{"id":1561,"date":"2015-02-28T19:32:37","date_gmt":"2015-02-28T19:32:37","guid":{"rendered":"http:\/\/nethemba.com\/cs\/update-bezpecnostna-analyza-platobnych-nfc-kariet\/"},"modified":"2015-02-28T19:32:37","modified_gmt":"2015-02-28T19:32:37","slug":"update-bezpecnostna-analyza-platobnych-nfc-kariet","status":"publish","type":"post","link":"https:\/\/nethemba.com\/cs\/update-bezpecnostna-analyza-platobnych-nfc-kariet\/","title":{"rendered":"UPDATE: Bezpe\u010dnostn\u00e1 anal\u00fdza platobn\u00fdch NFC kariet"},"content":{"rendered":"<h1><strong>Zhrnutie<\/strong><\/h1>\n<p>Bezkontaktn\u00e9 platobn\u00e9 karty VISA (payWave), \u010di Mastercard (PayPass) patria na Slovensku medzi najpopul\u00e1rnej\u0161ie &#8211; preferuje ich viac ako <a href=\"http:\/\/www.mastercard.sk\/osobne-karty\/_assets\/06_11_mastercard_index.pdf\">polovica \u013eud\u00ed (56%)<\/a>.<\/p>\n<p>V apr\u00edli 2012 bola na konferencii Hackito Ergo Sum v Par\u00ed\u017ei publikovan\u00e1 prezent\u00e1cia <a href=\"http:\/\/2012.hackitoergosum.org\/blog\/wp-content\/uploads\/2012\/04\/HES-2012-rlifchitz-contactless-payments-insecurity.pdf\">Hacking the NFC credit cards for fun and profit<\/a>, kde bolo prv\u00fdkr\u00e1t pop\u00edsan\u00e9, \u017ee je technicky mo\u017en\u00e9 plne anonymne a bez autentifik\u00e1cie z\u00edska\u0165 na dia\u013eku ve\u013ek\u00e9 mno\u017estvo citliv\u00fdch inform\u00e1ci\u00ed a n\u00e1sledne zneu\u017ei\u0165. Medzi tak\u00e9to inform\u00e1cie patr\u00ed napr\u00edklad zoznam v\u0161etk\u00fdch realizovan\u00fdch platobn\u00fdch transakci\u00ed (platby v POS termin\u00e1loch, v\u00fdbery z bankomatov).<\/p>\n<p>Ked\u017ee ide o takmer 3 roky star\u00e9 inform\u00e1cie, rozhodli sme sa realizova\u0165 bezpe\u010dnostn\u00fa anal\u00fdzu platobn\u00fdch NFC kariet v Slovenskom prostred\u00ed s cie\u013eom zisti\u0165, \u010di vydavatelia kariet tieto odhalenia reflektovali a za\u010dali u\u017e vyd\u00e1va\u0165 dostato\u010dne bezpe\u010dn\u00e9 platobn\u00e9 NFC karty. V\u00fdsledok na\u0161ej anal\u00fdzy je alarmuj\u00faci &#8211; v\u00e4\u010d\u0161ina platobn\u00fdch NFC kariet na Slovensku uklad\u00e1 st\u00e1le mno\u017estvo citliv\u00fdch inform\u00e1ci\u00ed.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"\" src=\"http:\/\/upload.wikimedia.org\/wikipedia\/commons\/thumb\/0\/0e\/PayPass_POS_terminal.jpg\/514px-PayPass_POS_terminal.jpg\" alt=\"\" width=\"353\" height=\"412\" \/><\/p>\n<p>Tieto citliv\u00e9 inform\u00e1cie je mo\u017en\u00e9 na\u010d\u00edta\u0165 \u013eubovo\u013en\u00fdm predajcom, ktor\u00fd disponuje NFC POS termin\u00e1lom alebo bankou, ktorej bankomaty dok\u00e1\u017eu \u010d\u00edta\u0165 bezkontaktn\u00e9 NFC karty, pr\u00edpadne n\u00e1hodn\u00fdm \u00fato\u010dn\u00edkom, ktor\u00fd z\u00edska fyzick\u00fd pr\u00edstup k zranite\u013enej platobnej NFC karte. N\u00e1sledne je mo\u017en\u00e9 uveden\u00e9 inform\u00e1cie zneu\u017ei\u0165 na z\u00edskanie nakupovacieho profilu vlastn\u00edka karty, identifik\u00e1ciu kraj\u00edn (na z\u00e1klade pou\u017eitej meny), ktor\u00e9 vlastn\u00edk karty nav\u0161t\u00edvil a kde dan\u00fa kartu pou\u017e\u00edval, odhadnutie jeho solventnosti a na z\u00e1klade toho napr\u00edklad cielen\u00fd marketing. Podobne je mo\u017en\u00e9 kartu po na\u010d\u00edtan\u00ed fyzicky zablokova\u0165 (zaslanie 3x chybn\u00e9ho PIN k\u00f3du).<\/p>\n<h1><strong>Pou\u017eit\u00e9 n\u00e1stroje<\/strong><\/h1>\n<p>NFC \u00fadaje ulo\u017een\u00e9 na samotnej bezkontaktnej platobnej karte id\u00fa na\u010d\u00edta\u0165 \u013eubovo\u013enou NFC \u010d\u00edta\u010dkou podporuj\u00facou protokol ISO14443a pracuj\u00facou na frekvencii 13.56 Mhz. V na\u0161om pr\u00edpade sme pou\u017eili \u0161tandardn\u00e9 smartf\u00f3ny a tablety s podporou NFC a \u0161pecializovan\u00e9 NFC \u010d\u00edta\u010dky <a href=\"http:\/\/en.wikipedia.org\/wiki\/Touchatag\">touchatag<\/a>. Ako aplik\u00e1ciu sme pou\u017eili <a href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.github.devnied.emvnfccard\">Banking card reader NFC (EMV)<\/a> dostupn\u00fa priamo z Google Play. Uveden\u00e1 aplik\u00e1cia nedok\u00e1zala niektor\u00e9 inform\u00e1cie (ako vlastn\u00edka karty) na\u010d\u00edta\u0165. Tie bolo mo\u017en\u00e9 na\u010d\u00edta\u0165 napr\u00edklad aplik\u00e1ciou <a href=\"https:\/\/github.com\/laane\/nfcmillionaire\">NFC millionare<\/a>, demon\u0161tra\u010dn\u00e9 video k <a href=\"https:\/\/www.youtube.com\/watch?v=8ptqLROjgsg&amp;feature=youtu.be\">dispoz\u00edcii tu<\/a>, kedy je to mo\u017en\u00e9 realizova\u0165 skuto\u010dne nen\u00e1padne.<\/p>\n<p><img decoding=\"async\" class=\"\" src=\"https:\/\/lh4.ggpht.com\/IbcbMuDpDIKBFJG_OrIVnAaoKncWReK-nGr6zNJIcRoi8B_X4ZvyyjpbYMATJ5gRo5Q=h900\" alt=\"\" width=\"356\" height=\"633\" \/><img decoding=\"async\" class=\"\" src=\"https:\/\/lh4.ggpht.com\/rtBNCx75vbc3BAEMIG1ILCLE9kS07uPd0tnjfhyvMsVjbGWdK_gvfywqfT8SdBordNU=h900\" alt=\"\" width=\"356\" height=\"633\" \/><\/p>\n<h1><strong>Maxim\u00e1lna vzdialenos\u0165<\/strong><\/h1>\n<p>\u010c\u00edtanie kariet bolo realizovan\u00e9 bez externej NFC ant\u00e9ny zo vzdialenosti do 4 centimetrov. NFC \u0161tandard umo\u017e\u0148uje t\u00fato vzdialenos\u0165 nav\u00fd\u0161i\u0165 a\u017e do <a href=\"http:\/\/physics.stackexchange.com\/questions\/44037\/why-is-near-field-communication-nfc-range-limited-to-about-20cm\">vzdialenosti 20 centimetrov<\/a>.<\/p>\n<p>Pod\u013ea prezent\u00e1cie &#8222;<a href=\"http:\/\/2012.hackitoergosum.org\/blog\/wp-content\/uploads\/2012\/04\/HES-2012-rlifchitz-contactless-payments-insecurity.pdf\">Hacking the NFC credit cards for fun and debit<\/a>&#8220; (slajd 21) je mo\u017en\u00e9 pomocou externej ant\u00e9ny dosah \u010d\u00edtania zosil\u0148ova\u010dom (za 2000 EUR) a ant\u00e9nou (za 1000 EUR) zv\u00fd\u0161i\u0165 a\u017e do vzdialenosti 1.5 metra. Pr\u00edpadne pas\u00edvnym sniffovan\u00edm a\u017e do vzdialenosti 15 metrov pou\u017eit\u00edm r\u00e1dio prij\u00edma\u010da (napr\u00edklad USRP) so \u0161tandardnou teleskopickou ant\u00e9nou.<\/p>\n<p>Video ako je mo\u017en\u00e9 NFC platobn\u00e9 karty elegantne a jednoducho na\u010d\u00edta\u0165.<\/p>\n<div id=\"fb-root\" class=\" fb_reset\">\n<div><\/div>\n<div>\n<div><iframe id=\"fb_xdm_frame_https\" tabindex=\"-1\" title=\"Facebook Cross Domain Communication Frame\" src=\"https:\/\/staticxx.facebook.com\/connect\/xd_arbiter.php?version=42#channel=f1f7d531bc&amp;origin=https%3A%2F%2Fcore.nethemba.com%3A4444\" name=\"fb_xdm_frame_https\" width=\"300\" height=\"150\" frameborder=\"0\" scrolling=\"no\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/div>\n<\/div>\n<\/div>\n<div class=\"fb-post fb_iframe_widget\" data-href=\"https:\/\/www.facebook.com\/video.php?v=10152895235582418\" data-width=\"466\"><iframe class=\"\" title=\"fb:post Facebook Social Plugin\" src=\"https:\/\/www.facebook.com\/plugins\/post.php?app_id=&amp;channel=https%3A%2F%2Fstaticxx.facebook.com%2Fconnect%2Fxd_arbiter.php%3Fversion%3D42%23cb%3Df20a752c08%26domain%3Dcore.nethemba.com%26origin%3Dhttps%253A%252F%252Fcore.nethemba.com%253A4444%252Ff1f7d531bc%26relation%3Dparent.parent&amp;container_width=0&amp;href=https%3A%2F%2Fwww.facebook.com%2Fvideo.php%3Fv%3D10152895235582418&amp;locale=cs_CZ&amp;sdk=joey&amp;width=466\" name=\"ff6a3c5a8\" width=\"466px\" height=\"1000px\" frameborder=\"0\" scrolling=\"no\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/div>\n<p>&nbsp;<\/p>\n<h1><strong>Zneu\u017eitie platobn\u00fdch kariet<\/strong><\/h1>\n<p>Mno\u017estvo NFC EMV platobn\u00fdch kariet obsahuje citliv\u00e9 inform\u00e1cie, ktor\u00e9 na spr\u00e1vnu funkcionalitu platobnej karty nie s\u00fa potrebn\u00e9, ako meno vlastn\u00edka karty \u010di jeho vykonan\u00fa transak\u010dn\u00fa hist\u00f3riu.<\/p>\n<p>Anal\u00fdzou dostupn\u00fdch slovensk\u00fdch NFC EMV kariet sme odhalili, \u017ee<strong> bolo mo\u017en\u00e9 plne anonymne, bez autentifik\u00e1cie pre mno\u017estvo testovan\u00fdch kariet a behom len p\u00e1r sek\u00fand na\u010d\u00edta\u0165 cel\u00fa transak\u010dn\u00fa hist\u00f3riu<\/strong>.<\/p>\n<p>Tie\u017e bolo mo\u017en\u00e9 z NFC \u010dipu pre\u010d\u00edta\u0165 \u010d\u00edslo karty a d\u00e1tum expir\u00e1cie (bez CVC k\u00f3du), ktor\u00e9 je tie\u017e vytla\u010den\u00e9 na samotnej karte, ako aj po\u010det zost\u00e1vaj\u00facich pokusov PIN. Pomocou aplik\u00e1cie <a href=\"https:\/\/github.com\/laane\/nfcmillionaire\">NFC millionare<\/a> bolo mo\u017en\u00e9 na\u010d\u00edta\u0165 vlastn\u00edka karty.<\/p>\n<p>Inform\u00e1cia ako CVC\/CVV k\u00f3d nie je na karte ulo\u017een\u00e1 a nemala by sa uklada\u0165.<\/p>\n<table style=\"height: 2401px;\" border=\"5\" width=\"964\" cellspacing=\"5\" cellpadding=\"5\" align=\"center\">\n<caption>Porovnanie platobn\u00fdch NFC EMV kariet na Slovensku<\/caption>\n<tbody>\n<tr>\n<td><strong>Banka<\/strong><\/td>\n<td><strong>Typ karty<\/strong><\/td>\n<td><strong>Ulo\u017een\u00e1 transak\u010dn\u00e1 hist\u00f3ria?<\/strong><\/td>\n<td><strong>\u010c\u00edslo karty a d\u00e1tum expir\u00e1cie<\/strong><\/td>\n<td><strong>Ulo\u017een\u00e1 inform\u00e1cia o zost\u00e1vaj\u00facich PIN pokusoch<\/strong><\/td>\n<td><strong>D\u00e1tum expir\u00e1cie<\/strong><\/td>\n<\/tr>\n<tr>\n<td>SLSP<\/td>\n<td>Visa Electron<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>06\/16<\/td>\n<\/tr>\n<tr>\n<td>SLSP<\/td>\n<td>Visa Electron<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>10\/17<\/td>\n<\/tr>\n<tr>\n<td>SLSP<\/td>\n<td>Visa Classic<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>11\/17<\/td>\n<\/tr>\n<tr>\n<td>SLSP<\/td>\n<td>Visa Electron<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>09\/15<\/td>\n<\/tr>\n<tr>\n<td>SLSP<\/td>\n<td>Visa Electron<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>01\/17<\/td>\n<\/tr>\n<tr>\n<td>SLSP<\/td>\n<td>MasterCard Maestro<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>10\/16<\/td>\n<\/tr>\n<tr>\n<td>SLSP<\/td>\n<td>Visa Electron<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>08\/17<\/td>\n<\/tr>\n<tr>\n<td>SLSP<\/td>\n<td>Visa Electron<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>09\/17<\/td>\n<\/tr>\n<tr>\n<td>SLSP<\/td>\n<td>Visa Electron<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>07\/15<\/td>\n<\/tr>\n<tr>\n<td>SLSP<\/td>\n<td>Visa Classic<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>06\/17<\/td>\n<\/tr>\n<tr>\n<td>SLSP<\/td>\n<td>Visa Classic<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>06\/15<\/td>\n<\/tr>\n<tr>\n<td>SLSP<\/td>\n<td>Visa Electron<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>06\/15<\/td>\n<\/tr>\n<tr>\n<td>SLSP<\/td>\n<td>MasterCard Maestro<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>02\/16<\/td>\n<\/tr>\n<tr>\n<td>SLSP<\/td>\n<td>MasterCard Debit<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>07\/15<\/td>\n<\/tr>\n<tr>\n<td>mBank<\/td>\n<td>Visa Classic<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>04\/17<\/td>\n<\/tr>\n<tr>\n<td>mBank<\/td>\n<td>Visa Classic<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>01\/17<\/td>\n<\/tr>\n<tr>\n<td>mBank<\/td>\n<td>Visa Classic<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>12\/15<\/td>\n<\/tr>\n<tr>\n<td>mBank<\/td>\n<td>Visa Classic<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>01\/18<\/td>\n<\/tr>\n<tr>\n<td>mBank<\/td>\n<td>Visa Classic<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>09\/17<\/td>\n<\/tr>\n<tr>\n<td>Zuno<\/td>\n<td>Visa Classic<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>07\/17<\/td>\n<\/tr>\n<tr>\n<td>Zuno<\/td>\n<td>Visa Classic<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>02\/18<\/td>\n<\/tr>\n<tr>\n<td>Zuno<\/td>\n<td>Visa Classic<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>09\/16<\/td>\n<\/tr>\n<tr>\n<td>Zuno<\/td>\n<td>Visa Classic<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>07\/17<\/td>\n<\/tr>\n<tr>\n<td>Zuno<\/td>\n<td>Mastercard<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>02\/17<\/td>\n<\/tr>\n<tr>\n<td>Zuno<\/td>\n<td>Visa Classic<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>02\/17<\/td>\n<\/tr>\n<tr>\n<td>Zuno<\/td>\n<td>MasterCard<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>03\/17<\/td>\n<\/tr>\n<tr>\n<td>Zuno<\/td>\n<td>Visa Classic<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>10\/17<\/td>\n<\/tr>\n<tr>\n<td>V\u00daB<\/td>\n<td>Visa Classic<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>02\/18<\/td>\n<\/tr>\n<tr>\n<td>V\u00daB<\/td>\n<td>Visa Classic<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>08\/15<\/td>\n<\/tr>\n<tr>\n<td>V\u00daB<\/td>\n<td>Visa Electron<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>08\/15<\/td>\n<\/tr>\n<tr>\n<td>V\u00daB<\/td>\n<td>Visa Classic<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>12\/16<\/td>\n<\/tr>\n<tr>\n<td>V\u00daB<\/td>\n<td>Visa Classic<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>06\/15<\/td>\n<\/tr>\n<tr>\n<td>V\u00daB<\/td>\n<td>Visa Classic<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>01\/17<\/td>\n<\/tr>\n<tr>\n<td>Tatra banka<\/td>\n<td>Visa Classic<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>06\/15<\/td>\n<\/tr>\n<tr>\n<td>Tatra banka<\/td>\n<td>Visa Electron<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>11\/15<\/td>\n<\/tr>\n<tr>\n<td>Tatra banka<\/td>\n<td>Visa Electron<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>01\/16<\/td>\n<\/tr>\n<tr>\n<td>Tatra banka<\/td>\n<td>Visa Electron<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>03\/16<\/td>\n<\/tr>\n<tr>\n<td>Tatra banka<\/td>\n<td>Visa Electron<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>02\/17<\/td>\n<\/tr>\n<tr>\n<td>Tatra banka<\/td>\n<td>Visa Electron<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>09\/16<\/td>\n<\/tr>\n<tr>\n<td>Tatra banka<\/td>\n<td>Visa Electron<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>09\/16<\/td>\n<\/tr>\n<tr>\n<td>Tatra banka<\/td>\n<td>Visa Classic<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>07\/17<\/td>\n<\/tr>\n<tr>\n<td>Tatra banka<\/td>\n<td>Visa Electron<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>07\/16<\/td>\n<\/tr>\n<tr>\n<td>Tatra banka<\/td>\n<td>Visa Electron<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>06\/17<\/td>\n<\/tr>\n<tr>\n<td>Tatra banka<\/td>\n<td>Visa Classic<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>11\/15<\/td>\n<\/tr>\n<tr>\n<td>Tatra banka<\/td>\n<td>Visa Electron<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>02\/17<\/td>\n<\/tr>\n<tr>\n<td>Tatra banka<\/td>\n<td>Visa Classic<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>11\/16<\/td>\n<\/tr>\n<tr>\n<td>Tatra banka<\/td>\n<td>Visa Electron<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>07\/15<\/td>\n<\/tr>\n<tr>\n<td>Unicredit<\/td>\n<td>MasterCard Maestro<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>XX\/XX<\/td>\n<\/tr>\n<tr>\n<td>Unicredit<\/td>\n<td>MasterCard Maestro<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>05\/17<\/td>\n<\/tr>\n<tr>\n<td>Unicredit<\/td>\n<td>MasterCard<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>05\/13<\/td>\n<\/tr>\n<tr>\n<td>Sberbank<\/td>\n<td>MasterCard Maestro<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>07\/18<\/td>\n<\/tr>\n<tr>\n<td>\u010cSOB<\/td>\n<td>Visa Classic<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>02\/18<\/td>\n<\/tr>\n<tr>\n<td>\u010cSOB<\/td>\n<td>Visa Classic<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>05\/17<\/td>\n<\/tr>\n<tr>\n<td>\u010cSOB<\/td>\n<td>Visa Electron<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>07\/15<\/td>\n<\/tr>\n<tr>\n<td>\u010cSOB<\/td>\n<td>Visa Classic<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>11\/17<\/td>\n<\/tr>\n<tr>\n<td>\u010cSOB<\/td>\n<td>MasterCard<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>01\/18<\/td>\n<\/tr>\n<tr>\n<td>\u010cSOB<\/td>\n<td>Visa Classic<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>01\/18<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<table style=\"height: 947px;\" border=\"5\" width=\"774\" cellspacing=\"5\" cellpadding=\"5\" align=\"center\">\n<caption>Porovnanie platobn\u00fdch NFC EMV kariet v \u010cech\u00e1ch<\/caption>\n<tbody>\n<tr>\n<td><strong>Banka<\/strong><\/td>\n<td><strong>Typ karty<\/strong><\/td>\n<td><strong>Ulo\u017een\u00e1 transak\u010dn\u00e1 hist\u00f3ria?<\/strong><\/td>\n<td><strong>\u010c\u00edslo karty a d\u00e1tum expir\u00e1cie<\/strong><\/td>\n<td><strong>Ulo\u017een\u00e1 inform\u00e1cia o zost\u00e1vaj\u00facich PIN pokusoch<\/strong><\/td>\n<td><strong>D\u00e1tum expir\u00e1cie<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Raiffaisen<\/td>\n<td>MasterCard<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>04\/17<\/td>\n<\/tr>\n<tr>\n<td>\u010cesk\u00e1 sporite\u013ena<\/td>\n<td>Visa Classic<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>01\/16<\/td>\n<\/tr>\n<tr>\n<td>\u010ceska sporite\u013ena<\/td>\n<td>Visa Classic<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>10\/16<\/td>\n<\/tr>\n<tr>\n<td>Airbank<\/td>\n<td>MasterCard<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>06\/17<\/td>\n<\/tr>\n<tr>\n<td>Citi bank<\/td>\n<td>MasterCard<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>11\/15<\/td>\n<\/tr>\n<tr>\n<td>mBank<\/td>\n<td>Visa<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>04\/16<\/td>\n<\/tr>\n<tr>\n<td>Equa bank<\/td>\n<td>Master Card<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>09\/13<\/td>\n<\/tr>\n<tr>\n<td>Citi bank<\/td>\n<td>Visa<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>01\/14<\/td>\n<\/tr>\n<tr>\n<td>GE Money bank<\/td>\n<td>Visa<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>06\/17<\/td>\n<\/tr>\n<tr>\n<td>\u010cSOB<\/td>\n<td>MasterCard<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>01\/17<\/td>\n<\/tr>\n<tr>\n<td>\u010cesk\u00e1 spo\u0159itelna<\/td>\n<td>MasterCard<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>09\/16<\/td>\n<\/tr>\n<tr>\n<td>mBank<\/td>\n<td>Visa<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>10\/16<\/td>\n<\/tr>\n<tr>\n<td>\u010cesk\u00e1 spo\u0159itelna<\/td>\n<td>Visa<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>09\/14<\/td>\n<\/tr>\n<tr>\n<td>Citi bank<\/td>\n<td>MasterCard<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>06\/14<\/td>\n<\/tr>\n<tr>\n<td>Citi bank<\/td>\n<td>MasterCard<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>09\/13<\/td>\n<\/tr>\n<tr>\n<td>Unicredit bank<\/td>\n<td>MasterCard<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>04\/13<\/td>\n<\/tr>\n<tr>\n<td>\u010cSOB era<\/td>\n<td>MasterCard<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>07\/19<\/td>\n<\/tr>\n<tr>\n<td>Citi bank<\/td>\n<td>MasterCard<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>09\/13<\/td>\n<\/tr>\n<tr>\n<td>\u010cSOB era<\/td>\n<td>MasterCard<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>05\/18<\/td>\n<\/tr>\n<tr>\n<td>freedom Visa card<\/td>\n<td>MasterCard<\/td>\n<td>Nie<\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>07\/13<\/td>\n<\/tr>\n<tr>\n<td>mBank<\/td>\n<td>Visa Classic<\/td>\n<td><strong>\u00c1no<\/strong><\/td>\n<td>\u00c1no<\/td>\n<td>\u00c1no<\/td>\n<td>11\/16<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p>Mno\u017estvo analyzovan\u00fdch testovan\u00fdch vzoriek platobn\u00fdch kariet v s\u00fa\u010dasnej dobe bohu\u017eia\u013e e\u0161te nie je dosta\u010duj\u00face na to, aby sme mohli vytvori\u0165 jednozna\u010dn\u00fd z\u00e1ver, v ka\u017edom pr\u00edpade sme identifikovali, \u017ee:<\/p>\n<ul>\n<li>pri SLSP kart\u00e1ch bolo mo\u017en\u00e9 na\u010d\u00edta\u0165 zoznam vykonan\u00fdch transakci\u00ed len pre star\u0161ie karty, ktor\u00e9 maj\u00fa expir\u00e1ciu 09\/15, 06\/16, 10\/16, 01\/17, 08\/17. Pre nov\u0161ie SLSP karty s d\u00e1tumami expir\u00e1cie 09\/17, 10\/17 a 11\/17 to nebolo mo\u017en\u00e9 a vyzer\u00e1, \u017ee nov\u00e9 platobn\u00e9 NFC karty s d\u00e1tumom expir\u00e1cie od 09\/17 u\u017e t\u00fato inform\u00e1ciu u\u017e neukladaj\u00fa<\/li>\n<li>v pr\u00edpade men\u0161\u00edch baniek (mBank, Zuno, Unicredit, Sberbank) &#8211; <strong>podarilo sa n\u00e1m z\u00edska\u0165 zoznam vykonan\u00fdch transakci\u00ed z ka\u017edej testovanej karty<\/strong> a to aj z kariet, ktor\u00e9 expiruj\u00fa 07\/18 (Sberbank). Na zistenie, \u010di aj \u00faplne posledn\u00e9 vydan\u00e9 karty ukladaj\u00fa inform\u00e1cie o vykonan\u00fdch transakci\u00e1ch, je potrebn\u00e9 analyzova\u0165 NFC platobn\u00e9 karty vydan\u00e9 v poslednom mesiaci.<\/li>\n<li>\u010do sa t\u00fdka V\u00daB a \u010cSOB kariet, tak sa n\u00e1m nepodarilo zo \u017eiadnej testovanej karty na\u010d\u00edta\u0165 zoznam vykonan\u00fdch transakci\u00ed<\/li>\n<li>s Tatra bankou je situ\u00e1cia trochu zvl\u00e1\u0161tna, lebo zo star\u0161\u00edch kariet (expiruj\u00facich 06\/15 a\u017e 03\/16) sa n\u00e1m transak\u010dn\u00e1 hist\u00f3ria nepodarila z\u00edska\u0165. Z VISA Electron karty s d\u00e1tumom expir\u00e1cie 02\/17 sa n\u00e1m uveden\u00e1 inform\u00e1cia ale z\u00edska\u0165 podarila.<\/li>\n<\/ul>\n<p>V pr\u00edpade, \u017ee bolo mo\u017en\u00e9 na\u010d\u00edta\u0165 z danej karty transak\u010dn\u00fa hist\u00f3riu, tak pre ka\u017ed\u00fa transakciu boli dostupn\u00e9 nasleduj\u00face inform\u00e1cie:<\/p>\n<ul>\n<li>typ transakcie (platba kartou, v\u00fdber z bankomatu apod)<\/li>\n<li>d\u00e1tum transakcie<\/li>\n<li>celkov\u00e1 suma a pou\u017eit\u00e1 mena<\/li>\n<\/ul>\n<p>Na z\u00e1klade meny krajiny, kde bola transakcia vykonan\u00e1, je mo\u017en\u00e9 vytvori\u0165 geografick\u00fd profil vlastn\u00edka karty teda v ak\u00fdch \u010dasoch, a ktor\u00e9 krajiny nav\u0161t\u00edvil.<\/p>\n<p>Na z\u00e1klade periodicity a objemu samotn\u00fdch platieb je mo\u017en\u00e9 vytvori\u0165 nakupovac\u00ed profil vlastn\u00edka karty ako aj odhadn\u00fa\u0165 jeho solventnos\u0165, teda napr\u00edklad ko\u013eko priemerne m\u00ed\u0148a pe\u0148az\u00ed za dan\u00fd \u010dasov\u00fd interval.<\/p>\n<p>Uveden\u00e9 inform\u00e1cie, ktor\u00e9 dok\u00e1\u017ee z\u00edska\u0165 \u013eubovo\u013en\u00fd vlastn\u00edk POS termin\u00e1lu (predajca) ako aj anonymn\u00fd \u00fato\u010dn\u00edk vo fyzickej bl\u00edzkosti vlastn\u00edka karty, je mo\u017en\u00e9 zneu\u017ei\u0165 napr\u00edklad na cielen\u00fd marketing alebo na z\u00edskanie inform\u00e1ci\u00ed o pohybe dan\u00e9ho \u010dloveka v \u010dase.<\/p>\n<p>Ve\u013ea e-commerce str\u00e1nok pri platbe nevy\u017eaduje CVC\/CVV k\u00f3d, ale na platbu posta\u010duj\u00fa len 3 z\u00e1kladne inform\u00e1cie (vlastn\u00edk karty, \u010d\u00edslo karty a d\u00e1tum expir\u00e1cie), ktor\u00e9 z NFC \u010dipu id\u00fa obvykle bez probl\u00e9mov na\u010d\u00edta\u0165. \u010c\u00edm sa riziko zneu\u017eitia zvy\u0161uje.<\/p>\n<p>Podobne je mo\u017en\u00e9 realizovat DoS \u00fatok a kartu na dia\u013eku zablokova\u0165 (po zaslan\u00ed 3 chybn\u00fdch PIN k\u00f3dov).<\/p>\n<h1><strong>Ako sa chr\u00e1ni\u0165?<\/strong><\/h1>\n<p>V prvom rade si overte pou\u017eit\u00edm \u013eubovo\u013en\u00e9ho Android zariadenia s podporou NFC aplik\u00e1ciou <a href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.github.devnied.emvnfccard\">Banking card reader<\/a>, ak\u00e9 inform\u00e1cie je mo\u017en\u00e9 na\u010d\u00edta\u0165 z Va\u0161ej platobnej karty. V pr\u00edpade, \u017ee ide o inform\u00e1cie citlivej\u0161ieho charakteru (transak\u010dn\u00e1 hist\u00f3ria, pr\u00edpadne va\u0161e meno a priezvisko), kontaktujte Va\u0161u banku a po\u017eiadajte ju o vydanie novej bezpe\u010dnej\u0161ej karty.<\/p>\n<p>Pok\u00fdm va\u0161a banka bezpe\u010dnej\u0161\u00edmi NFC platobn\u00fdmi kartami nedisponuje a napriek tomu vy\u017eadujete bezkontaktn\u00e9 platby, je dobr\u00e9 zv\u00e1\u017ei\u0165 alternat\u00edvu inej banky, ktor\u00e1 disponuje bezpe\u010dnej\u0161\u00edmi NFC kartami.<\/p>\n<p>Proti n\u00e1hodnym \u00fato\u010dn\u00edkom je mo\u017en\u00e9 sa chr\u00e1ni\u0165 umiestnen\u00edm svojej platobnej karty do tzv. RFID shieldu (<a href=\"http:\/\/sk.wikipedia.org\/wiki\/Faradayova_klietka\">faradayovej klietky<\/a>, ktor\u00e1 blokuje ak\u00e9ko\u013evek elektromagnetick\u00e9 vy\u017earovanie).<\/p>\n<h1><strong>Zapojte sa do na\u0161ej anal\u00fdzy!<\/strong><\/h1>\n<p>St\u00e1le n\u00e1m ch\u00fdbaj\u00fa inform\u00e1cie z NFC platobn\u00fdch kariet z mno\u017estva in\u00fdch slovensk\u00fdch baniek, podobne inform\u00e1cie z aktu\u00e1lne vyd\u00e1van\u00fdch kariet a kariet MasterCard.<\/p>\n<p>Radi uv\u00edtame Va\u0161u pomoc a pon\u00fakame V\u00e1m drobn\u00fd dar\u010dek za poskytnutie anonymizovan\u00fdch inform\u00e1ci\u00ed z Va\u0161ej NFC platobnej karty &#8211; n\u00e1\u0161 firemn\u00fd RFID shield (faradayovu klietku) za ka\u017ed\u00fa Va\u0161u kartu, ktorej inform\u00e1cie (v rozsahu vy\u0161\u0161ie uvedenej tabu\u013eky) n\u00e1m poskytnete. V pr\u00edpade z\u00e1ujmu, n\u00e1s nev\u00e1hajte kontaktova\u0165 na adrese &lt;<a href=\"mailto:nfc@nethemba.com?subject=Inform%C3%A1cia%20o%20NFC%20karte\">nfc@nethemba.com<\/a>&gt;.<\/p>\n<h1><strong>Medi\u00e1lny ohlas<\/strong><\/h1>\n<p><a href=\"http:\/\/mf.srv.markiza.sk\/vod\/_definst_\/smil:part\/E0uyiATvMWMVU9gZ8kiiFSVwXU41g8Mj.smil\/chunklist_w1242968988_b1188480.m3u8\">Videoreport\u00e1\u017e o bezpe\u010dnosti bezkontaktn\u00fdch platobn\u00fdch NFC kariet u\u017e aj na Mark\u00edze<\/a>.<br \/>\n<a href=\"http:\/\/www.zive.sk\/clanok\/102994\/informacie-z-bezkontaktnej-karty-precita-ktokolvek-chrante-sa\">Detailnej\u0161\u00ed a vysvet\u013euj\u00faci \u010dl\u00e1nok na \u017eive.sk (testy robila aj samotn\u00e1 redakcia).<\/a><br \/>\n<a href=\"http:\/\/ekonomika.sme.sk\/c\/7677375\/bezkontaktne-karty-odhalia-nase-sukromie-staci-len-mobil.html\">Bezkontaktn\u00e9 karty odhalia va\u0161e s\u00fakromie, sta\u010d\u00ed len mobil na SME (testy robila aj samotn\u00e1 redakcia).<\/a><br \/>\n<a href=\"http:\/\/aktualne.atlas.sk\/pohodlnost-moze-mat-vysoku-cenu-ako-sa-daju-zneuzit-slovenske-bezkontaktne-karty\/ekonomika\/financie\/\">Pohodlnos\u0165 m\u00f4\u017ee ma\u0165 vysok\u00fa cenu. Ako sa daj\u00fa zneu\u017ei\u0165 slovensk\u00e9 bezkontaktn\u00e9 karty (\u010dl\u00e1nok na aktuality.sk).<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Zhrnutie Bezkontaktn\u00e9 platobn\u00e9 karty VISA (payWave), \u010di Mastercard (PayPass) patria na Slovensku medzi najpopul\u00e1rnej\u0161ie &#8211; preferuje ich viac ako polovica \u013eud\u00ed (56%). V apr\u00edli 2012 bola na konferencii Hackito Ergo Sum v Par\u00ed\u017ei publikovan\u00e1 prezent\u00e1cia Hacking the NFC credit cards for fun and profit, kde bolo prv\u00fdkr\u00e1t pop\u00edsan\u00e9, \u017ee je technicky mo\u017en\u00e9 plne anonymne a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[12],"tags":[],"class_list":["post-1561","post","type-post","status-publish","format-standard","hentry","category-uncategorized-cs"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>UPDATE: Bezpe\u010dnostn\u00e1 anal\u00fdza platobn\u00fdch NFC kariet - Nethemba<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/nethemba.com\/cs\/update-bezpecnostna-analyza-platobnych-nfc-kariet\/\" \/>\n<meta property=\"og:locale\" content=\"cs_CZ\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"UPDATE: Bezpe\u010dnostn\u00e1 anal\u00fdza platobn\u00fdch NFC kariet - Nethemba\" \/>\n<meta property=\"og:description\" content=\"Zhrnutie Bezkontaktn\u00e9 platobn\u00e9 karty VISA (payWave), \u010di Mastercard (PayPass) patria na Slovensku medzi najpopul\u00e1rnej\u0161ie &#8211; preferuje ich viac ako polovica \u013eud\u00ed (56%). V apr\u00edli 2012 bola na konferencii Hackito Ergo Sum v Par\u00ed\u017ei publikovan\u00e1 prezent\u00e1cia Hacking the NFC credit cards for fun and profit, kde bolo prv\u00fdkr\u00e1t pop\u00edsan\u00e9, \u017ee je technicky mo\u017en\u00e9 plne anonymne a [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nethemba.com\/cs\/update-bezpecnostna-analyza-platobnych-nfc-kariet\/\" \/>\n<meta property=\"og:site_name\" content=\"Nethemba\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/nethemba\" \/>\n<meta property=\"article:published_time\" content=\"2015-02-28T19:32:37+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/upload.wikimedia.org\/wikipedia\/commons\/thumb\/0\/0e\/PayPass_POS_terminal.jpg\/514px-PayPass_POS_terminal.jpg\" \/>\n<meta name=\"author\" content=\"Pavol Lupt\u00e1k\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@nethemba\" \/>\n<meta name=\"twitter:site\" content=\"@nethemba\" \/>\n<meta name=\"twitter:label1\" content=\"Napsal(a)\" \/>\n\t<meta name=\"twitter:data1\" content=\"Pavol Lupt\u00e1k\" \/>\n\t<meta name=\"twitter:label2\" content=\"Odhadovan\u00e1 doba \u010dten\u00ed\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minut\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/update-bezpecnostna-analyza-platobnych-nfc-kariet\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/update-bezpecnostna-analyza-platobnych-nfc-kariet\\\/\"},\"author\":{\"name\":\"Pavol Lupt\u00e1k\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#\\\/schema\\\/person\\\/5f4ba68c8e1a2013d30e0804245b8234\"},\"headline\":\"UPDATE: Bezpe\u010dnostn\u00e1 anal\u00fdza platobn\u00fdch NFC kariet\",\"datePublished\":\"2015-02-28T19:32:37+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/update-bezpecnostna-analyza-platobnych-nfc-kariet\\\/\"},\"wordCount\":2029,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/update-bezpecnostna-analyza-platobnych-nfc-kariet\\\/#primaryimage\"},\"thumbnailUrl\":\"http:\\\/\\\/upload.wikimedia.org\\\/wikipedia\\\/commons\\\/thumb\\\/0\\\/0e\\\/PayPass_POS_terminal.jpg\\\/514px-PayPass_POS_terminal.jpg\",\"articleSection\":[\"Uncategorized @cs\"],\"inLanguage\":\"cs\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/nethemba.com\\\/cs\\\/update-bezpecnostna-analyza-platobnych-nfc-kariet\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/update-bezpecnostna-analyza-platobnych-nfc-kariet\\\/\",\"url\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/update-bezpecnostna-analyza-platobnych-nfc-kariet\\\/\",\"name\":\"UPDATE: Bezpe\u010dnostn\u00e1 anal\u00fdza platobn\u00fdch NFC kariet - Nethemba\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/update-bezpecnostna-analyza-platobnych-nfc-kariet\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/update-bezpecnostna-analyza-platobnych-nfc-kariet\\\/#primaryimage\"},\"thumbnailUrl\":\"http:\\\/\\\/upload.wikimedia.org\\\/wikipedia\\\/commons\\\/thumb\\\/0\\\/0e\\\/PayPass_POS_terminal.jpg\\\/514px-PayPass_POS_terminal.jpg\",\"datePublished\":\"2015-02-28T19:32:37+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#\\\/schema\\\/person\\\/5f4ba68c8e1a2013d30e0804245b8234\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/update-bezpecnostna-analyza-platobnych-nfc-kariet\\\/#breadcrumb\"},\"inLanguage\":\"cs\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/nethemba.com\\\/cs\\\/update-bezpecnostna-analyza-platobnych-nfc-kariet\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"cs\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/update-bezpecnostna-analyza-platobnych-nfc-kariet\\\/#primaryimage\",\"url\":\"http:\\\/\\\/upload.wikimedia.org\\\/wikipedia\\\/commons\\\/thumb\\\/0\\\/0e\\\/PayPass_POS_terminal.jpg\\\/514px-PayPass_POS_terminal.jpg\",\"contentUrl\":\"http:\\\/\\\/upload.wikimedia.org\\\/wikipedia\\\/commons\\\/thumb\\\/0\\\/0e\\\/PayPass_POS_terminal.jpg\\\/514px-PayPass_POS_terminal.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/update-bezpecnostna-analyza-platobnych-nfc-kariet\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/home-new-2025\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"UPDATE: Bezpe\u010dnostn\u00e1 anal\u00fdza platobn\u00fdch NFC kariet\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/nethemba.com\\\/de\\\/\",\"name\":\"Nethemba\",\"description\":\"We care about your security\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/nethemba.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"cs\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#\\\/schema\\\/person\\\/5f4ba68c8e1a2013d30e0804245b8234\",\"name\":\"Pavol Lupt\u00e1k\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"cs\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g\",\"caption\":\"Pavol Lupt\u00e1k\"},\"sameAs\":[\"https:\\\/\\\/www.nethemba.com\\\/\"],\"url\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/author\\\/nethemba-admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"UPDATE: Bezpe\u010dnostn\u00e1 anal\u00fdza platobn\u00fdch NFC kariet - Nethemba","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/nethemba.com\/cs\/update-bezpecnostna-analyza-platobnych-nfc-kariet\/","og_locale":"cs_CZ","og_type":"article","og_title":"UPDATE: Bezpe\u010dnostn\u00e1 anal\u00fdza platobn\u00fdch NFC kariet - Nethemba","og_description":"Zhrnutie Bezkontaktn\u00e9 platobn\u00e9 karty VISA (payWave), \u010di Mastercard (PayPass) patria na Slovensku medzi najpopul\u00e1rnej\u0161ie &#8211; preferuje ich viac ako polovica \u013eud\u00ed (56%). V apr\u00edli 2012 bola na konferencii Hackito Ergo Sum v Par\u00ed\u017ei publikovan\u00e1 prezent\u00e1cia Hacking the NFC credit cards for fun and profit, kde bolo prv\u00fdkr\u00e1t pop\u00edsan\u00e9, \u017ee je technicky mo\u017en\u00e9 plne anonymne a [&hellip;]","og_url":"https:\/\/nethemba.com\/cs\/update-bezpecnostna-analyza-platobnych-nfc-kariet\/","og_site_name":"Nethemba","article_publisher":"https:\/\/www.facebook.com\/nethemba","article_published_time":"2015-02-28T19:32:37+00:00","og_image":[{"url":"http:\/\/upload.wikimedia.org\/wikipedia\/commons\/thumb\/0\/0e\/PayPass_POS_terminal.jpg\/514px-PayPass_POS_terminal.jpg","type":"","width":"","height":""}],"author":"Pavol Lupt\u00e1k","twitter_card":"summary_large_image","twitter_creator":"@nethemba","twitter_site":"@nethemba","twitter_misc":{"Napsal(a)":"Pavol Lupt\u00e1k","Odhadovan\u00e1 doba \u010dten\u00ed":"10 minut"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/nethemba.com\/cs\/update-bezpecnostna-analyza-platobnych-nfc-kariet\/#article","isPartOf":{"@id":"https:\/\/nethemba.com\/cs\/update-bezpecnostna-analyza-platobnych-nfc-kariet\/"},"author":{"name":"Pavol Lupt\u00e1k","@id":"https:\/\/nethemba.com\/de\/#\/schema\/person\/5f4ba68c8e1a2013d30e0804245b8234"},"headline":"UPDATE: Bezpe\u010dnostn\u00e1 anal\u00fdza platobn\u00fdch NFC kariet","datePublished":"2015-02-28T19:32:37+00:00","mainEntityOfPage":{"@id":"https:\/\/nethemba.com\/cs\/update-bezpecnostna-analyza-platobnych-nfc-kariet\/"},"wordCount":2029,"commentCount":0,"image":{"@id":"https:\/\/nethemba.com\/cs\/update-bezpecnostna-analyza-platobnych-nfc-kariet\/#primaryimage"},"thumbnailUrl":"http:\/\/upload.wikimedia.org\/wikipedia\/commons\/thumb\/0\/0e\/PayPass_POS_terminal.jpg\/514px-PayPass_POS_terminal.jpg","articleSection":["Uncategorized @cs"],"inLanguage":"cs","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/nethemba.com\/cs\/update-bezpecnostna-analyza-platobnych-nfc-kariet\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/nethemba.com\/cs\/update-bezpecnostna-analyza-platobnych-nfc-kariet\/","url":"https:\/\/nethemba.com\/cs\/update-bezpecnostna-analyza-platobnych-nfc-kariet\/","name":"UPDATE: Bezpe\u010dnostn\u00e1 anal\u00fdza platobn\u00fdch NFC kariet - Nethemba","isPartOf":{"@id":"https:\/\/nethemba.com\/de\/#website"},"primaryImageOfPage":{"@id":"https:\/\/nethemba.com\/cs\/update-bezpecnostna-analyza-platobnych-nfc-kariet\/#primaryimage"},"image":{"@id":"https:\/\/nethemba.com\/cs\/update-bezpecnostna-analyza-platobnych-nfc-kariet\/#primaryimage"},"thumbnailUrl":"http:\/\/upload.wikimedia.org\/wikipedia\/commons\/thumb\/0\/0e\/PayPass_POS_terminal.jpg\/514px-PayPass_POS_terminal.jpg","datePublished":"2015-02-28T19:32:37+00:00","author":{"@id":"https:\/\/nethemba.com\/de\/#\/schema\/person\/5f4ba68c8e1a2013d30e0804245b8234"},"breadcrumb":{"@id":"https:\/\/nethemba.com\/cs\/update-bezpecnostna-analyza-platobnych-nfc-kariet\/#breadcrumb"},"inLanguage":"cs","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nethemba.com\/cs\/update-bezpecnostna-analyza-platobnych-nfc-kariet\/"]}]},{"@type":"ImageObject","inLanguage":"cs","@id":"https:\/\/nethemba.com\/cs\/update-bezpecnostna-analyza-platobnych-nfc-kariet\/#primaryimage","url":"http:\/\/upload.wikimedia.org\/wikipedia\/commons\/thumb\/0\/0e\/PayPass_POS_terminal.jpg\/514px-PayPass_POS_terminal.jpg","contentUrl":"http:\/\/upload.wikimedia.org\/wikipedia\/commons\/thumb\/0\/0e\/PayPass_POS_terminal.jpg\/514px-PayPass_POS_terminal.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/nethemba.com\/cs\/update-bezpecnostna-analyza-platobnych-nfc-kariet\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/nethemba.com\/cs\/home-new-2025\/"},{"@type":"ListItem","position":2,"name":"UPDATE: Bezpe\u010dnostn\u00e1 anal\u00fdza platobn\u00fdch NFC kariet"}]},{"@type":"WebSite","@id":"https:\/\/nethemba.com\/de\/#website","url":"https:\/\/nethemba.com\/de\/","name":"Nethemba","description":"We care about your security","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nethemba.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"cs"},{"@type":"Person","@id":"https:\/\/nethemba.com\/de\/#\/schema\/person\/5f4ba68c8e1a2013d30e0804245b8234","name":"Pavol Lupt\u00e1k","image":{"@type":"ImageObject","inLanguage":"cs","@id":"https:\/\/secure.gravatar.com\/avatar\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g","caption":"Pavol Lupt\u00e1k"},"sameAs":["https:\/\/www.nethemba.com\/"],"url":"https:\/\/nethemba.com\/cs\/author\/nethemba-admin\/"}]}},"_links":{"self":[{"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/posts\/1561","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/comments?post=1561"}],"version-history":[{"count":0,"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/posts\/1561\/revisions"}],"wp:attachment":[{"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/media?parent=1561"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/categories?post=1561"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/tags?post=1561"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}