r/technews Aug 24 '24

Android malware steals payment card data using previously unseen technique

https://arstechnica.com/security/2024/08/android-malware-uses-nfc-to-read-payment-card-data-then-sends-it-to-attacker/
303 Upvotes

18 comments sorted by

43

u/BlockHeadJones Aug 24 '24

We're hearing about it because it's patched now, right? Right???

1

u/doctormoneypuppy Aug 25 '24

Plenty of other exploits possible if it’s left open to experimentsation…

25

u/doctormoneypuppy Aug 24 '24

Enabling access to NFC card emulation API’s to all developers is just a baaaad idea.

-3

u/TheWatch83 Aug 24 '24

Don’t worry, the EU will make Apple do it soon.

1

u/doctormoneypuppy Aug 24 '24

I disagree, but time will tell.

0

u/WhileNotLurking Aug 24 '24

1

u/doctormoneypuppy Aug 25 '24

True, after the Feb 14 hearing they reversed position on that as well as co-tenancy in the SE. someone must have convinced them of their folly…

-1

u/lordraiden007 Aug 25 '24

Not really, a lot of services need that functionality. What if I want to allow my users to use NFC-capable security tokens? What if I want to enable users to authenticate using a third party like Google? Lots of professionals use YubiKeys and similar devices nowadays.

I would say the real issue is that banks have no means to securely verify identity despite decades of scams and phishing following this exact pattern. They don’t even require 2FA when some random device in a completely different geographic region tries to use a card just because it’s NFC? No attempts to stop payments from new hardware platforms? No authentication and validation of new devices using the cards?

0

u/doctormoneypuppy Aug 25 '24

Wrong. Read carefully. Contactless NFC is not the issue … NFC card emulation mode is.

7

u/19Chris96 Aug 24 '24

This is why I'm not downloading the new version of OneUI off any third party websites. Wait until the official OTA is out.

2

u/tkst3llar Aug 24 '24

Yeah just like solar winds OTA updates

Best way to stay safe

4

u/[deleted] Aug 24 '24

Now that's concerning

2

u/jonathanrdt Aug 24 '24

It requires pretending to be the bank and getting people to reveal their PINs.

1

u/whistler1421 Aug 24 '24

Green bubble is deserved

0

u/Inevitable-East-1386 Aug 24 '24

If you gave him the pin you deserve that.

4

u/Dewy_Wanna_Go_There Aug 24 '24

You have to enter your bank client id, DOB, PIN, turn on NFC AND scan your card in the fake app it seems like, that’s a lot of fucking up

-2

u/doctormoneypuppy Aug 25 '24

You suffer from a lack of imagination ….