forked from L1L1/cardpeek
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
ipamo
committed
Dec 12, 2018
1 parent
92b5a37
commit 48faceb
Showing
15 changed files
with
98 additions
and
25 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
File renamed without changes.
File renamed without changes.
File renamed without changes.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,21 @@ | ||
# How can I read the contents of my EMV bank card? # | ||
|
||
![http://cardpeek.googlecode.com/files/sample-emv.jpg](http://cardpeek.googlecode.com/files/sample-emv.jpg) | ||
|
||
The "emv" script in **cardpeek** provides an analysis of EMV banking cards used across the | ||
world. | ||
|
||
# Notes # | ||
|
||
This script will ask you if you want to issue a Get Processing Option (GPO) | ||
command for each application on the card. Since some cards have several applications | ||
(e.g. a national and an international application), this question may be asked twice or | ||
more. This command is needed to allow access to some information in the card. Issuing this command will also increase an internal counter inside the card (the ATC). | ||
|
||
# Notes on privacy # | ||
|
||
You will notice that many of these bank cards keep a \transaction log" of the last | ||
transactions you have made with your card. Some banks cards keep way over a hundred | ||
transactions that are freely readable, containing the date, the amount and the country of the transaction, which brings up some privacy issues. Why do banks need to keep so much information in the card? | ||
|
||
The security elements in the card, such as the PIN and the cryptographic keys are fully protected in the card and cannot be read. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,21 @@ | ||
# How can I read the contents of my EMV bank card? # | ||
|
||
![http://cardpeek.googlecode.com/files/sample-emv.jpg](http://cardpeek.googlecode.com/files/sample-emv.jpg) | ||
|
||
The « emv » script in **cardpeek** provides an analysis of EMV banking cards used across the | ||
world. | ||
|
||
# Notes # | ||
|
||
This script will ask you if you want to issue a Get Processing Option (GPO) | ||
command for each application on the card. Since some cards have several applications | ||
(e.g. a national and an international application), this question may be asked twice or | ||
more. This command is needed to allow access to some information in the card. Issuing this command will also increase an internal counter inside the card (the ATC). | ||
|
||
# Notes on privacy # | ||
|
||
You will notice that many of these bank cards keep a \transaction log" of the last | ||
transactions you have made with your card. Some banks cards keep way over a hundred | ||
transactions that are freely readable, containing the date, the amount and the country of the transaction, which brings up some privacy issues. Why do banks need to keep so much information in the card? | ||
|
||
The security elements in the card, such as the PIN and the cryptographic keys are protected in the card and cannot be read. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,15 @@ | ||
Comment lire le contenu de son Pass Navigo ? | ||
============================================ | ||
|
||
![sample-navigo.jpg](sample-navigo.jpg) | ||
|
||
Le script "calypso" inclu dans **cardpeek** permet de lire le contenu des cartes "Navigo" utilisées en région parisienne. Cet outil offre une analyse améliorée des "journaux d'évènements" de la carte affichant notamment le nom des stations de métro/RER où la carte a été utilisée. Cet outil a été testé avec succès sur les cartes Navigo Découverte, Navigo et Navigo Intégrale. | ||
|
||
## Notes | ||
|
||
Il faut utiliser **cardpeek** avec un lecteur de carte à puce à contact pour lire le contenu d'une carte "navigo" (ou un lecteur sans contact spécialisé). En effet, les cartes "navigo" ne peuvent pas êtres lues avec des lecteurs sans contact _classiques_ (car elles utilisent un protocole de communication radio qui n'est pas totalement compatible avec l'ISO 14443 B). | ||
|
||
## Protection de la vie privée | ||
|
||
Ces cartes de transport conservent un "journal d'évènement" décrivant les 3 dernières validations effectuées par le porteur de la carte. Ce journal, qui peut poser un risque pour la protection de la vie privée, n'est pas protégé en lecture. | ||
Par contre le nom du porteur de la carte n'est pas, selon nos analyses, accessible en lisant la carte. En revanche, c'est le cas pour la carte MOBIB utilsée à Bruxelles. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,15 @@ | ||
How to read the content of your Navigo Pass? | ||
============================================ | ||
|
||
![sample-navigo.jpg](sample-navigo.jpg) | ||
|
||
The "calypso" script included in **cardpeek** can read the content of Navigo cards used in Paris. It provides enhanced "event log" analysis notably with subway/train station names, as illustrated in the screenshot above. It has been successfully tested on Navigo Découverte, Navigo and Navigo Intégrale cards. | ||
|
||
## Notes | ||
|
||
You must use the contact interface to read a Navigo card (or a special contactless reader), because they cannot be read with a normal conctactless card-reader (these cards use a specific protocol that is not fully compatible with ISO 14443 B). | ||
|
||
## Privacy notes | ||
|
||
These transport cards keep an "event log" describing at least 3 of the last stations/stops you have been through. This "event log", which could pose a privacy risk, is not protected by any access control means and is freely readable. | ||
Note however that your name does not appear on the card (to our best knowledge), as opposed to the MOBIB card in Brussels. |
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.