107
top 12 comments
sorted by: hot top controversial new old
[-] conciselyverbose@sh.itjust.works 32 points 3 weeks ago

I mean, this is "malware" in the obvious sense.

But it's not compromising anything Android is doing. (Though it's worth noting that things like this are why Apple restricts NFC).

It's just phishing at the end of the day. Something you should make users aware of, but not a security flaw of the device.

[-] randoot@lemmy.world 9 points 3 weeks ago

So they need to keep the victim's card next to one phone, and then they can use another internet connected phone elsewhere to make a purchase. Doesn't sound that scary to me. If they already have my card then does it matter how far away they can make a purchase?

[-] HubertManne@moist.catsweat.com 5 points 3 weeks ago

This could be bad in the sense that anyone working a drive through could spend a day doing it.

[-] Ghoelian@lemmy.dbzer0.com 3 points 3 weeks ago

How? You don't actually give the card to the employees, do you?

[-] sawdustprophet@midwest.social 7 points 3 weeks ago

You don't actually give the card to the employees, do you?

Typically when I go through a drive thru, I hand my card to someone who then leans back inside to swipe/tap/whatever it, then they hand it back. So yes, commonly I do give my card to an employee for at least a few seconds.

During 2020-2022 more of them were in the habit of placing the PIN pad at the window so it could be reached by customers from their cars, but it wasn't designed to be used that way and I'm sure it caused other issues.

[-] Ghoelian@lemmy.dbzer0.com 7 points 3 weeks ago

Over here they just put the pin terminal on a stick and shove it in to your car, it was already that way even before covid. Don't think I've ever just handed my card to someone.

[-] JasonDJ@lemmy.zip 3 points 3 weeks ago* (last edited 3 weeks ago)

Y'all also use PINs. Americans freak out if they have to enter a PIN.

Here it's only used for debit transactions (that is, taken directly out of a checking account). PIN for credit transactions is incredibly rare here.

This is probably because the merchants are responsible for fraudulent credit purchases. Credit companies kinda have them over a barrel in that regard...they have no incentive to enforce PINs, and users just want convenience.

Meanwhile Sally the Walmart clerk gets written up because some knucklehead in her lane swiped a cloned card. She has no power here either...card readers rarely ask for signature anymore (not like they are trained signature analysts, a pseudoscience in itself) and I can't remember the last time I was asked for ID for a credit purchase (aside from booze, smokes, or Sudafed, but that's a different reason)

[-] HubertManne@moist.catsweat.com 2 points 3 weeks ago

yeah not sure if its a us thing or a midwest thing but you hand your card to the person who swipes/taps it.

[-] QuizzaciousOtter@lemm.ee 1 points 3 weeks ago

It's funny because where I live there were even warnings to never give your card to the cashier back when they weren't so popular. It was precisely because of some rare cases of cashiers managing to clone or charge the card during that moment. I, and most people I know, wouldn't just hand in their card if asked. It just doesn't happen here.

[-] HK65@sopuli.xyz 1 points 3 weeks ago

It is a US thing, and it's a thing European tourists are weirded out over.

[-] HubertManne@moist.catsweat.com 2 points 3 weeks ago

would love if it was not. dont see hwy it cant just be accesible at the window.

[-] jayandp@sh.itjust.works 1 points 3 weeks ago

In the US at least it's still fairly common for the card to be taken by the employee of the Drive-Thru/Restaurant to be run through their POS.

this post was submitted on 26 Aug 2024
107 points (93.5% liked)

Technology

58135 readers
6252 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS