transactions.

But on today’s episode of Boing Boing tv, hacker and inventor Pablos Holman shows Xeni how you can use about $8 worth of gear bought on eBay to read personal data from those credit cards — cardholder name, credit card number, and whatever else your bank embeds in this manner.

Fears over data leaks from RFID-enabled cards aren’t new, and some argue they’re overblown — but this demo shows just how cheap and easy the “sniffing” can be.

This episode is part of our ongoing series of interviews with some of the thinkers, hackers, and tinkerers at the O’Reilly Emerging Technology conference this year.

For more episodes of Boing Boing tv, visit tv.boingboing.net.

Duration : 0:3:23


Technorati Tags: , , , , , ,

Tags: , , , , , ,

Monday, November 23rd, 2009 Credit Cards

25 Comments to How to hack RFID-enabled Credit Cards for $8 (BBtv)

  1. if jesus is real, …
    if jesus is real, why dont he make himself relevant and come perform so miracles now.??

  2. IamInYourClosett on November 23rd, 2009
  3. he probably works …
    he probably works for a credit card company now, a ”reformed hacker”

  4. IamInYourClosett on November 23rd, 2009
  5. awsome thank you …
    awsome thank you for showing me how to steal credit cards mexico here i come.

  6. cody181818 on November 23rd, 2009
  7. I wanna your …
    I wanna your girls to you filthy black bastard… White bankers steal but you know what were at the top of the food chain and you will always just keep on parasiting. GO BACK TO AFRICA WERE YOU BELONG MOTHER FUCKER. CAUSE TRUST ME YOU AINT ALL PUNK.

  8. abcaston on November 23rd, 2009
  9. White bankers also …
    White bankers also rob African natives by helping their parasites store stolen funds and monies in their european and american and arab banks so it is ok for blacks to rob yur credit card accounts. WHITEY I WANNA YUR GIRLS.

  10. michaelfagbemiro on November 23rd, 2009
  11. buyin is the easy …
    buyin is the easy part shippin is easy to your have people all over go look on a mail box and watch for ups lol

  12. Zephonthedark on November 23rd, 2009
  13. stop being such a …
    stop being such a racist bastard!

  14. greggyboy13 on November 23rd, 2009
  15. Racist fuck.
    Racist fuck.

  16. adamshor on November 23rd, 2009
  17. you should tell …
    you should tell your parents sorry for being a wothless piece of and kill yourself. that should solve your problem

  18. red83944 on November 23rd, 2009
  19. holy censorship, …
    holy censorship, ever here of freedom of speech much? better enjoy it now, it wont be here much longer.

  20. misterscreenprint on November 23rd, 2009
  21. try that 2000jago. …
    try that 2000jago. ur probably an american black arent u? u still rob ppl for 20$ at gunpoint? there r lots of black hats trading credit card #s dob address ssn etc in bulk on several underground chat sites. again dont go calling fbi yet. ic3 already knows about this and i dont encourage it but i lov seeing criminals in jail and victims crying

  22. Pleasedonthitmemore on November 23rd, 2009
  23. Holy crap off topic …
    Holy crap off topic much?

  24. nunrgsensation on November 23rd, 2009
  25. You must be joking. …
    You must be joking. “what places to buy from” Do you ever use the internet?
    And everyone knows you ship to an empty house. The “for sale” sign outside and lack of curtains is usually a giveaway. Or any house you know the owners will be away on vacation or whatever. Of course you arrange next day shipping so you can conveniently be there “in the process of moving” to collect. – Don’t you watch TV? I got all that from the discovery channel, but it’s not exactly rocket science you know.

  26. 2000jago on November 23rd, 2009
  27. One could also get …
    One could also get a job I guess…
    You can use the money to go to spelling lessons.

  28. 2000jago on November 23rd, 2009
  29. getting credit card …
    getting credit card numbers this way is risky y not just buy them for 50 of them for $60 on irc or create a spoof site? dont go calling da fbi yet, im not encouraging dis behavior but i love seeing criminals going2 jail and victims suffering

  30. Pleasedonthitmemore on November 23rd, 2009
  31. Getting credit card …
    Getting credit card numbers is the easy part. Figuring out what places to buy from and where to ship the stuff is the hard part. Anyone care to enlighten me on that part of the equation?

  32. logistix11111 on November 23rd, 2009
  33. We offer 100% fresh …
    We offer 100% fresh US,UK EU CCV and fullinfo cc yhm cvvmasters

  34. cvvmasters on November 23rd, 2009
  35. lol you probably …
    lol you probably watched Zitgiest to manny times bro
    One – u obviously didnt do any research because there are more differences than similarities.

  36. majortom321 on November 23rd, 2009
  37. If I was going to …
    If I was going to implement passive RFID I would at least use strong crypto with keys off the card with an integrity check internal to the passive logic.

    This way servers could send decryption keys with public key cryptography based on some unique salt. The key is(no pun intended) to keep the internal that decryption and integrity logic away from debugging/dumping/altering.

  38. tjc0der on November 23rd, 2009
  39. Actually you could …
    Actually you could get a reader with more khz and read without “grabbing asses”

  40. r0dvan on November 23rd, 2009
  41. Damn, i wish i …
    Damn, i wish i could kills 1000′s of people that are just completely stupid…..honestly why post like this up, the fbi are going to watch his like crazy now.

  42. kikiller on November 23rd, 2009
  43. I took a hammer to …
    I took a hammer to my cards. F that.

  44. hippykiller1 on November 23rd, 2009
  45. Book of the Dead^
    Book of the Dead^

  46. Cawby on November 23rd, 2009
  47. Accept Jesus Christ …
    Accept Jesus Christ? Why would I accept a plagiarized story based on astronomy as anything more than what it is? You people really need to get your heads out your asses. The story of jesus christ is almost word for word identical to the story of Horus, written originally in 3,000 b.c. but even so officially on record in the Bood of the Dead in 1300 b.c.

  48. Cawby on November 23rd, 2009
  49. Not to mention that …
    Not to mention that CERN has released the new name of it’s global ‘supercomputer’, called “The Grid”.

    Nice..

  50. PillowcaseHead on November 23rd, 2009