Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm 90% sure that NFC on a card can't do any kind of dynamic token generation, so it'd be the same token every time. Even if it isn't your actual credit card number, that would mean you could at least use a copy of it at other contactless terminals.


That's Static Data Authentication. Dynamic Data Authentication is also a thing - the recommended thing nowadays, actually. Check it out https://www.openscdp.org/scripts/tutorial/emv/DDA.html

These schemes are independent of physical transfer mechanism (well, mostly)

Edit: https://en.m.wikipedia.org/wiki/Contactless_smart_card you might be talking about MSD while I'm talking about EMV. C'mon, America, you're better than that




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: