
Get every episode summarized
Each time Secrets of Technology publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
About this episode
“If you'd like to support the podcast, please visit gifstarquest.com.”From the transcript
Is waving your card at a register riskier than swiping it? Dom Bettinelli, Thomas Sanjurjo, and Jack Baruzzini explain how NFC and RFID work, where the real weak spots are, and which fears to drop.
The post Invisible Radios: NFC and RFID Myths vs. Real Risks appeared first on StarQuest Media.
Get every episode summarized
Each time Secrets of Technology publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
560 searchable segments. Every word is indexed and playable.
Full transcript
Secrets of Technology — Invisible Radios: NFC and RFID Myths vs. Real Risks. Machine-transcribed; use the interactive transcript above to jump the player to any line.
The Secrets of Technology is brought to you by the StarQuest Production Network and is made possible by our many generous patrons. If you'd like to support the podcast, please visit gifstarquest.com. Hi, I'm Dom Betanelli and you're listening to the Secrets of Technology, where we discuss the technology news that's important to you from a uniquely Catholic point of view. Joining me today on the panel are Thomas Centroho, Hey Thomas, hey Dom, and Jack Bersini, hey Jack, hey Dom, welcome back, it's been a bit. Yeah, glad to have you back whenever you can. So folks today, we're going to be talking about NFC and RFID and some other acronyms probably. We'll explain what all that is. These are the invisible radios in your pocket irradiating you all over the place. But what we're going to do here is actually we're going to discuss
the basics of what NFC and RFID are. We're going to talk about the security risks that might be involved, but also we want to dispel some of the myths surrounding it and things that actually make life better because of these things. In the future, we'll have an episode where we discuss how we can use these in a practical sense, some of the fun ways that you can use NFC around your own home or your office, that's what I think. So let's get into that. I want to start with just a positive question and think thinking your mind. Think of how often you tap with something electronic each day. Your phone at the coffee shop, your badge at the office door, a hotel key, the metro, whether you're on the bus or getting on the subway, your passport has a little card in the back of it with a chip.
These are all basically the same technology, basically, broadly speaking. And most people don't even know what's going on with it. And there's a lot of fear and certainty in doubt surrounding it. And so we'll talk about some of that. But here's a couple of things to know. Like tap to pay has become a big deal last five or six years really in the US in much longer in Europe. And yet people are very afraid of using tap to pay with their credit card. They'd rather swipe it because it feels more secure rather than waving it around the year like a one. But in fact, your credit card when you tap to pay is one of the best protected things you own. Whereas your hotel room door is less so. That'll help you sleep easy next time you go to a hotel. So just keep track of your keys. That's the really big thing. The rest of what we're going to talk about, like even if the key itself is not secure,
getting a copy of that key is not as easy as like the TV shows want to make it look. Right. Right. There have been certain cases where the hotels have left themselves open to being hacked, shall we say. But the big thing is, you know, your biggest sense of protection in a hotel is to physically turn that thing that locks the door when you're inside. That's the big thing. All right. So let's talk about that. What are we talking about? So there's the term RFID, radio frequency identification. That's the broad term for the whole family of devices we're talking about. And it basically the way it works, you have a reader which transmits a signal, a radio field. And then something will have this chip that is not powered, doesn't have any power on its own. When it enters the field, that reader, radio field, energizes it, gives it power,
and it responds and sends a signal, sends data back to the reader. So that's basically how it works. Does that sound about right? I mean, my attractors. Yeah, that's pretty much how it works. Yeah. Okay. I want to make sure I'm getting the right information on it. But what's great about that technology is that it'll last forever because the chip has no battery to go bad. They're the 10-year life on them. In fact, I'm not even sure what would cause them to degrade, I mean, maybe just a grade over time or whatever. It's a really strong magnet. Yeah. It can mess them up. But that can do that. And it's basically a really tiny capacitor that's just getting enough charge from the field to give it enough power to send it back. So they do have a shelf life, but for something like a credit card, you're not going to have a credit card for like 15 years. Right.
Right. It's not really an issue for most of those things. Right. ID badges, that sort of thing. Right. And it's a number of taps, not so much a length of time, although the capacitor can still go bad too. So if you leave it long enough, it would be. It would eventually go bad. But yeah. Yeah. What you're talking about is such a, it's sort of a low tech-ish version of the Wi-Fi charge, or the wireless charge that you have for your phone. So when you put your phone down and there's a field that gets created and it charges your phone, it's a very similar kind of thing. It's just that the battery inside of the RFID is super duper tiny. Right. It's, I mean, it's similar in principle, except at a vastly lower power range, that like I make a way of oven. It just radio waves that energize what it encounters. No, thankfully it's not cooking anything in your pocket. But it's the same principle.
So then you have NFC, which is Stanford Near Field Communications. And that's just a small slice of the whole RFID family. It works at a very specific frequency, 13.56 megahertz. And the, its design is it has to be an extremely close proximity to the receiver to work. That's the whole idea. It needs to be, I think it says a typical range of two centimeters with a certified connection range of five millimeters. Now, anyone who's had to search around on one of those key pads at the checkout looking for a way to put your phone so that it will register, you know, how much on target you have to be with it, how close you have to be. So that's the best, because it's extremely short range, which means you can't accidentally charge, you'll have some charge money on your credit card. You're not going to accidentally activate it unless you put it right up against
whatever it is you're going to use. So that's the basic idea. So that short range is, that's a choice by the designers. It's not an accident or a bug. It's a feature. And then one other part of the RFI inspection that we will be concerned about here is the 125 kilohertz low frequency tags. Those are, if you've ever seen like a big thick white office badge, you know, the kind that you use to check in and out of secure areas, which is a very old technology. It's decades old. That's the other kind. And we'll talk, we'll get to those in a minute. But so basically, this three things an NFC device can do. It can read a tag. It can act like a tag. So when an NFC device, like say your phone, just think of your phone. So your phone can read a tag so you can put it up against an NFC tag that has a chip embedded
and energize it. But it can also act like a tag, which is what's happening when you're using, you know, tap to pay with your phone. Or it could talk to another device. So, you know, if you do ever like not Venmo, Venmo does a QR code. But like there are certain like tap to pay things where you can tap on someone else's phone. Like iPhones can do this. I don't know if Android does, but iPhones can can transfer money between each other. If you've ever transferred your contact information to someone, yes, that's true. Name drop is what they call it on an Apple. Right. It uses, because it's sensitive data that it's sending back and forth, your personal information. So, the important thing here is, isn't the frequencies that are used and that's where things, it's whether the chip is doing any math. And what I mean by that, a chip that
just shouts a number. Oh, I've detected an energy field. Here's my number. That is absolutely not secure. What you want is a chip that runs a challenge in response. Are you, I detect an energy field? Are you the one I'm supposed to be talking to? What's this secret number? And if it gets it right, then it gives a number. So, though, that's the key security difference in the different technologies. How many do you guys? Yeah, that's pretty dead on it. Okay. Okay. So, let's talk about tap to pay then. So, the tap to pay is great because your real credit card isn't on your phone. For instance, Apple says right there in their text specs, they don't store the original credit debit or prepaid card numbers. Numbers are not stored on the phone. The banks, they've, have all got together Visa, a Mascard, and all the banks, they issue device specific device account numbers that live in the
secure enclave on your phone, a secure area that's encrypted on your phone. And I think it's fascinating how they've all worked together to make this happen. This idea of like, okay, so we have your credit card numbers. And those are credit card numbers as we all know are super insecure. It's just a number, a date, and a three-digit code that's securing you. And if someone gets them, you're toast. But they've all worked together to develop this other technology that they all use, which is fascinating. So, that when you, even if the card reader, where you're doing the tap to pay a register, even if it, if someone has something that's intercepting the messaging, it does them no good if they get that number because that number is only good for that one transaction. I think it's fascinating. It is interesting. And I actually had a situation where I had my credit card number still and I had to get a new physical card. But through that whole time where I was waiting
for my new physical credit card number to come, the tap to pay on my phone still worked. And I never had to change the digital number on my, on my phone. So it, I feel like, I feel like we're a finite number of years away from just getting rid of credit card numbers altogether. I think so. And we'd be much better off for it, frankly. I think it goes hand in hand with past keys. You know, when we can get rid of passwords altogether, we'll be much better off. The downside is that phone is going to be so important because it's going to have everything. Yeah. That's the summary we concerned about there. But, but I agree with you. I think we're not long from getting rid of credit cards. And frankly, the banks want to get rid of them because they're such a hassle. They have so much fraud related to them. Imagine you can't give out your credit card number over the phone to someone. How much fraud we could stop just by that. Of course, the scammers will find another way to do this. There's always
there's always social, I love it that even later in this, you know, we've got to we've got an example of social engineering being part of the breaking of this process. Another fascinating aspect to this is they don't need to be connected to the internet to work even. Like if you have an Apple watch that doesn't have cellular and you leave your phone in the car at home, you could still do a transaction at a tap to be terminal. It doesn't need to be connected to the internet. It's whatever. I don't know exactly how the technology works. Some of it is pretty arcane. But whatever they're doing, it's internal to the device in the uncle. In that case, what it's done is it's essentially wrapped your identity into the bucket of your device. And so where you would normally put on your credit card, check ID, and then you would have to show your ID, the assumption is that your Apple watch is locked to you. It's a device that you have.
And so it's got that credential packet kind of put together in it. So it's got both your credit card and the ID to check alongside of it so that when it does the scan, now the scan goes through. And then the other really cool, secure part of it is that when you go to challenge that that charge, so if something went wrong and there were there were reason to challenge the charge, the bank has all the information it needs to say whether or not it was actually you. There's a lot of built-in like, was this person logged in? How were they interacting with their device when the transaction was made? And so they can tell a lot of the state of what was going on during that transaction because it all gets stored as these small packets that get sent back and forth. And it's, I mean, it's, some of it's just really incredible. And I think we're going to get kind of a new wave of it too as they, as they get better and more interested. Now that also comes with a
lot of data collecting and the other side of it. But for now, I really like this system. I think it does a really good job of all of the stuff that needs to do with minimal intrusion. Every cool advance in technology comes along with costs. That is a reality we've all come to realize in the past few years. Something that we've done and this is more related to the, like, the UHF RFID tags and my line of work is, and this is for like acid and inventory tracking, is that we just utilize the, like we program in the data on the tag itself, but it's just a string of numbers. And the only thing it's associated with is our data in our specific databases. So anybody could go in and grab all those RFID numbers, but it's meaningless unless you have the data that it's tied to. So it has a lot of built-in security just from the way it works fundamentally, which is, which is nice.
I saw this YouTuber. He built an inventory system in his basement. He has like a wall of bins and he built a robotic arm that goes and collects bins and he's got a terminal, you know, running the Raspberry Pi that has all the inventory and it knows what's in every bin. And so he types things and the robot arm goes out, reads the, he's got NFC tags on it, reads the tag, grabs the bin and brings it to him, you know, whatever he needs, something out of his inventory. You know, he's basically built, you know, a small robotic warehouse in his basement, which is fascinating. That's a cool use case. And it's a technology too. Like that's the other side of it that, like it is, it is consumer grade. Like it's something that you can get and play with and, you know, and explore and actually make useful things out of. Right. You can go on the Amazon and buy a roll of 50 stickers. They're basically like a roll of
stickers that are NFC tags that you can then program. You can scan it with your phone and say, this is what this tag is. And like on an iPhone, I can attach it to a shortcut. So that when I, for instance, if I sit down at my desk, I can scan the tag with my phone and it will run a shortcut setting up my lights or whatever for the day. That's the possibility of journalists. Or every time I walk in the door, I can scan the tag by the door and it starts playing my favorite music or something. Style voice comes over to all the homebuds. And the nice thing about that is that you can utilize those to build a completely offline smart home. It's not tied to any external services. Yes. Yes. That's the thing we should talk about when we get to talking about practical uses for this in the next episode because that is certainly something worth talking about. So, you know, talking about the tap to paste system. So as we're saying, you know, every tap
has a transaction specific dynamic security code. So this is, this is the security. Now, compare that to the MagStrike, the magnetic tape that's on the back of your credit card that's been on those credit cards for decades. It's basically, it has your number in, you know, open, encrypted. Just, I mean, as clear as it's written on the front of the card, frankly, you know, that's, that's what the, which is why skimmers have worked at gas pumps for 20 years. Right. And why I will never use a credit card in a gas pump again, like I just won't. Like, because even like I used to like, you go in and I grabbed the thing and I'd pull on it to, you know, if it comes off, it means it's a scammer on it. Like the, the card reader, I, like they've gotten better at that and attaching them. So you can't even tell. But if I go up and I tap to pay or actually, I use an app when I go to the local mobile station, I just use their app. I'm at this station. I'm using this pump, charge it to my Apple card,
my Apple Bay. And I don't even have to touch anything, you know, which is, which is better. And then you're so much more secure. So yeah. Well, and RFID chip, the NFC is the better option there because if you tap it and, and they've put a skimmer in between the two of them, you're not going to get gas. The nothing's going to activate. Nothing's going to work. They're not, but they're, but the other side of that is if you tap it and everything works, you know that everything went through correctly and nobody's been able to get that token or your information off of your, your device. And even if they did, they can copy that all day long, but it doesn't do them any good because all it was was this one time click to pay for gas at this particular place with your card at this particular time, at this particular time. And that's it. So there's nothing else to do it. Three seconds later too late. Can't use it. Yeah. Exactly. And one of the changes that we,
that has come about recently in 2024, Apple started opening up that secure element, that secure enclave to allow third party apps to store things in that two. So in addition to credit cards. So car keys, transit passes, corporate badges, student IDs, hotel keys, all that sort of stuff can now go in your wallet on your phone. And I'm sure you enjoy just doing the same thing. So there are cards where you can just go in, sit in your car with your phone and start the car with your phone. No more key. Which, if you're the issue of running out of battery on your phone is real is a real issue. So that's something to consider. But, but even like key fobs now, like there are cars have, they don't have like a literal key. They just have a fob that you carry. And you just have to be in possession of it in the car. That sort of thing. So there, there are NFC sort of things for that too. I may be remembering wrong, but I think on iPhone at least,
they have like when your phone dies, it doesn't really actually completely die. They have like a threshold for it to have some battery. So you can still use like the fine mine stuff. Yeah, I think that's set up so that you can still use like transit passes and things, even if your phone is dead. And house key, I think too. Yeah. Yes. The house key, I actually have a electronic lock where I can use the house key function. And it's so much, it's so cool. It's and I'm actually planning, not in right away, once when the I've got a watch on the on the price to when it comes down. I'm going looking at a one where it does near feel like what do they call it? It's a technology where like as you approach, it recognizes that you're approaching and which direction you're coming from. If you're coming from outside with your phone, it will, you know, in your possession, it will unlock the door as you arrive. But what's that? Is it UWB? Yes. Ultra wide bin. Yeah, UWB. And which is great,
if your arms are full of groceries and you get into the door, you know, you're not fumbling for your phone to push it up against it or try to tap things in or use a key, it's already unlocked when you get there. So that stuff is really cool. Now let's talk about the other side of this coin, the where things are not so good. Hotel keys and office badges. These are problematic. Couple of stories about, you know, some issues that have happened recently. So there was, there's a company called UnsaFlock. They picked a bunch of letters out of a hat made a company name. In March, 2024, researchers found flaws in their brand of locks. I'm not going to try with the names. It's going to be like Scandinavia or something. They look like IKEA brands. They're in their locks affecting more than three million doors at 13,000 properties in 131 countries. Folks, there are not many more countries than that. This is nearly every country. So what you could do is you could read any key card from the property,
including an expired one that you grab out of the checkout box for the hotel, you know, like when you're checking out a hotel, you just throw it in the box. Any key, you could use that to forge a pair of cards that open every room. And the tools are commercially available and all you need is an NFC capable Android phone to write the card. That is a huge security hole. You might as well not have locks on your doors, basically. This was originally reported to the company in September, 2022, made public in two year, almost two year, well, a year and a half later, March, 2024. And 36% of the affected locks were fixed at the time of disclosure, which meant two thirds of all of the locks that were affected by this were still unfixed. And fixing it means updating or replacing every lock, reissuing every key and updating all your front desk software. That's a huge lift for anyone. So that's bad. I think largely it's one of those things where
you have to draw the line between secure and it's there to keep people honest. Like the lock on the hotel door is there to keep people honest. And that's kind of, that's the limit of it, right? There's not really, you can't really expect much more than that. Because they're not spending super high amounts of money on these locks systems and all honesty. Right. I mean, it's probably the equivalent of any sort of traditional lock that would be on any hotel room door. Like it's insanely, if you know what you're doing, it's really easy to pick a lock. Yes. Yeah. So this is why they're, yeah, this is why there are safes and hotel rooms. Right? Yeah. You just have to assume that nothing in your room is super secure. It's like a lot of things in life, car doors, house doors, you know, they are there to keep honest people honest,
but a determined attacker will be able to get through them. That's just the way it is. So same thing with security on phones or computers, you know, that most people have enough security for their needs. Some people need a lot more security. If you are like president of the United States or you know, somebody in his orbit, you need a lot more security around your personal devices than Joe nobody. You know, so that's a good point though. Office badges are in the same boat. The old 125 kilohertz cards had no encryption at all. And so these, according to one researcher, these unauthenticated broadcast identifiers have been considered broken for well over a decade. Reading one and writing a copy takes seconds. So like having it. So basic like office key card or office badge is the same way. Yeah. So that's if yeah, if anyone's interested, there's a great
device called the flipper zero. And it has some some capabilities in this range. And then you can buy dedicated NFC devices too that will do this in just a matter of seconds. And they will often come with like a generic blank card that you can just insert both, pull them both out, drop the original back off with its owner. And then you've got an exact copy of whatever it was that you just walked around with. Right. And they're not expensive. Like none of this is dramatically expensive. Yeah. So for our audience, here's the thing. If you work in a parish, a school, or an office that uses any type of this technology, a lot of schools do these days. Ask your vendor what credential technology your system uses. If they tell you 125 kilohertz prox PROX, that's the broken one. This and that's the thing. There's a there is a solution. They've solved this problem. There are
technologies that there are these these badge technologies that actually are secure. They're out there. It's just a matter of making sure that you're using that one. So it's not a technology problem. It's a procurement problem. You need to buy the right one. So I get some stories about transit cards that come from my hometown here in Boston. We've got something called the Charlie card. I don't know if folks remember ancient folk songs from the 70s, but there was a song called Charlie and the MTA. You never returned. No, we never returned. It's made a student learn to anyway, Charlie and the MTA. That's where we get the name from. So the Charlie card has been hacked twice publicly by students. Boston is also the hometown of MIT. It's going to say this is going to be MIT. So back in 2008, three MIT students prepared a talk or a demonstration for DEF CON. DEF CON is an annual hacker conference that takes place in Las Vegas.
Normal people should stay away from DEF CON wherever it's happening because you'll get hacked. So the MBTA, which is our metro, the mass bay transit authority, sued and got a temporary restraining order against these students to prevent them from giving the talk. A second judge let it expire and they presented anyway. And because they sued that got more attention not less than to the information got out there anyway because you can't sue to stop information. It doesn't work that way. Not with technology. So the hack was that they were able to hack into these stored value cards. That's what a Charlie card is. You put $10, $20, whatever on it and then you can use the card. Again, 2023, four high school students, high school students presented the Boston Infinite Money Glitch. They called it at another DEF CON conference where they fully reverse engineered the fair system and built a portable fair machine where they could get transactions. And their talk
was partly about how to disclose to a government agency without hiring lawyers. In the sense of they're trying to tell them this is how your system is broken. But they are being disincentivized because they're being told if you reveal this information even to us that we'll think you were hacking and therefore we want to prosecute you. Like no, they're like they're white hat hacking versus black hat hacking. Right. White hat hacking is finding vulnerabilities and letting the people know so they can fix it. So the reason it worked was because stored value cards keep the balance on the card. So if you can rewrite the card, you can rewrite the balance. And if the technology for writing that is not good enough. So it took 15 years for them to actually fix that vulnerability. It makes you wonder how many people were silently hacking their cards all that time.
I would imagine probably not enough. I think it's one of those things where it's just like this is something that you really have to be pretty darn nerdy to get into this realm. And even with pirated video games, there's a small sliver of people that are really engaging in video game piracy. And you can prove that by just looking at the video game industry. Right. They're still making billions and billions of dollars. Still making lots of money. Yeah. And the interesting aspect of this is if this were a bank, they would have closed the whole immediately in 2008. Because when a bank loses money, they're losing money. When a government agency loses money, taxpayers losing money. So there's less incentive to admit that there's a hole in your system. So just a little cautionary tale. A few years ago, passports started
including an RFID chip in them so that when you're going through passport control, they can scan them and make sure that they're genuine passports because that's an important security issue. But there was this fear at the time. I remember this. Everyone was like, oh, these are my passport will get hacked or the information on it is too easily. So the chip actually is pretty well designed. In 2008, there was a big scare about it. And people were buying shielded sleeves and stuff like that. But basically, there's an encryption key that's derived by optically reading the machine readable zone. That's the two lines of text at the bottom of the photo page that look like the bottom of your checkbook. That there's no physical access to the printer page and no conversation with the chip. That's the basic access control. That's when they look at it, right? They're not the basically not scanning.
But there's another level in which they do scan. But in general, they're not scanning. But the cover itself is shielded. So when it's closed, you can't scan the chip. It can only be scanned when the book is open. That's an important distinction. And you still have to be you. Like that, I think that's the right. That's kind of the key here. Like you can copy the thing exactly. So if you were able to get somebody's passport, open it, scan it, you can copy the whole thing. But then when you get to the desk, they're going to scan it and look at you and go, you are not this person that's in this passport. And then the whole game's up. So it's not really. The big fear was that someone was standing in line. Someone would brush up against you with a card reader and download your data and spoof your passport. But like you said, like that
your face on the card, you know, like, yeah. Let me tell you, it is really hard to do that. And not be incredibly obvious about it because I have built an NFC reader and getting close enough to someone's NFC card to read out of their pocket. You are going to definitely, you would have to do a little dance, like rubbing your hip against them to try and get the, because you don't know where their phone is. You don't know where their card is in their phone. Be careful in clubs. Be careful. It's strange women in clubs. You would still need, yeah, well, because the device would have to be hidden somehow. There's other realms to that. But like, it's not something that is in any way easy to do. And it's definitely not something that's not obvious. So if you're worried about this kind of stuff, it really is. Like, there's a lot, like just a mat, like you were saying, I'm just imagine how hard it is
for you to get your device in the right spot when you're doing it in the open, obviously. And on purpose, on purpose, and to know what you're aiming for and what you're aiming with. And then just imagine trying to do that blind, seek in secret and without knowing where everything is on either side. Yeah, it's very hard. I'm imagining being like someone out in public in these places and putting an obvious NFC tag hanging off like my bag or something that's loaded with malware. Not that I do that, but that just seems like it would be fun. That's not a bad idea, anyone come up to the scanner. So passports are good. If you change anything on the chip, the digital signature on the chip on it stops matching, invalidates the document, and blocks you out. In the system, that passport becomes invalid. So, yes, the chip can be copied,
byte for byte, but that's really hard to do. That is not a trivial matter. And get that. Without the physical passport and you being you, it's not going to matter anyway. And that's really kind of what we're getting to with this episode is the threat that everyone worried about in this case, which is your passport getting scanned in an airport line. That was engineered out from the beginning. The threat that nobody thinks about, like your hotel door, that's still something to think about. We have to be clear about where the holes in our security are with this stuff. So, I mentioned before, you can buy NFC tags yourself. You can get stickers and cars for just a couple bucks. Any modern phone can write to them, can program them. I was going to say there's things like you could put a tag on your nightstand that turns off all the lights in the house when you put your phone on it. There's, I've seen people who put them on
like a sticker on the charger, like on top of the charge, like the nightstand charger. So, you have like a wireless charger that you put your phone on. They put the sticker right on top of that so that when they put their phone on it, it activates. It's kind of interesting. I'm not sure how, if that magnetic field from the magnetic charger would interfere with the app. I'm wondering how quickly that would burn out the tag. That might be something that would bread it up pretty quickly, but they think about it. But you could also have a tag that works like just has a URL on it or a shortcut trigger or something like that. You do have to be careful of tags in the wild because you never know what's on it. Could be an app or a malicious website with a payload of some sort. Just like QR codes. When you see a random QR code on the wild, you know, consider the source where it is, what it's on. That sort of thing. I wouldn't just scan things at random necessarily. I would enter URLs at random that are sprawled on subway walls.
That's where I think. So, yes, this was a, something I put in the notes. A tag you can't see under a table at a restaurant or on the back of a poster deserves the same suspicion as a QR code and a parking lot. It's the same sort of thing. So, let's talk about real rare risks versus myths. The myth. Someone can walk through a crowd with a reader and drain your card. That's pretty much a myth. The AARP, which has a best interest in this area, they quote, the identity theft resource saying we do not believe this topic addresses a real risk. It's just very theoretical fraud. Advises don't waste your money on sleeves, RFID sleeves, RFID wallets and all that sort of stuff. You need to be like you said, Thomas. You need to be so close. The transaction code is one time
anyway. It's not worth spending money on technology to stop that sort of thing. And similarly, the next one is I need an RFID, brought blocking wallet, which for payment cards, no. If you have an office badge, that 125 kilohertz range, sure. That actually could protect the car, the badge or a hotel key ones that are that are unencrypted. That's what if you have something like that, that might be an argument for that. But really, not for your credit cards, payment cards, that's worth. NFC attacks require exotic hardware, also a myth. A regular Android phone can write a lot of these different cards, RFID. And you mentioned Thomas, the flipper zero. It can read all kinds of stuff. So the attacks are easy. That's misleading
statement. There was a case in 2024 of a malware in the Czech Republic. It required a phishing text, a fake banking app, a phone call from a fake bank employee, and the victim holding their own card against their own phone before an accomplice at an ATM in Prague could really leave the card. A lot of things had to go exactly right for the bad guys are exactly wrong for the victim. It was, it's basically social engineering. Yeah. And there's so many steps there. And if you think about it, even with the most malicious thing I could see somebody doing was setting up some kind of payment system, where they were just going to charge you a random amount of money off of your device. But in order to do that, they have to set up an app that's actually got some kind of financial backing. And then when they do actually scan, there is going to be a data trail for exactly what
happened when and where. Right. It's a bad attack. Like it's a really dumb, like you've just admitted to everyone exactly what you did fraudulently. And the person on the receiving end, if they see a charge that they don't know where it came from, they're just going to report it. And then you're automatically caught out for everything that you've done with that exact device. So right. Exactly. It's a bad. This is why so many scams are trying to move to things like crypto ATMs, which is another topic we really need to talk about. Because it's been big news here where I am. Basically every crypto ATM, so ATM that does cryptocurrency pretty much 90% of transactions are stealing our scam transactions. Not that the guys who only ATM are scammers, but scammers send people to them to then send them money usually overseas. Because crypto is still not traceable, right, or can be untraceable, which is why they love it. So
so. But as far as RFID goes and NFC, the bottom line is the tech, this technology is not what's what where you will get robbed or where you will have your security strip from you. It's the social engineering. It's the phone call. It's the, you know, it's the person who's convincing you to use it in an insecure way. The person who's conning you into thinking that they're trustworthy. That's where you really need to be concerned. The technology itself is not the issue. It's same as it ever was all of human history. It's about untrustworthy people, tricking you into doing something unsafe. Okay. Anything else you guys want to add to that before we move on? I just want to say next time we're at the grocery store, you know, closed shopping, you can just take a look around and see how many RFID and NFC tags that are out there. Because they're absolutely everywhere. And once you start noticing them, it's it's hard to stop. Yeah. Yeah.
I have to say it is interesting how for all the ways that it was negatively affected us. COVID is really, I think, what accelerated the use of NFC payment systems. Before COVID, I would use my Apple Pay and people would be like, Oh, what are you doing here? That's really weird. And then COVID hit and everything was like, don't touch anything. And so now everybody knows. It's weird. Now it's weird when you have a place where it's like, no, I have to stick my credit card into that thing. That's bizarre. Why am I doing that? I'm always free to see people who are cashed to other people. Walmart's finally jumping on the jumping on that after years, which I don't go to Walmart because of that. Yes. Right? Whenever I've had to go to Walmart, it's so frustrating. I'm like, Oh, yeah, you. They're finally adding it though, thankfully. Yeah. Welcome to the 21st century, Walmart. All right. So we'll have a ton of links in the show notes. Everything we talked
about, including links to some of the stories of the hacks and various things. So be sure to check those out. Before we move on, I want to take a moment to thank our patrons who make it possible for us to create the secrets of technology, including, let's see, this right. Kapuna, Haley, W. Hawaiian, maybe. Diana L. Paul E. Robert B. and Alfred O M. They're generous donations at givestarquest.com. Make it possible for us to continue the secrets of technology and all the shows at StarQuest. And you can join them by visiting givestarquest.com. I love the variety of names that are patrons. They come from all over. So we're going to move on to our picks of the week. And Jack, why don't you go first? What's your pick this week? My pick of the week is something very practical and boring. I keep trying to find a good, comfortable Apple Watch band for like exercising that doesn't have those weird little
metal magnetic clasps that not really give me a rash. And I found a pack on Amazon. Of course, the company is one of those no-name companies. DeKeen, I think is how you probably say it. But this is a three pack of stretchy nylon Apple Watch bands. It's like eight bucks in a bottom and I've used them for months. And they're really comfortable and cheap. And I think that's the best thing you can find for something like that. That is great. Yeah. A $6, $8, $9, Apple Watch band that lasts for six months or whatever is I think perfectly fine. I think it's amazing to see the market for this sort of thing of that. I'm still using the band that came with my watch. I like the... I've had so many different bands over the years, but I've kind of settled on just the stretchy fabric one. Yeah. Yeah. Comfortable. All the silicon ones they have are like rash inducing in a very, very serious way. Like it's bizarre how uncomfortable they can get.
Yeah. I think, yeah, I really like the cloth ones, the braided nylon even sometimes those are nice. I had a nice Grogu in the Mandalorian one a few years ago, which was fun. That's cool. Excellent. Good pick of the week. Thomas, what's your pick this week? All right. So mine is this weird app. It's called What Three Words. And essentially what they've done is they've taken the entire surface of the earth and broken it up into three meter squares. And they've given three words that identify each and every one of these squares throughout the entire world. And so no matter where you are, you'll fit into one of these little squares. And you can tell your precise location within three meters to anyone using their app. So if you've ever been in a situation where you're like trying to explain to somebody where you are for them to be able to find you and you're in a crowd and they're like looking around and can't... You could just pull this
app up, tell them to pull the app up, give them your three words, and then they could walk directly to your location. Obviously it assumes that the GPS is accurate enough to get you in that range, but even without that, it is really... It's wildly accurate how it puts you on the map and has you within this little grid. And then you do... I mean, like you think about trying to explain your location to someone or trying to give them GPS coordinates, which nobody knows what those mean at all, and trying to even enter in GPS coordinates as impossible. So just giving them three regular, everyday English words that sound bizarre in sequence, but are easy enough to remember and to transmit to someone. And then they can just enter it into the app and find exactly where you are and get to you. Great little app, especially if you're an outdoors person and you want to go exploring and want to make sure that you can be found if something were to go wrong. Definitely
a good way to do it. I'm tempted to tell everyone what my... this rooms... three words are, because they're cool, but I'm not doing that. That's the thing I don't share your exact location with people that you don't want to share your exact location with. Exactly. I know that in certain there are certain locations where emergency services are using this. Yes, this app. And it's really cool. So yeah, it's three words. Bob, Uncle, Red, Bob, Uncle, Red. That's where I am in this one spot, this building in this location. Now obviously it doesn't do altitude. So if you're in a multi-story building, I think that's... You still got to find them wherever that is, but especially outdoors. It's a really great tool. What one interesting function that I found for it is I have
VPNs that I have that I use when I'm jumping on the internet. And if I go to the what three words site, it captures the exact three meters in which my VPNs. That's pretty cool. That's pretty cool. Excellent. That's a good one. And it's free for... Yes, yes. This is a pro. I'm not sure what the pro gets you. I'm sure it's a corporate. It's kind of interesting because it's like for businesses. So you can, you know, directly locate where you're delivering something to somebody. And so you can share with them without having to use the three words thing. It gives you a way to share a precise location with somebody or give them an easy way to share their precise location with you. That's a good idea. Yeah. Especially if you're like in an office park or a big complex, like delivered to this door. Well, which door? And here's the three words. Exactly. Here's the actual three words that will get you there. Yeah. Excellent. So my pick this week is a security cam. I've recently upgraded my home security cameras. And I've settled on the anchor
UFI cameras. And partly because I'm in the bag for anchor. But I mean, they're not giving me anything, but I just I buy everything get it anchor on it. But because these do not require the cloud, these are offline. They have some outdoor cameras. And they have also the indoor cam E220. This is a pantil scan. So it turns and up and down does day and night. So it can in the dark, does infrared night vision. It can do 2k resolution. And it connects to what I have is a it's called the home base. And it's it's got a the home base has a hard drive or SD card storage in it. And it stores all of the video footage from my security cameras in it. So none of it goes out in the internet. Like I can access it from an app, but it's not being stored in someone's cloud. Put it that way. And it has like it can do like person tracking. So I can set it up so that at certain
time of the day, like at night when I'm sleeping, if someone enters into my office, it tracks them and you know, records who who's in my office, which is usually my daughter gets up in the middle of the night wonders around the house. I don't know why, but she does. I've faster. But now the camera tracks her and she thinks it's creepy. So she doesn't come in here anymore. But it's it's a their decent cameras. It's USB power and they connect via Wi-Fi. And you know, if you buy one, it's $15 about $55 for the camera. So not too expensive. And that's the outdoor ones have solar. Yeah, the outdoor ones have solar panels on this. Yes. I have the outdoor ones. And the solar ones work really well. I'm kind of curious how they'll do in New England winter because of the the shorter, sudden day. But but over the summer, they they they never would drop below 99% charge. I mean, they they really hold a charge. You can really kill them if you turn on all of the AI
tracking features and stuff, which I try not to do. Because then it's also recording everything all the time and alerting you. It happens a day. So that's my pick. And I'll I'll I'll I'm sure I'll talk about those cameras in the future if I haven't yet. Those are probably on my list. So those are our picks of the week. And that's our show we'd love to get your thoughts on anything we've discussed this time. You can do that by sending us an email to technology at sqpn.com. Visit the StarQuest Discord community at sqpn.com slash discord. You can find links from our discussion and our picks of the week on our show notes at starquest.fm slash tec361. You'll find previous episodes at sqpn.com slash technology. And be sure to follow the secrets of tech and Apple podcasts, Spotify, tune in your favorite podcast app or at our YouTube channel where you should make sure to hit the bell to get notifications and our channels at youtube.com slash starquest media.
And we always appreciate it with a if you read a nice five star review in Apple podcasts or anywhere you can write reviews of podcasts and share the show with somebody help them learn about what we do. Until next time Jack Barrazyne, thank you for joining me in sharing the secrets of technology. Thanks Tom. And Thomas Center Ho, thank you as well. It's been great. And once again, I'm Don Betanelli. Thank you for listening to the secrets of technology on StarQuest. Hey friends, a quick request before we go. StarQuest is running a short survey and we're not asking you for money. We're asking you what to make, what to give you, whether you support the network or just listen, we want to know which extras you care about and what we should try next. Livestreams, Q&As, behind the scenes stuff, that kind of thing. It's anonymous and it takes about five minutes and it's open until September 29th. You'll find the link in the show notes or go
to starquest.fm slash survey 2026. Here's another show on the Starquest network you're sure to enjoy. The Catholics of Oz find it wherever find podcast or found or at sqpn.com slash auz.
More episodes
More from Secrets of Technology

Apple Unfolds Their New iPhone Future
Secrets of Technology

Announcing Holy Troublemakers
Secrets of Technology

Stop Deleting Your Photos First: The Real Phone Storage Fix
Secrets of Technology

Friction Maxxing: The Internet Rediscovers That Struggle Is Good for You
Secrets of Technology