Message from @red

Discord ID: 438010723713548299


2018-04-23 16:12:23 UTC  

the integrated one of the thinkpad works fine tbh, just the fact that they use completely unmaintained software in a banking environment is a little weird

2018-04-23 16:12:59 UTC  

yeah, but it's kind of like a form of 2factor

2018-04-23 16:13:22 UTC  

But I noticed the heavy Win XP usage still in 2018

2018-04-23 16:13:33 UTC  

I never use that function though

2018-04-23 16:13:45 UTC  

I just set it up with mine to verify through my phone

2018-04-23 16:14:06 UTC  

that works? Didn't know that, I'll tell her, the auth is a pain rn

2018-04-23 16:14:26 UTC  

might depend on the bank, but I can do ATM transfers online just with a phone verification

2018-04-23 16:14:34 UTC  

Are you at citibank?

2018-04-23 16:14:47 UTC  

not really one to discuss that sort of thing

2018-04-23 16:15:02 UTC  

i'd be surprised if they didn't have that function, though

2018-04-23 16:15:07 UTC  

it's not like I'll raid your account but you don't have to tell

2018-04-23 16:16:44 UTC  

From a security point of view I like the MRT cards

2018-04-23 16:17:00 UTC  

Tried to dump the NFC onto my phone but they are properly encrypted

2018-04-23 16:17:09 UTC  

it used to be shit

2018-04-23 16:17:23 UTC  

some german guy demonstrated it years ago with the gen 1 cards

2018-04-23 16:17:23 UTC  

is this why they made this "version 2" thing lately?

2018-04-23 16:17:37 UTC  

v2 and later have been out for years

2018-04-23 16:17:43 UTC  

I only have v2

2018-04-23 16:17:50 UTC  

if it doesn't have a chip it's v1

2018-04-23 16:18:10 UTC  

said german was able to decrypt the contents of the card and add as much money as he wanted

2018-04-23 16:18:14 UTC  

since it was still stored on the card back then

2018-04-23 16:18:20 UTC  

and the encryption was piss-poor

2018-04-23 16:18:26 UTC  

Just checked

2018-04-23 16:18:32 UTC  

I have an EasyCard V2 with a chip

2018-04-23 16:18:53 UTC  

now it's just on a server so even if you have a v1 you can't modify it to have more money

2018-04-23 16:19:23 UTC  

you might be able to impersonate another v1 card though, i dunno

2018-04-23 16:19:55 UTC  

So yuou're saying all those busses in the middle of nowhere, all taxis etc have an active internet connection that checks the balance?

2018-04-23 16:20:36 UTC  

I've thought about that and I can only assume it's yes or it's hybrid

2018-04-23 16:21:30 UTC  

there was a story a few years back about how someone was arrested for falsifying the balance on cards

2018-04-23 16:21:46 UTC  

might have been done with v1 cards

2018-04-23 16:21:46 UTC  

```
At the 27th annual German Chaos Communication Congress hacker conference ("27C3") in 2010, German free software programmer Harald Welte showed that it is possible to artificially change the amount of money stored on a first-generation EasyCard —based on the MIFARE Classic chip— using nothing more than a USB RFID reader and a laptop computer running open source software. Welte denounced the system for its poor choice of cipher and lack of user authentication. He was able to map out and manipulate the card's internal format in 2 days on a trip in Taiwan.[22]

However, hacking the EasyCard remains illegal, and in September 2011 a 24-year-old engineer was arrested on suspicion of fraudulently using a hacked EasyCard.[23]
```

2018-04-23 16:21:49 UTC  

yes

2018-04-23 16:22:56 UTC  

it might be that the mobile readers trust a balance on the card and then it's all settled afterwards

2018-04-23 16:23:23 UTC  

the card readers on buses fail occasionally so that might be a connectivity issue

2018-04-23 16:23:41 UTC  

either to the servers or just a card reading issue

2018-04-23 16:24:07 UTC  

or the readers actually all have GSM

2018-04-23 16:24:15 UTC  

Wouldn't surprise me much

2018-04-23 16:24:17 UTC  

i dunno, cell connectivity in taiwan is everywhere

2018-04-23 16:24:20 UTC  

so yeah

2018-04-23 16:24:22 UTC  

exactly

2018-04-23 16:24:29 UTC  

it wouldn't really be an issue