NFC: Privacy Exposed
This one came as a shocker to me. Major banks issue major credit cards that keep a history of transactions and offer that openly to any reader. And by *any* I don't mean an authorized wireless payment terminal a waiter uses in a restaurant. It can be just any NFC reader, like the one most of us have in mobile phones.
So I can be riding a bus with my wallet safe in my pocket and the bus is a little crowded and a person behind me is standing with a phone in her hand. Entirely common situation. And then this person is capable of scanning my cards without me even being aware of this.
Look what happens. You can actually get a lot of information. The transaction history on the attached screenshot is real. You can see this person travels a lot and even can track back the countries: Singapore, Poland, Hong Kong. You can trace the dates and spending habits.
I just can't imagine what is the use for this information? Why did the bank decide to store that in the open? Is this somewhere in my contract? Do I agree to provide my transaction history to any stranger without them even asking?
This is a huge privacy hole. The bank - whatever they say now - absolutely does not care about my privacy. Which is why I choose to be the bank's customer - to have my records private.
So I can be riding a bus with my wallet safe in my pocket and the bus is a little crowded and a person behind me is standing with a phone in her hand. Entirely common situation. And then this person is capable of scanning my cards without me even being aware of this.
Look what happens. You can actually get a lot of information. The transaction history on the attached screenshot is real. You can see this person travels a lot and even can track back the countries: Singapore, Poland, Hong Kong. You can trace the dates and spending habits.
I just can't imagine what is the use for this information? Why did the bank decide to store that in the open? Is this somewhere in my contract? Do I agree to provide my transaction history to any stranger without them even asking?
This is a huge privacy hole. The bank - whatever they say now - absolutely does not care about my privacy. Which is why I choose to be the bank's customer - to have my records private.
Comments
Post a Comment