(1) Don't put your phone in the same pocket as your card, (2) Get either a metal or protected wallet for NFC-enabled cards, (3) Review card usage and don't worry about it. You aren't responsible for card fraud with credit cards. The chances of this being used against you are incredibly slim. It's also less useful as an avenue to commit fraud since payment with NFC is usually limited to under $25 by merchant agreements. Besides, duplicated cards are old hat, what with programmable chips and magnetic strips already. What's neat here is the proof-of-concept demo involving phones without the need for specialized SIM cards or approved phone handsets. Not 100% sure myself, but maybe it only works because PayPass allows for stickers on your phone case to emulate a credit card?
Oh and if you go to pay for something on a website and enter your 3-digit code plus the card number, well, spyware could have your card already. So NFC as an attack vector is slower and less useful. Watch out for those custom keyboards ;-)
When I was cracking mifare cards (used as authentication in many buildings) I found that it was significantly quicker to crack several cards at the same time than to crack them individually - this is because the attack that I was using required demagnetising the card hundreds of times which takes a lot longer than any communication with the card.
I could crack a single mifare card in 5 seconds, I could crack 5 in 6 seconds (and for most applications cracking one card is all you need - all cards use the same encryption key).
http://www.amazon.com/HideCell-Cell-Protection-Bag-Standard/...
This is the only thing that can really stop wireless snooping. Even pervasive location tracking.
What you really should be getting is an RF-shielded wallet for NFC-enabled cards. Your phone doesn't need anything shielding it, and most phones have sane permission models around how you permit apps to use your GPS.
And when you do, go with something that shields everything in the wallet. (I bought ID Stronghold wallets for myself and the family.)
Here in London it should be possible to market these wallets with an extra twist. Oyster cards are used everywhere, and for the last 4-5 months I've noticed a constant stream of announcements - "Please keep your oyster and contactless payment cards separate to prevent card clash." An enterprising individual with import and retail experience could tap into this market by selling wallets with one outside - unshielded - pocket for the Oyster card, and everything else inside fully shielded.
People in general don't care about privacy or security, but they do care about convenience. So, by way of introducing a convenient way to prevent card clash, they would also get automatic protection against these drive-by NFC payment card attacks.
I just got back to the US from a month in Europe. The entire time, I was carrying passport, credit cards, transit-system cards, hotel key cards, etc. in a fully shielded wallet. It wasn't a problem at all to have to pull out the transit card when necessary in order to get on/off a tram or bus, or enter/leave a station (hotel key card has to come out anyway, since often you have to put it in the slot by the door to turn on the room's lights). And the peace of mind is worth it.
(my only actual complaint about the wallet is that I bought it because it had an internal zippered pouch for coins, something that's much more useful for EUR than for USD, but the zipper broke after less than a week)
I haven't tested it, but it's better than nothing, right? And much cheaper. I've a few cards, so I bought two (different colors). For those also in Toronto, you can pick them up at the Umbra showroom off Queen and John. For everyone else, there's Amazon, local stores...
That said, when I looked at this project, I saw it as something I wanted -- not for fraud, for personal convenience. I'm sick of carrying so many cards. I was like, crap, I only have Visa in my wallet, I wonder how hard it'd be to add PayWave support? Right now my hopes lie in rumoured iPhone 6 support of NFC which might in turn encourage global adoption of phones for payment ... and perhaps with one-time credit card numbers, right? One can dream...
I do understand though -- they look nicer too.
It doesn't matter what they think their target is. They're making the devices not cell phones anymore. Maybe you want to be unreachable, but I highly doubt you want everyone you call/text to also be unreachable.
It is 100% the point of a smartphone that its RF antennae work. If you're thinking of putting your smartphone in a Faraday cage whenever you're out in public, don't own one. Stick with the landline. It's cheaper anyway.
I guess you could argue that you still want to make outgoing calls and texts, but if people in general used these devices, there would be no point in making outgoing calls or texts because people would never receive them (except at home, where you have landlines and email anyway.)
Having said that - how well would just lining your wallet with tinfoil work? (inb4 tinfoil hat jokes)
- [Dump card into Downloads](https://github.com/MatusKysel/EMVemulator/blob/master/src/co...)
- [Read card from Downloads](https://github.com/MatusKysel/EMVemulator/blob/master/src/co...)
- [Respond to NFC requests](https://github.com/MatusKysel/EMVemulator/blob/master/src/co...)
Edit: Reading that is...
But this whole attack isn't anything new — this was pretty widely reported back in 2012 in the UK, e.g. http://www.channel4.com/news/millions-of-barclays-card-users...
I wrote essentially the same proof of concept app two years ago after seeing that report pretty much just by reading the specs. From reading the paper mentioned on GitHub, the only real difference to what I wrote is that I didn't check for the CVC3 information (which I think is generally not included, or doesn't correspond to the actual security code on the back of the card).
But in any case, just the card number and expiry number are enough — as mentioned in the Channel 4 report — to make purchases from a lot of places.
Or should I rush out tomorrow and get one? (Australia, so yep, all of them are paywave, whether you want them or not).
The app read the card correctly and gave the card number and expiry. When I tried to use it in store the eftpos terminal returned roughly: Err 226 contactless card not allowed. The terminal fell back to swipe/insert mode and the merchant told me 'contactless not allowed'. Inserted the (same) card and paid successfully.
I was disappointed because for me, being able to carry just mmy phone for day to day would be awesome, and NAB has no phone solution yet.