[LINK] RFI: PayWave/PayPass Contactless Chip Cards

Scott Howard scott at doc.net.au
Wed Apr 11 16:37:55 AEST 2012


On Tue, Apr 10, 2012 at 11:20 PM, Stephen Wilson <swilson at lockstep.com.au>wrote:

> The ability of the chip to disguise personal data is important and
> under-utilised.  The ability should be exploited to secure online
> transactions as well as POS & ATM transactions


Given that we're talking about contactless credit cards, how is this
ability NOT being "exploited" at the moment?

None of the major credit cards include any personal information within the
RFID component.  None of them include the owners name/address/any other
personal detail.  Very few (probably none now days) include the credit card
number, the CVV2, or any other information included on the physical card
(with the possible exception of the expiry).

There's definitely room for improvement with other contactless cards (eg,
E-Passports), but credit cards is one area where it's hard to argue they
haven't got it as close to "right" as the technology allows.

  Scott.



More information about the Link mailing list