RFID credit card hacked

Hacker Pablos Holman shows off the results of his RFID scan

Following on from last week’s story about how the MIFARE Classic’s RFID chip, as used in London Transport’s Oyster card, had been compromised, BoingBoing has gone a step further. It gave a video demonstration of a hacker demonstrating how easy it is to extract details from a RFID-equipped credit card.

In the video, the hacker Pablos Holman boasts that he is able to “decrypt the data” using an “eight dollar reader from eBay”. One quick swipe of the reporter’s American Express card later and he appears to have done just that, with the cardholder’s name and expiry date both visible.

“You’ll get that from most cards,” explains Holman, before adding “now we can go online and start shopping”.

Holman then offers his explanation as to why the use of RFID technology is spreading despite its obvious security flaws. “The credit card industry understands that creating a secure system isn’t really the priority; creating a system that feels secure to the user is. In reality it’s easier for me to get numbers now than it was before.”

Security risk

Mr Holmon then shows how RFID card carriers could protect themselves from readers with the aid of a metal wallet, before offering his views on how much of a security risk RFID-equipped credit cards really pose:

“I don’t expect this to be a major threat for a while. People are stealing credit card numbers from websites and that’s still pretty easy,” he says, before adding, somewhat more ominously “with a bigger antenna hooked up to this I can go into Starbucks and get the name of everyone in there”.

Latest in Cyber Security
Dark Web monitoring
How users benefit from Dark Web monitoring
The X logo next to a silhouette of Elon Musk
Who was really behind the massive X cyberattack? Here’s what experts say about Elon Musk’s claims
A person holding a phone looking at a scam text with warning signs around
A massive SMS toll fee scam is sweeping the US – here’s how to stay safe, according to the FBI
View on National Assembly building in Paris, France, with French and European flags flying.
France rejects controversial encryption backdoor provision
ignal messaging application President Meredith Whittaker poses for a photograph before an interview at the Europe's largest tech conference, the Web Summit, in Lisbon on November 4, 2022.
"We will not walk back" – Signal would rather leave the UK and Sweden than remove encryption protections
Man uses a laptop in a hotel room
4 ways to avoid misinformation on social media and retain control of your newsfeed
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring