sweet
HN user
samyk
samy kamkar https://samy.pl
[ my public key: https://keybase.io/samy; my proof: https://keybase.io/samy/sigs/mulP3pEgZ_y5ujRQJiX7DY9X-S9NytWV08B744Yw3RA ]
Yup, however Samsung Pay/LoopPay keep the chip bit meaning you need to bring your cards with you when they require Chip, where MagSpoof can disable the bit, allowing you to leave your cards at home.
Hi windexh8er, I choose this hardware because it's portable and convenient. It would technically be much easier to carry out this attack with something like rfcat via yardstick one, hackrf, etc, but I didn't want a USB based device and no need to build my own device when something existed with everything I needed! And did I mention it's pink?
Hi lukeholder, the screen resolution is "tied" to how quickly the mouse moves, so no matter which screen resolution you choose, the mouse will always move to the right location.
Hi totony, unfortunately with the way our systems are designed today, it's typically trivial to usurp admin later on when the user escalates privileges, even after the USB device has been removed. Examples such as injected LD_PRELOAD, adjusting PATH to MITMA sudo, etc.
In my example, we interestingly see how by default, OS X does not require additional permissions in this unique scenario. Crazy!