Viewing a single comment thread. View all comments

geminimad4 t1_j1gbomc wrote

Whenever possible I use the tap to pay option. I don’t trust card reader slots.

57

TheGeekVault OP t1_j1gc1hx wrote

This might be a silly question but if you use the Tap to pay option can the skimmer still get your info? I was under the impression the skimming device took over the whole unit not just the "insert card" option.

12

pm_me_your_dota_mmr t1_j1gd7nn wrote

I think tap to pay (and chips) work similar to a 2fa app on your phone, they generate a secret code every time you auth a payment so that the info can’t be stolen and reused through that method, though I might be wrong. When you swipe your card, the full card number is included which is why it can be reused

41

drtywater t1_j1ggemo wrote

Correct. Also added benefit of a public private key exchange to counter a man in middle listening in. Basically a lot more layers to make it a pain in the ass for would be attackers.

16

geminimad4 t1_j1gd7yk wrote

It’s my understanding that the skimmer picks up the info that’s inserted but not tapped. But I could be wrong and we are all fucked.

8

RogueInteger t1_j1hsgmv wrote

Skimmers, as far as I have seen, require a magnetic strip.

To skim chips would be way more complicated and less likely to be done.

6

limitedteeth t1_j1jn68q wrote

They can do it with RFID now. Happened to me a couple months ago in New York, I didn't use my card at all for anything and it still got skimmed.

1

RogueInteger t1_j1jtq61 wrote

I've heard of people running charges by tapping pockets but they got your full credit card info?

2

limitedteeth t1_j1ju85f wrote

Debit card, I was staying with my fiance and one of their roommates snagged the info. I never left my wallet unattended even to go to the bathroom because the people living there are pretty disreputable so it had to have been contactless. Started getting small charges from bodegas and the landlord found receipts in the dudes room with my info on them for stuff I didn't buy. Did a little research and apparently it's possible to scan from 10 ft away then clone the info onto a blank card so you can physically use it.

2

[deleted] t1_j1gxtla wrote

[deleted]

−1

geminimad4 t1_j1gzhfj wrote

PIN for debit card transaction but not if you specify that it’s a credit card transaction.

4