Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Perhaps passive credit cards should use a barcode instead of a magnetic stripe, so any endpoint with a camera can swipe them.


It would be better to move to something more secure, not less.

Barcode you could just photocopy/reproduce trivially.


Magstripes are only incrementally harder to reproduce: the equipment is more expensive, but still available to any attacker. That the magstripe is visually opaque contributes to a false sense of security -- people thinking the magstripe info is somehow locked against unauthorized use, even though it's still essentially plaintext.

The magstripe is thus a bit like the 'lock icon gif' on an insecure login page -- creating enough of an illusion of security to assist commerce, but ultimately misleading. A visual barcode would be more honest: letting anyone see/possess your card long enough to scan/photocopy it is the exact same level of risk as letting them swipe it through a magstrip reader.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: