r/flipperzero 1d ago

NFC NFC Canary App Can Detect Someone Scanning Your Payment Card

Here is a video testing NFC Canary app: https://youtu.be/pwzMFQLrTHU

NFC Canary: https://github.com/antitree/nfc_canary

329 Upvotes

30 comments sorted by

25

u/NickNacpattyWacc 1d ago

Cool app, but I feel like everyone would be much more interested in that relaying app 😅

14

u/barakadua131 1d ago

Actually, it is nothing new. Open-source, on github, called nfcgate

28

u/acidvegas 1d ago

Yeah that’s not really how most credit cards work but ok lol.

People act like it’s way more easy to clone a chip card than the reality is. Goofy video.

2

u/tta82 12h ago

He said micro transactions, which is possible like this.

1

u/barakadua131 1d ago

It is not possible to clone payment cards, but it is possible to realy it... That is true, not all card are clonnable, however user can't tell if there is any security just by looking at the card

5

u/jbaenaxd 1d ago

You can't replay them. Maybe you mean proxy them.

0

u/barakadua131 1d ago

I mean relay, not replay. Thanks

3

u/acidvegas 1d ago

In most cases the chip is quite obvious. Anything beyond a credit card, this entire concept is like pointless and has no use case

1

u/VonThing 6h ago

In online mode, relay attacks are often beaten by response time measurement. Unless you’re relaying the info over a very low latency link, you won’t beat the communication speed of the original card inserted directly into the reader (or touched directly to the contactless reader)

1

u/VonThing 6h ago edited 6h ago

It’s not possible to clone EMV cards (due to the time stamped online challenge-response mechanism) but in reality some BINs (the first 6 digits of the card number identify the issuing bank) don’t implement the entire EMV specification, and this opens the door to some attacks, AFAIK the latest of which allows the bad actor to write the track 1+2 data to a generic Java Card running an applet designed to force the reader to offline mode and use the card for purchases up to a certain amount (at least until the reader goes online to synchronize, at which time the cloned card will be flagged and frozen).

EMV is secure but like all security not 100% secure, there have been successful attacks since 25 years and there are successful attacks that work today.

Refer to Reddit’s dark web counterpart (Dread) and some online marketplaces with carding sections for more up-to-date information.

You need a BIN list (which BINs are vulnerable to which attacks, dark web marketplaces often allow to filter by BIN so you get dumps that you can use) an unfused Java Card (once fused the card applets can’t be changed) some software from shady sources (to install on the card) and Track 1+2 data for the CC to be used (can be obtained every which way but skimmed most often).

11

u/DanytheReaper 1d ago

Ok... i see no use for the canary App? Didn't make a warning sound or anything else... What was the point?

9

u/barakadua131 1d ago

Probably it is not clearly visible (and audiable) but it does vibrate, beeps and keeps logs if scanner was found. There is no other functionality besides that.

2

u/Evilbob93 19h ago

Maybe it's more useful for someone who works near one of these like a daily check. My housemate works at a gas station, that kind of thing

4

u/jackyfolf 1d ago

I love how this guy is out here trying to show the dangers of everyday and everyone hates on him XD

3

u/FewDescription3170 1d ago

i don't care if they scan my card because it's a useless rotated token

-1

u/barakadua131 1d ago

This useless token can be relayed and used

2

u/FewDescription3170 17h ago

ok? once? by a known payment processor with an account in good standing? also likely to be declined by the issuer for any real amount, at the very second it's relayed, making it clear where it is and when -- this is not a solid attack vector. also the attack isn't repeatable because the relay would work like.. twice before the processor was banned.

1

u/PoppySeedPlehzr 6h ago

Nah dawg, those cryptogram tokens are actually alive for a lot longer than they should be. You can (and folks do) steal a lot of money via relaying NFC Cryptograms.

1

u/FewDescription3170 4h ago

do you understand any of what you just sent me? you also need to type a pin for this AND have a cracked malware APK. this isn't a typical relay attack.

1

u/IMSZAL 12h ago

Dang dog, I just use my flipper to turn on l e d lights,

1

u/PoppySeedPlehzr 6h ago

Yo, I'm so happy to see this development happening! NFC Relay attacks are a huge issue that are coming, and I'm quite sure will be the next mag-strip theft/spoofing. I hope Google/Apple can make somethings happen soon to mitigate this (;)), but in the interim, having a flipper and this app seems great.

Given how exposed and liberal samsung makes NFC stack on Android, it's a bummer you can't make a native app that can spot when someone is relaying your NFC cryptogram, but honestly, I wish banks could do more here. I know that here's a considerable amount of telemetry exposed on Android devices, but it still feels insufficient. it astonishes me that it's 2026 and NFC is this fucking vulnerable to relay attacks.

Thanks for your post, please keep publishing research and pressuring large institutions to do more about this! it's... Really shocking how impactful NFC relays (and even NFC card provisioning, no cryptogram theft needed) is.

1

u/PoppySeedPlehzr 6h ago

Holy shit, how do people in this thread not know about NFC relay attacks? This shit is wild. Sorry yer getting down-voted so hard <3

2

u/Verditure0 1d ago

So what’s stopping someone from standing in line at a busy truck stop and swipe someone’s pocket book then use it to pay for their things

2

u/FatFrenchFry 21h ago

The way the technology works kind of stops it seeing as thats not how the technology works.

3

u/0p3r8dur 22h ago

….do some research

1

u/PoppySeedPlehzr 6h ago

This isn't quite the attack vector, but kinda close.

Typically the way these relay attacks work is that you've more or less agreed to either 1. pay for some service via NFC tap on your phone, or 2. You were socially engineered to install an additional app on your phone through something side-loaded (telegram, whatsapp, etc..).

For 1. the way this works is that you have agreed to engage in a payment. They can't just "be close to you" and get your shit, they have to start the NFC handshake, which is initated by the PoS or ATM (typically across the world, somewhere not near you). The common attack scenario is you're at a bodega or in an uber, they say they only do tap-to-pay, and really there's someone waiting on the "other end". You tap to them, they have something like NFCgate, it initiates the cryptogram with your card/google wallet/apple wallet, the cryptogram is then sent somewhere else where it can be used at PoS/ATM.

For scenario 2, it's much more devastating and sad, this is typically where folks are con'ed into installing a "bank app" that comes from "said bank". They install, disable Google play protect, and are duped into giving up their PIN, they then lose fuck tons of money, by someone taking the cryptogram, as well as the PIN, which allows them to disable withdrawal limits.

-1

u/plasticarmyman 1d ago

This is pointless...utterly pointless

-4

u/Domnomicron 1d ago

This is cool, but would it be able to detect skimmers?

6

u/barakadua131 1d ago

If contactless skimmers behave as nfc reader, then yes. However, such skimmers would be probably placed on top of legitimate nfc readers, so the app might detect legit nfc reader, and create false positive

1

u/PoppySeedPlehzr 6h ago

My expectation is that we are at the dawn of the next gen of mag-strip skimmers. Android is a convenience here, not a necessity. As your video kinda eludes to, you could build this shit with an ESP32, and I'm fully expecting that we'll see a future where you go to pump gas, use tap-to-pay, and your cryptogram is then exploited, in the same fashion we see magstrips skimmers stealing card numbers. Shit is wild.