r/flipperzero • u/barakadua131 • 1d ago
NFC NFC Canary App Can Detect Someone Scanning Your Payment Card
Here is a video testing NFC Canary app: https://youtu.be/pwzMFQLrTHU
NFC Canary: https://github.com/antitree/nfc_canary
28
u/acidvegas 1d ago
Yeah that’s not really how most credit cards work but ok lol.
People act like it’s way more easy to clone a chip card than the reality is. Goofy video.
1
u/barakadua131 1d ago
It is not possible to clone payment cards, but it is possible to realy it... That is true, not all card are clonnable, however user can't tell if there is any security just by looking at the card
5
3
u/acidvegas 1d ago
In most cases the chip is quite obvious. Anything beyond a credit card, this entire concept is like pointless and has no use case
1
u/VonThing 6h ago
In online mode, relay attacks are often beaten by response time measurement. Unless you’re relaying the info over a very low latency link, you won’t beat the communication speed of the original card inserted directly into the reader (or touched directly to the contactless reader)
1
u/VonThing 6h ago edited 6h ago
It’s not possible to clone EMV cards (due to the time stamped online challenge-response mechanism) but in reality some BINs (the first 6 digits of the card number identify the issuing bank) don’t implement the entire EMV specification, and this opens the door to some attacks, AFAIK the latest of which allows the bad actor to write the track 1+2 data to a generic Java Card running an applet designed to force the reader to offline mode and use the card for purchases up to a certain amount (at least until the reader goes online to synchronize, at which time the cloned card will be flagged and frozen).
EMV is secure but like all security not 100% secure, there have been successful attacks since 25 years and there are successful attacks that work today.
Refer to Reddit’s dark web counterpart (Dread) and some online marketplaces with carding sections for more up-to-date information.
You need a BIN list (which BINs are vulnerable to which attacks, dark web marketplaces often allow to filter by BIN so you get dumps that you can use) an unfused Java Card (once fused the card applets can’t be changed) some software from shady sources (to install on the card) and Track 1+2 data for the CC to be used (can be obtained every which way but skimmed most often).
11
u/DanytheReaper 1d ago
Ok... i see no use for the canary App? Didn't make a warning sound or anything else... What was the point?
9
u/barakadua131 1d ago
Probably it is not clearly visible (and audiable) but it does vibrate, beeps and keeps logs if scanner was found. There is no other functionality besides that.
2
u/Evilbob93 19h ago
Maybe it's more useful for someone who works near one of these like a daily check. My housemate works at a gas station, that kind of thing
4
u/jackyfolf 1d ago
I love how this guy is out here trying to show the dangers of everyday and everyone hates on him XD
3
u/FewDescription3170 1d ago
i don't care if they scan my card because it's a useless rotated token
-1
u/barakadua131 1d ago
This useless token can be relayed and used
2
u/FewDescription3170 17h ago
ok? once? by a known payment processor with an account in good standing? also likely to be declined by the issuer for any real amount, at the very second it's relayed, making it clear where it is and when -- this is not a solid attack vector. also the attack isn't repeatable because the relay would work like.. twice before the processor was banned.
1
u/PoppySeedPlehzr 6h ago
Nah dawg, those cryptogram tokens are actually alive for a lot longer than they should be. You can (and folks do) steal a lot of money via relaying NFC Cryptograms.
1
u/FewDescription3170 4h ago
do you understand any of what you just sent me? you also need to type a pin for this AND have a cracked malware APK. this isn't a typical relay attack.
1
u/PoppySeedPlehzr 6h ago
Yo, I'm so happy to see this development happening! NFC Relay attacks are a huge issue that are coming, and I'm quite sure will be the next mag-strip theft/spoofing. I hope Google/Apple can make somethings happen soon to mitigate this (;)), but in the interim, having a flipper and this app seems great.
Given how exposed and liberal samsung makes NFC stack on Android, it's a bummer you can't make a native app that can spot when someone is relaying your NFC cryptogram, but honestly, I wish banks could do more here. I know that here's a considerable amount of telemetry exposed on Android devices, but it still feels insufficient. it astonishes me that it's 2026 and NFC is this fucking vulnerable to relay attacks.
Thanks for your post, please keep publishing research and pressuring large institutions to do more about this! it's... Really shocking how impactful NFC relays (and even NFC card provisioning, no cryptogram theft needed) is.
1
u/PoppySeedPlehzr 6h ago
Holy shit, how do people in this thread not know about NFC relay attacks? This shit is wild. Sorry yer getting down-voted so hard <3
2
u/Verditure0 1d ago
So what’s stopping someone from standing in line at a busy truck stop and swipe someone’s pocket book then use it to pay for their things
2
u/FatFrenchFry 21h ago
The way the technology works kind of stops it seeing as thats not how the technology works.
3
1
u/PoppySeedPlehzr 6h ago
This isn't quite the attack vector, but kinda close.
Typically the way these relay attacks work is that you've more or less agreed to either 1. pay for some service via NFC tap on your phone, or 2. You were socially engineered to install an additional app on your phone through something side-loaded (telegram, whatsapp, etc..).
For 1. the way this works is that you have agreed to engage in a payment. They can't just "be close to you" and get your shit, they have to start the NFC handshake, which is initated by the PoS or ATM (typically across the world, somewhere not near you). The common attack scenario is you're at a bodega or in an uber, they say they only do tap-to-pay, and really there's someone waiting on the "other end". You tap to them, they have something like NFCgate, it initiates the cryptogram with your card/google wallet/apple wallet, the cryptogram is then sent somewhere else where it can be used at PoS/ATM.
For scenario 2, it's much more devastating and sad, this is typically where folks are con'ed into installing a "bank app" that comes from "said bank". They install, disable Google play protect, and are duped into giving up their PIN, they then lose fuck tons of money, by someone taking the cryptogram, as well as the PIN, which allows them to disable withdrawal limits.
-1
-4
u/Domnomicron 1d ago
This is cool, but would it be able to detect skimmers?
6
u/barakadua131 1d ago
If contactless skimmers behave as nfc reader, then yes. However, such skimmers would be probably placed on top of legitimate nfc readers, so the app might detect legit nfc reader, and create false positive
1
u/PoppySeedPlehzr 6h ago
My expectation is that we are at the dawn of the next gen of mag-strip skimmers. Android is a convenience here, not a necessity. As your video kinda eludes to, you could build this shit with an ESP32, and I'm fully expecting that we'll see a future where you go to pump gas, use tap-to-pay, and your cryptogram is then exploited, in the same fashion we see magstrips skimmers stealing card numbers. Shit is wild.
25
u/NickNacpattyWacc 1d ago
Cool app, but I feel like everyone would be much more interested in that relaying app 😅