Def Con hackers reach for digital wallets

Jul 29, 2012 by Glenn Chapman

Hackers at a notorious Def Con gathering that ends here Sunday have come up with ways to reach into digital wallets.

Smartphones at the heart of modern lifestyles are becoming top targets for cyber attacks, according to security specialists and hackers who flocked to Las Vegas this week for back-to-back Def Con and conferences.

"We are entering a post-PC (personal computer) exploitation world," said researcher Stephen Ridley of Xipiter, where his team uncovered that the same types of attacks that plague can be turned on .

"I think phones are going to be the only thing people are interested in popping in the next five years or so," he concluded, saying hacker attention is shifting to the always-on, personal data rich devices in people's pockets.

Along with contact information for friends and logs of activities such as , smartphones typically have location-sensing capabilities that track where they have been.

Using smartphones as "wallets" will be common within a decade, largely replacing cash and credit cards, according to a Pew Research survey released in April.

Sixty-five percent of "technology stakeholders and critics" who responded to an opt-in poll by Pew Research and Elon University Imagining the Internet Center agreed that would be a mainstream way to pay by the year 2020.

"What is in your wallet now? Identification, payment, and personal items," chief economist Hal Varian was quoted as saying in a survey response. "All this will easily fit in your mobile device and will inevitably do so."

Google last year launched a "Wallet" service that lets sophisticated Android-powered mobile phones be used to "tap and pay" for purchases at shops.

Blackwing Intelligence security researcher Eddie Lee showed Def Con attendees how to how to use an Android-powered smartphone to pick up the data from a credit card and then used the swiped information for purchases.

"You can start spending on someone's credit card; basically you can use it the way you use Google Wallet," Lee said while demonstrating his technique for a packed room of hackers.

"We've know for a long time you can skim RFID credit cards," he said. "This lets you abuse that information and spend on those cards. Maybe this will give the credit card companies an incentive to fix the things in my wallet."

He theorized the tactic could work on other cards, such as those for metro system fares or building access.

Accuvant computer security firm consultant and former National Security Agency analyst Charlie Miller showed Def Con attendees a way to slip into smartphones by getting a sensor close enough to read signals from NFC chips.

In some cases, it is even possible to take over control of a phone via NFC -- stealing photos and contact lists, and sending text messages or make phone calls, according to Miller's presentation.

"You're supposed to be paying for stuff and scanning movie posters with your smartphone, but be aware that this is another way that bad guys can attack your phone," Miller told AFP.

He showed that if he could briefly get an antennae device easily concealed in a sticker near enough to a phone at an opportune moment, it can open a virtual door that a hacker could slip in through.

He contended it would be simple to discreetly affix an innocuous-looking sticker near a digital wallet touchpad at a store checkout counter and then linger nearby and hack phones of buyers.

"It will pair with my machine and I can control the phone," Miller said.

"A bad guy can use that moment of talking to your phone to steal data," he continued. "NFC is cool, convenient and fun; I'm just trying to say let's pay attention to the security implications."

NFC or RFID technology used to share data with nearby sensors is used in smartphones, credit cards, and even passports.

Explore further: As online video thrives, TV companies push back

add to favorites email to friend print save as pdf

Related Stories

Smartphones wallets going mainstream: survey

Apr 17, 2012

Using smartphones or tablets as digital "wallets" will be common within a decade, largely replacing cash and credit cards, according to a Pew Research survey released on Tuesday.

PayPal letting Google phones swap cash

Jul 13, 2011

Online financial transactions giant PayPal on Wednesday showed off a mini-program that lets people exchange money by touching together a pair of Google smartphones.

Google turning smartphones into wallets: source

May 25, 2011

Google on Thursday will launch a mobile payment platform that lets people use smartphones to pay at shops as easily as they use a credit card, according to a source familiar with the matter.

PayPal fattens digital wallet

Mar 13, 2012

PayPal on Tuesday pulled out a revamped digital wallet service amid rumors it is poised to introduce a plug-in gizmo that will let small businesses accept credit card payments using smartphones.

Recommended for you

As online video thrives, TV companies push back

May 14, 2013

The evolving TV and video industry faces uncertainty as it embraces new technology like wireless streaming, as traditional US broadcasters urged lawmakers Tuesday to help preserve their marketplace primacy.

Improving communication during disasters

May 13, 2013

A small armband which can be attached to the injured. An information board containing a complete visual record of events. This is technology helping to improve communications during major national disasters.

Samsung announces 5G data breakthrough

May 13, 2013

Samsung Electronics said Monday it had successfully tested super-fast fifth-generation (5G) wireless technology that would eventually allow users to download an entire movie in one second.

User comments : 1

Adjust slider to filter visible comments by rank

Display comments: newest first

Osiris1
not rated yet Jul 31, 2012
I did not use the 'wallet' feature in my computer, and I sure as H E double toothpicks am not gonna use no steeeenkin 'digital wallet' in my smart fone. And I will never willingly use one of those RFID credit cards. I will hope my companies never try to foist one on me.

More news stories

Morocco to harness the wind in energy hunt

Morocco is ploughing ahead with a programme to boost wind energy production, particularly in the southern Tarfaya region, where Africa's largest wind farm is set to open in 2014.