# "Tap Here" on credit machines at McDonalds

**URL:** https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948
**Category:** Factual Questions
**Created:** [November 1, 2005, 7:21pm UTC](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948 "2005-11-01T19:21:42Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Jayrot](https://avatars.discourse-cdn.com/v4/letter/j/3ec8ea/32.png) [@Jayrot](https://boards.straightdope.com/u/Jayrot)
#### Post date: [November 1, 2005, 7:21pm UTC](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948/1 "2005-11-01T19:21:42Z")

</div>

On one of my infrequent trips to McDonalds recently, I noticed at the top of the ATM/Credit Card swiper pin-pad thingy is a red…extension with the words “Tap Here” and a graphic of a credit card tapping the machine. So I tapped it.

Alarm siren’s went off and the manager vaulted over the counter and tackled me, pinning down my arms and legs until the breakfast menu switched over to lunch.

Actually, nothing happened. What’s this thing for?

---

<div class="post-metadata">

### Author: ![groman](https://avatars.discourse-cdn.com/v4/letter/g/73ab20/32.png) [@groman](https://boards.straightdope.com/u/groman)
#### Post date: [November 1, 2005, 7:29pm UTC](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948/2 "2005-11-01T19:29:22Z")

</div>

Just a WAG but maybe it’s an RFID reader for some sort of RFID enabled payment method? It wouldn’t require you to tap, but to wave in front just close enough, however “tap here” is a lot easier than explaining what “close enough” means on a label.

---

<div class="post-metadata">

### Author: ![CynicalGabe](https://avatars.discourse-cdn.com/v4/letter/c/3e96dc/32.png) [@CynicalGabe](https://boards.straightdope.com/u/CynicalGabe)
#### Post date: [November 1, 2005, 7:35pm UTC](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948/3 "2005-11-01T19:35:53Z")

</div>

Its a new sort of card scanner that doesn’t require “swiping”.

---

<div class="post-metadata">

### Author: ![Jayrot](https://avatars.discourse-cdn.com/v4/letter/j/3ec8ea/32.png) [@Jayrot](https://boards.straightdope.com/u/Jayrot)
#### Post date: [November 1, 2005, 7:47pm UTC](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948/4 "2005-11-01T19:47:20Z")

</div>

And this is supposed to work with standard, run of the mill credit cards?

---

<div class="post-metadata">

### Author: ![Cleophus](https://avatars.discourse-cdn.com/v4/letter/c/a88e57/32.png) [@Cleophus](https://boards.straightdope.com/u/Cleophus)
#### Post date: [November 1, 2005, 8:07pm UTC](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948/5 "2005-11-01T20:07:29Z")

</div>

> [@Jayrot](#):
>
> And this is supposed to work with standard, run of the mill credit cards?

No. You need a credit card with an RFID tag.

---

<div class="post-metadata">

### Author: ![tanstaafl](https://avatars.discourse-cdn.com/v4/letter/t/ba8739/32.png) [@tanstaafl](https://boards.straightdope.com/u/tanstaafl)
#### Post date: [November 1, 2005, 8:07pm UTC](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948/6 "2005-11-01T20:07:41Z")

</div>

It’s a new type of card coming out called the “Blink” card. They are being test marketed in some areas.

ObCites…

[http://msnbc.msn.com/id/7976809/](http://msnbc.msn.com/id/7976809/)

> **[How Blink Technology Works](https://money.howstuffworks.com/personal-finance/debt-management/blink.htm)**
>
> Tired of all that time-consuming swiping at the register? Credit cards using contactless technology allow you to pay for stuff by holding the card near a special reader instead of handing it to a clerk or wondering if you slide it with the stripe...

---

<div class="post-metadata">

### Author: ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)
#### Post date: [November 1, 2005, 8:32pm UTC](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948/7 "2005-11-01T20:32:47Z")

</div>

CS guy checking in:

I got one of these RFID credit cards a couple weeks ago. Unasked for.

I immediately called and asked for a regular card. It really confused the woman at the helpdesk. “But you can use it just like a regular card too.” and “It’s perfectly secure.”

I didn’t bother to tell her that 1 week after the invention of the RSA encryption scheme I was in the back seat of a car with R and A. I know a lot more about this stuff than she does. Secure my foot.

You do _not_ want to carry this card around. The issue isn’t so much payment (which might be insecure) but what can be done with it while you’re just walking around.

I got “normal” credit cards last week. I then took apart the RFID cards and tried to find the tag (so I could tell if my new ones might secretly have them). No luck.

The use of RFID tags everywhere is going to be A Very Bad Thing.

---

<div class="post-metadata">

### Author: ![bordelond](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bordelond/32/150_2.png) [@bordelond](https://boards.straightdope.com/u/bordelond)
#### Post date: [November 1, 2005, 8:33pm UTC](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948/8 "2005-11-01T20:33:58Z")

</div>

> [@Cleophus](#):
>
> No. You need a credit card with an RFID tag.

Aaaah … like security badge at some large office buildings that open magnetic doors. Not a bad idea at all. The magnetic strips on the back of most debit/credit cards seem to degrade over time.

---

<div class="post-metadata">

### Author: ![bordelond](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bordelond/32/150_2.png) [@bordelond](https://boards.straightdope.com/u/bordelond)
#### Post date: [November 1, 2005, 8:36pm UTC](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948/9 "2005-11-01T20:36:15Z")

</div>

> [@ftg](#):
>
> You do _not_ want to carry this card around. The issue isn’t so much payment (which might be insecure) but what can be done with it while you’re just walking around.

Go on. The dangers are not obvious to me (well, I think I know what you’re getting at, but it seems like a one-in-a-kajagoogoojillion kind of thing).

---

<div class="post-metadata">

### Author: ![TJVM](https://avatars.discourse-cdn.com/v4/letter/t/b38774/32.png) [@TJVM](https://boards.straightdope.com/u/TJVM)
#### Post date: [November 1, 2005, 8:58pm UTC](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948/10 "2005-11-01T20:58:44Z")

</div>

> [@](#):
>
> 1 week after the invention of the RSA encryption scheme I was in the back seat of a car with R and A

Is that what it takes to get them to give up their secrets?

---

<div class="post-metadata">

### Author: ![Velma](https://avatars.discourse-cdn.com/v4/letter/v/85e7bf/32.png) [@Velma](https://boards.straightdope.com/u/Velma)
#### Post date: [November 1, 2005, 9:21pm UTC](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948/11 "2005-11-01T21:21:19Z")

</div>

> [@ftg](#):
>
> CS guy checking in:  
> The use of RFID tags everywhere is going to be A Very Bad Thing.

Is this the same technology they use for the Speedpass? They are metal cylinders that go on your keychain that can be used at some gas stations. It is set up so I just wave my pass at the pump and my debit card is charged. Why is it bad, and should I not carry it around?

---

<div class="post-metadata">

### Author: ![Joey\_P](https://avatars.discourse-cdn.com/v4/letter/j/919ad9/32.png) [@Joey\_P](https://boards.straightdope.com/u/Joey_P)
#### Post date: [November 1, 2005, 9:21pm UTC](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948/12 "2005-11-01T21:21:08Z")

</div>

> [@bordelond](#):
>
> Go on. The dangers are not obvious to me (well, I think I know what you’re getting at, but it seems like a one-in-a-kajagoogoojillion kind of thing).

I thought I had read somewhere that in stores that use them on their products, people could read them from outside the building. He’s saying there not safe becuase someone with an RFID reader could walk down the block and pick up ALOT of info. I’ll see if I can find the article.

---

<div class="post-metadata">

### Author: ![tanstaafl](https://avatars.discourse-cdn.com/v4/letter/t/ba8739/32.png) [@tanstaafl](https://boards.straightdope.com/u/tanstaafl)
#### Post date: [November 1, 2005, 9:25pm UTC](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948/13 "2005-11-01T21:25:35Z")

</div>

The article I linked to above indicated that someone could build a reader, place it in a busy area and read everyone’s credit cards as they walk by.

There were also concerns about someone walking past a checkout and paying for someone else’s purchases, or of the card being picked up by several readers and a payment being registered from all of them.

---

<div class="post-metadata">

### Author: ![UncleRojelio](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/unclerojelio/32/3160_2.png) [@UncleRojelio](https://boards.straightdope.com/u/UncleRojelio)
#### Post date: [November 1, 2005, 9:28pm UTC](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948/14 "2005-11-01T21:28:30Z")

</div>

> [@Velma](#):
>
> Is this the same technology they use for the Speedpass?

Yes

> [@Velma](#):
>
> Why is it bad, and should I not carry it around?

> [@](#):
>
> A second security concern is duplication, or “cloning” of RFID tags. When tags do not contain built-in security features, an attacker may be able to scan the tag and “clone” the data into a tag of her own.

[Cite](http://en.wikipedia.org/wiki/RFID)

---

<div class="post-metadata">

### Author: ![Jayrot](https://avatars.discourse-cdn.com/v4/letter/j/3ec8ea/32.png) [@Jayrot](https://boards.straightdope.com/u/Jayrot)
#### Post date: [November 1, 2005, 9:31pm UTC](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948/15 "2005-11-01T21:31:12Z")

</div>

Indeed. Let’s hear some more about RFID, **ftg** , since [starting in Oct. 2006, all US Passports will have RFID](http://news.zdnet.com/2100-1009_22-5913644.html).

---

<div class="post-metadata">

### Author: ![bordelond](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bordelond/32/150_2.png) [@bordelond](https://boards.straightdope.com/u/bordelond)
#### Post date: [November 1, 2005, 9:31pm UTC](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948/16 "2005-11-01T21:31:14Z")

</div>

> [@Joey P](#):
>
> I thought I had read somewhere that in stores that use them on their products, people could read them from outside the building. He’s saying there not safe becuase someone with an RFID reader could walk down the block and pick up ALOT of info. I’ll see if I can find the article.

I’m disinclined to believe this without amazingly solid evidence. Those chips don’t have much of a range, do they? I certainly can’t open the magnetic doors of my office with my badge from any kind of distance.

And as for the hypothetical thief with the RFID reader – how’s he getting PIN numbers? And how does he know that the info on the chips are straight-up CC numbers, expiration dates, and personal data? Can said thief safely assume that none of this data is encrypted?

Just how easy is it for a thief to actually get a RFID reader, pus some apparatus that can collect the data? Then how feasible is it for this guy to spend the day bumping into people in public? These chips certainly aren’t being read from further away than maybe a few inches, right?

I dunno … I can’t wrap my head around the easy fraud opportunities just yet. Criminals don’t usually work that hard for their loot.

---

<div class="post-metadata">

### Author: ![tanstaafl](https://avatars.discourse-cdn.com/v4/letter/t/ba8739/32.png) [@tanstaafl](https://boards.straightdope.com/u/tanstaafl)
#### Post date: [November 1, 2005, 9:39pm UTC](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948/17 "2005-11-01T21:39:32Z")

</div>

Since no one seems to be following the links…

> [@](#):
>
> A signature is not required when using a blink card, which leads to security concerns. … The problem, of course, is that if someone gets his or her hands on your blink card, there’s no need to verify anything at all in order to use it in a store. But Blink users are no more accountable for fraudulent charges than any other credit-card user.
> 
> There have been reports of problems in the testing of contactless RFID credit cards, however, that lead to additional security concerns. In some cases, if two or more terminals were close together, not only did both terminals read the card, but the read range of each terminal increased to as much as **30 feet** (9 m) [ref]. Even if the terminal is operating within the proper range of 4 inches, some people are worried that they could accidentally walk too close to a terminal and end up paying for someone else’s purchase. The simplest safeguard against this is probably merchants positioning the terminals in such a way as to make this unlikely.
> 
> The worst case scenario involves someone getting their hands on a blink terminal and modifying it to increase the range. Potentially, someone could set up the terminal at a crowded location and collect the credit-card data of anyone who came within the terminal’s read range. This probably won’t be a concern at first, since few terminals will be available, but if the technology matures, blink terminals could fall into the hands of criminals.

---

<div class="post-metadata">

### Author: ![bordelond](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bordelond/32/150_2.png) [@bordelond](https://boards.straightdope.com/u/bordelond)
#### Post date: [November 1, 2005, 9:49pm UTC](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948/18 "2005-11-01T21:49:23Z")

</div>

> [@tanstaafl's link](#):
>
> The worst case scenario involves someone getting their hands on a blink terminal and modifying it to increase the range

Well … just how easy is this? I thought these readers had a finite limit?

---

<div class="post-metadata">

### Author: ![AskNott](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/asknott/32/5790_2.png) [@AskNott](https://boards.straightdope.com/u/AskNott)
#### Post date: [November 1, 2005, 10:09pm UTC](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948/19 "2005-11-01T22:09:47Z")

</div>

Good grief, now I’m gonna have to keep my wallet in an Altoids tin. A tinfoil hat for my credit cards!

---

<div class="post-metadata">

### Author: ![tofergregg](https://avatars.discourse-cdn.com/v4/letter/t/bbe5ce/32.png) [@tofergregg](https://boards.straightdope.com/u/tofergregg)
#### Post date: [November 1, 2005, 10:19pm UTC](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948/20 "2005-11-01T22:19:09Z")

</div>

I’ve had a credit card stolen, as has a friend of mine, and neither of us was ever charged a dime towards the unauthorized charges. In the absolute worst-case scenario (with a credit card, debit cards are another story), you can be liable for up to $50 of the unauthorized charges. Not worth it to me to spend any extra time on the phone with my credit card company trying to get RFID-free cards.

-Tofer

[Next page](https://boards.straightdope.com/t/tap-here-on-credit-machines-at-mcdonalds/328948.md?page=2)
