# illicit scanning of CC's with RFID's: real deal?

**URL:** https://boards.straightdope.com/t/illicit-scanning-of-ccs-with-rfids-real-deal/563195
**Category:** Factual Questions
**Created:** [December 6, 2010, 8:31pm UTC](https://boards.straightdope.com/t/illicit-scanning-of-ccs-with-rfids-real-deal/563195 "2010-12-06T20:31:18Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![Machine\_Elf](https://avatars.discourse-cdn.com/v4/letter/m/82dd89/32.png) [@Machine\_Elf](https://boards.straightdope.com/u/Machine_Elf)
#### Post date: [December 6, 2010, 8:31pm UTC](https://boards.straightdope.com/t/illicit-scanning-of-ccs-with-rfids-real-deal/563195/1 "2010-12-06T20:31:18Z")

</div>

news video [here.](http://www.wreg.com/videobeta/?watchId=8ba6f8fc-90a2-4711-90ea-1884ec348310)

Summary: new credit/debit cards with RFID technology that enables non-contact scanning for puchases apparently enables a new kind of fraud. Perp approaches victim in a crowd/line, places scanner near victim’s wallet/purse, and is able to read the victim’s credit card info without the card ever leaving the victim’s wallet/purse. This technique does not work with common mag-strip cards (the ones you swipe through a reader or feed into an ATM slot), only the newer cards that let you make purchases by waving the card in front of a scanner at the point of sale.

The video apparently demonstrates the validity of the technique, but goes on to say there have been no reported cases. OTOH, how would a CC fraud victim know that this is how their account info was stolen?

The guy demonstrating the technique owns an identity theft prevention company, so this all comes with a grain of salt. Having said that, what’s the real deal? Is this indeed possible? If so, are there technological hurdles that make it difficult, and therefore not likely to be common? Isn’t the card info going to be encrypted somehow? 😕

---

<div class="post-metadata">

### Author: ![Telemark](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/telemark/32/372_2.png) [@Telemark](https://boards.straightdope.com/u/Telemark)
#### Post date: [December 6, 2010, 8:37pm UTC](https://boards.straightdope.com/t/illicit-scanning-of-ccs-with-rfids-real-deal/563195/2 "2010-12-06T20:37:21Z")

</div>

> **[RFID in credit cards -- latest UL](https://boards.straightdope.com/sdmb/showthread.php?t=587869)**
>
> Got an email from a friend warning me about people with nefarious plans (and apparently using IPADs) who can ‘scan’ my credit cards while still in my wallet as I wander thru crowded areas. So my questions, since this is the first I’ve heard of it: ...

Already a thread on this, or at least a very similar topic.

---

<div class="post-metadata">

### Author: ![Machine\_Elf](https://avatars.discourse-cdn.com/v4/letter/m/82dd89/32.png) [@Machine\_Elf](https://boards.straightdope.com/u/Machine_Elf)
#### Post date: [December 6, 2010, 8:44pm UTC](https://boards.straightdope.com/t/illicit-scanning-of-ccs-with-rfids-real-deal/563195/3 "2010-12-06T20:44:19Z")

</div>

> [@Telemark](#):
>
> [RFID in credit cards -- latest UL - Factual Questions - Straight Dope Message Board](http://boards.straightdope.com/sdmb/showthread.php?t=587869)
> 
> Already a thread on this, or at least a very similar topic.

Thanks, though a big question remains unanswered: isn’t the card data encrypted somehow? I’d like to think that card issuers anticipated this kind of scanning and took steps to thwart it.

---

<div class="post-metadata">

### Author: ![Palooka](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/palooka/32/2902_2.png) [@Palooka](https://boards.straightdope.com/u/Palooka)
#### Post date: [December 6, 2010, 8:57pm UTC](https://boards.straightdope.com/t/illicit-scanning-of-ccs-with-rfids-real-deal/563195/4 "2010-12-06T20:57:25Z")

</div>

No, it’s in plain text for most of them.

---

<div class="post-metadata">

### Author: ![engineer\_comp\_geek](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/engineer_comp_geek/32/504_2.png) [@engineer\_comp\_geek](https://boards.straightdope.com/u/engineer_comp_geek)
#### Post date: [December 6, 2010, 9:17pm UTC](https://boards.straightdope.com/t/illicit-scanning-of-ccs-with-rfids-real-deal/563195/5 "2010-12-06T21:17:09Z")

</div>

Most of the cards do use encryption. Blink and Express Pay cards for example both supposedly use 128 bit encryption.

That said, last year, folks at the University of Massachusetts were able to construct a card reader very cheaply and did manage to read quite a few cards. They also found that many cards sent back data in plain text that was not encrypted at all.

---

<div class="post-metadata">

### Author: ![Reply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/reply/32/15952_2.png) [@Reply](https://boards.straightdope.com/u/Reply)
#### Post date: [December 6, 2010, 10:53pm UTC](https://boards.straightdope.com/t/illicit-scanning-of-ccs-with-rfids-real-deal/563195/6 "2010-12-06T22:53:34Z")

</div>

Wouldn’t encryption require them to control all the RFID readers/receivers as well?
