iCard BlogiCard BlogiCard BlogiCard Blog
  • Go to iCard.com
  • English
    • English
    • български
    • Italiano
    • Română
Next Previous

How Safe are NFC Wearables & Contactless Cards?

Pavel Panayotov 5 July, 2019

We are happy to let you in on our Limited series NFC wearables that work exactly the same way as a standard contactless debit card.

Our NFC wearables are payment gadgets that can be connected to one of your payment accounts and only work with iCard’s digital wallet. Having one of our NFCs for yourself enables you to spend your money at Millions of retailers around the globe. 

 

What is NFC?

 

The term NFC is short for Near Field Communication. The technology is tiny in size and enables two devices communicating from a short distance – no-contact at all – approximately 2 centimetres away.

NFC tags and NFC readers can exist separately or together – as in your NFC-enabled phone – to function as a tag when paying or to function as a reader when getting paid.

Battery-Independent tag technology is making them very accessible and widely adopted. Now, contactless is a standard feature of bank and non-bank cards. Anything can be tagged with an NFC and scanned.

You can scan a lot of NFC tag types with your phone’s module or other readers – payment tags, entry cards, passports, transport cards, logistics and warehouse tracking, reward cards, library cards.

If you are the tech type – you can do all sorts of crazy and fun things with programmable NFC modules. For example, you can use tags to make contactless switches. You can have these little pieces installed in your smart home and just getting your phone near can control all sorts of connected things.

You can also have your phone’s NFC scanned for example when you are making a payment with your mobile device.

And of course, you can have your payment information in different tags – controlled by an app and used for payment almost anywhere.

 

iCard’s NFC key fob

 

NFC key fob

 

The latest addition to your iCard payment toolset is a small & stylish key fob that can keep your money safe and you can pay by tapping it at contactless POS terminals. Activating one, connecting it to any of your accounts and using it to the fullest requires you to be on the free Standard plan. All it takes is a quick video identification chat.

In the safety context, we need to answer this question for you: “What happens if I’m in public transport and someone scans my cards out of my wallet in my pocket?”

This curiosity will remain, just as it was probing the first contactless payment cards before they got into mass adoption.

Let’s explore how safe NFC payments are really.

 

The trade-offs for getting a payment done in 5 seconds

 

Contactless payments are not 100% secure, BUT …

They are secure enough even without the additional security steps that iCard provides.

First of all, there are store guidelines and you as a customer should be aware of them – conscious consumers for example never hand out their contactless cards.

Why would they call it contactless otherwise?

It’s like handling cash money – you should be cautious and use common sense to stay safe.

“But if I lose my card, people who find it can buy stuff!”

Same will happen if you lose your cash, BUT it won’t happen if you lose a magnetic stripe card or a chip card.

Yet, contactless payments feel safe AND THEY ARE FASTER THAN CASH.

That is the trade-off and consumers in some European countries like the UK have voted “FOR” with their contactless cards to risk it for the sake of convenience.

 

[Update: As of September 2019, every 6th PIN-less, contactless transaction under 25 Euro will require a PIN.]

 

So, can a hacker scan my NFC debit card or wearable and buy stuff with my money?

 

When was the last time you heard someone’s card was copied and used to pay at shops?

I haven’t.

Yet, there are cases.

Let me brief you on the different layers or levels of defence that you get when using contactless payments.

 

layers or levels of defence

 

DISTANCE: 1st level of defence

NFC cards or tags only get powered and active at very short distances. This allows owners to control their risks by controlling who is within their personal space. Entering a PIN for NFC transactions turns it to a contact payment, but your PIN usually remains safe because the POS terminal is right next to you at checkout. The UK Mirror reports there is card cloning risk:

Card skimming has also been known to occur in restaurants and bars, where waiters illegally tap cards while processing payments. Often they’ll have the devices hidden in sleeves, towels and aprons. During this process, they’ll gather details (but not your CVV number at the back) and trade them overseas for cloning.

This can happen when you, as a cardholder, are not careful and instead of just tapping your contactless card or NFC wearable at the terminal, you pass it on to someone else to handle. DON’T do that!


LIMITS: 2nd level of defence

Your NFC keychain, just like your iCard Visa debit card, has a limit on retail transactions you can make without a PIN. Depending on your country, the limit is 25.00 to 50.00 Euro (or it’s rounded up/down equivalent in another European currency). In addition, you can’t be billed twice if you tap twice on the same POS terminal.


ENCRYPTED: 3rd level of defence

Just like chip cards, contactless cards send out a transaction with a one-time code that protects your information and is decrypted by the payment processor – Visa, Mastercard, etc.

Chip+PIN, by the way, is much safer for ATM money withdrawals, because chip can’t be cloned easily as is the case of magnetic stripes.


REAL-TIME: iCard’s additional level of defence

iCard gives you instant payment notifications and freeze/unfreeze options. In the case of a lost contactless payment card or wearable, you can immediately block their use through your iCard digital wallet app. This gives you more responsibility and control when you actually need to prevent theft. With this last level of defence in your own hands, it’s only fair to say that you bear the responsibility to protect and block your money immediately if need be.


If you want maximum security
, you can always use a radio frequency shielded wallet or sleeve protector for your NFC tags & contactless cards.

 

Cool, how can I get my own NFC wearable?

 

You can get a FREE NFC wearable by joining our “#KeepTapping with Friends” program. 

We are making the iCard NFC wearables available for those of you who want just another option for frictionless payments and for those of you who are on iPhone and who are limited to Apple pay only, which is not widely available.

 

Download iCard today!

11

Pavel Panayotov

As a Communication Manager, Pavel is engaged with creating user journeys and presenting iCard to the world. Contributions include education, activation and engagement strategies, as well as unified cross-channel product and brand awareness campaigns. In his free time, Pavel enjoys keeping up with innovations, marketing trends, friends, family and nature.

More posts by Pavel Panayotov

Leave a Comment

Cancel reply

Your email address will not be published. Required fields are marked *

  • You may also like

    Hello and Welcome to the iCard Blog!

    Read now
  • You may also like

    Business Breakfast with iCard – Do Digital Wallets Have a Future in Bulgaria?

    Read now
  • You may also like

    How Virtual Cards Help You Stay Safe When Shopping Online?

    Read now
  • You may also like

    How SEPA vs SWIFT International Money Transfers Work Behind The Scenes

    Read now
  • You may also like

    The Ultimate Guide to Turning Money Into The Perfect Gift for Every Occasion

    Read now
  • You may also like

    7 of The Most Interesting and Sometimes Controversial New Year’s Eve Traditions Around The World

    Read now
  • You may also like

    “Cash Not Accepted” – 3 Awkward Money Situations to Avoid With a Free Visa Debit From iCard

    Read now
  • You may also like

    2018 Year in Review – Sharing The iCard Journey With You!

    Read now
Copyright © iCard AD 2022 | All Rights Reserved | Privacy Policy
  • Go to iCard.com
  • English
    • English
    • български
    • Italiano
    • Română
iCard Blog
logo
Cookie settings
We use "cookies" when you visit our website to provide you the best user experience. We give you the full opportunity to choose what information you would like to share with us, and you can control this by using the buttons on the right side of the page.
Necessary Cookies

These cookies are required in order to allow you to move throughout the website and use its functionalities, such as accessing secure areas of the website. Without these cookies the services you have applied for cannot be provided. These cookies are activated when you visit our website and remain active for the duration of your visit. These cookies allow us to provide you our service.

If you disable this cookie, we will not be able to save your preferences. This means that every time you visit this website you will need to enable or disable cookies again.

Statistical cookies

These cookies collect information about how you as a visitor use our website. For instance, which pages visitors go to most often and if they get error messages from web pages. This data in aggregate form is used to improve our websites and apps. This data is also used to identify whether customers may have specific interests needs based on pages they have visited within our websites/apps. These cookies allow us to provide you our service better.

Please enable Strictly Necessary Cookies first so that we can save your preferences!

Cookie Policy
What are cookies?

We use “cookies” and other technologies when you visit or use our websites or mobile apps. In this document you may find more information and details on about the cookies and the similar technologies as well as how to control them.
General information on cookies can be found here: http://www.allaboutcookies.org/

Use of Cookies
Our websites (including mobile) use cookies and similar technologies, which you can control in accordance with the present policy and the functionality of the websites. This policy applies additionally to any other Legal agreement, terms and conditions or contract provision for the iCard service being used by you. If you do not accept the use of cookies, please disable them by using the control panel (which loads when opening the websites).

Can I withdraw my consent (where applicable) to the use of cookies and similar technologies?
If you no longer consent to the use of consent-based cookies and similar technologies, please delete the cookies via your browser settings or use the control panel (which loads when opening the websites) . There is a brief instruction further in the policy below and you can find further information on deleting and blocking cookies here: http://www.aboutcookies.org/how-todeletecookies/

What are cookies and similar technologies?
Cookie is a small text file that a website saves on your computer or mobile device when you visit the site. It enables the website to remember your actions and preferences (such as login, language, font size and other display preferences) over a period of time, so you don’t have to keep re-entering them, whenever you come back to the site or browse from one page to another. Cookies are generated by the server of the visited website when the browser of your device loads it. The website sends information to the browser and creates a text file. Each time the user returns to the same website, the browser extracts this text file and sends it to the website’s server. The information that the cookie contains is specified by the server and may be used by the latter when the website is visited again by the user.
We use cookies to achieve different tasks such as like letting you navigate between pages efficiently and easily, remembering your preferences and generally improving your experience when browsing. We also use them to ensure that any ads you see on our websites or mobile apps and ads of other third-parties are more focused to you and your interests.
We also use similar technologies such as ‘pixel tags’ and ‘JavaScript’ to undertake these tasks. Pixel tags and JavaScript are tiny graphics files that contain a unique identifier that enable us to recognize when someone has our websites or mobile apps. This allows us, for example, to monitor the traffic patterns of users from one page within our websites or mobile apps to another, to provide or communicate with cookies, to understand whether you have come to our websites or mobile apps from via online advertisement displayed on a third-party website, to improve site performance.
If you visit our websites or mobile apps, we will deploy cookies and similar technologies to design an online service more suitable for your device, as well as to prevent and detect fraud. When you visit our website from any device we collect information about your use of the particular website, such as information about the device or browser you use to access the site (including device type, operating system, screen resolution, etc.), the way you interact with this site, and the IP address your device connects from. In many cases, the above said technologies are relying on cookies to function properly, and so declining cookies will impair their functioning, which means that you may not be able to exercise some activities within our secure online services unless these cookies or similar technologies are installed. Additionally, there might be a chance that we may not be able to process certain transactions if you are physically located in certain countries.
Cookies set by us are referred to as "first party cookies". Cookies deployed by parties other than us are called "third-party cookies". Third party cookies enable third party features or functionality to be displayed on or through the website/app. The parties that set these third-party cookies can recognize your computer both when it visits the website in question and also when it visits certain other websites.
We may not influence or control over third-party cookies. If you would like to find out more about the types of cookies which may be downloaded as a result, please visit the website of the third-party provider to do so.

Types of cookie inserted
There are different types of cookies which are usually split into the following categories, but note that not all these types will be used on our website or mobile app:

Necessary cookies
These cookies are required in order to allow you to move throughout the website and use its functionalities, such as accessing secure areas of the website. Without these cookies the services you have applied for cannot be provided. These cookies are activated when you visit our website and remain active for the duration of your visit. These cookies allow us to provide you our service. The use of these cookies is based on the legal basis of providing you access to our website and therefore are always active

Statistical cookies/Third-party cookies
These cookies collect information about how you as a visitor use our website. For instance, which pages visitors go to most often and if they get error messages from web pages. This data in aggregate form is used to improve our websites. This data is also used to identify whether customers may have specific interests needs based on pages they have visited within our websites. These cookies allow us to provide you our service better and are therefore based on our legitimate interests.

Functionality cookies
These cookies allow our website to remember choices you make and provide high level of personal features. These cookies can also be used to remember changes you have made to text size, fonts and other parts of web pages that you are allowed to customize. The information these cookies collect may be anonymized and they cannot track your browsing activity on other websites. These cookies memorize your preferences in order to provide you with the full functionalities of our website, and are therefore based on our contractual obligations towards you.

Cookies in Emails
We use cookies and similar technology in some of our emails which contain hyperlinks, each of which has a unique tag. They help us to understand a little bit about how you interact with our emails, and are used to improve our future email communications to you. If you click on links contained in this email it will allow us to track your use of our website and enable us to show content and offers of most interest to you.
These cookies are based on our legitimate interests for optimizing our marketing, promotion and similar activities.
If you do not wish to accept cookies from any one of our emails, simply close the email before downloading any images or clicking on any links. You can also set your browser to restrict cookies or to reject them entirely. These settings will apply to all cookies whether included on websites or in emails.
If you have configured your computer to automatically display images, or if you have added us to your email "address book" (or "safe senders" list), or if you have configured your computer to have "weak" security, cookies might be set at the same time as you download, open or read an email from us. If you would prefer for this not to happen, you should disable the automatic displaying of images, or remove us from your address book or strengthen your security settings.

How to control and delete cookies through your browser
The ability to disable or delete cookies can also be carried out by changing your browser’s settings. In order to do this, follow the instructions provided by your browser (usually found in the ‘Help’, ‘Edit’ or ‘Tools’ facility). Some pages may not work if you completely disable all cookies, but many third-party cookies can be safely blocked. If you do switch off cookies at a browser level, your device won't be able to accept cookies from any website. This means you will struggle to access the secure area of any website you use and you won't enjoy the best browsing experience when you are online.

Types of Cookies used for iCard website:
Below is a list of the types of cookies and similar technologies that we use in our website and mobile application along with instruction as to how they may be disabled.
Complete list with cookies can be found here:

NameExpirationDescriptionCategory
__cfduid5 yearsCookie assoiated with sites using CloudFlare, used to speed up page load times. According to CloudFlare it is used to override any security restrictions based on the IP address the visitor is coming from. It does not contain any user identification information.Necessary
_ym_isad2 daysDetermines whether a user has ad blockersStatistical
_ym_uid1 yearUsed for identifying site users
_ym_dStores the date of the user's first site session
yandexuidUsed for identifying site users
i
yabs-sidUntil the session endsSession ID
yp10 yearsSets a unique ID for the session. This allows the website to obtain data on visitor behaviour for statistical purposes.
_gaexpDepends on the length of the experiment but typically 90 days.Used to record a person’s involvement in a website experiment e.g. an A/B test where half of our website users see one webpage, and the other half see an alternative version.
This helps us test that the changes we make to our site are actually making it better.
Statistical
_gcl_au3 monthsUsed by Google AdSense for experimenting with advertisement efficiency across websites using their services.
ajs_anonymous_id1 yearThese cookies are generally used for Analytics and help count how many people visit a certain site by tracking if you have visited before.
ajs_group_idThese cookies track visitor usage and events within the website.
ajs_user_idThis cookie helps track visitor usage, events, target marketing, and can also measure application performance and stability.
hubspotutk13 monthsThis cookie is used to keep track of a visitor's identity. This cookie is passed to HubSpot on form submission and used when deduplicating contacts.
intercom-id24 hoursThis cookie is used by Intercom as a session so that users can continue a chat as they move through the site.Statistical
intercom-sessionUsed to distinguish users
mp_hj_mixpanel1 yearThird-party cookies used to track visitors and collect information about how visitors use our site. We use the information to compile reports and to help us improve the site. No personally identifiable information is stored. The cookies collect information in an anonymous form, including the number of visitors to the site, where visitors have come to the website from, and the pages they visited.Statistical
fuid01These cookies compile anonymous information on users’ browsing on the website in order to know the origin of the visits and other similar statistical data. These cookies do not identify the user or compile any type of personal information.Statistical
IDE2 yearsGoogle also use one or more cookies for advertising we serve across the web. One of the main advertising cookies on non-Google sites is named ‘IDE‘ and is stored in browsers under the domain doubleclick.net. Another is stored in google.com and is called ANID. We use other cookies with names such as DSID, FLC, AID, TAID, and exchange_uid. Other Google properties, like YouTube, may also use these cookies to show you more relevant ads.Statistical
_ga_gat3 monthsThese cookies are used to collect information about how visitors use our Site. We use the information to compile reports and to help us improve the Site. The cookies collect information in an anonymous form, including the number of visitors to the Site, where visitors have come to the Site from and the pages they visited. If you do not allow these cookies we will not be able to include your visit in our statistics. You can read the full Google Analytics privacy policy at: http://www.google.com/policies/privacy/.
_gid
1P_JAR
APISID
DV
HSID
NID
SAPISID
SID
SIDCC
SSID
UULE
__hssrcSessionWebsite usage statistics
__hstc2 yearsWebsite usage statistics
muc2 yearsUsed to facilitate Twitter functionality on our website and to:
- track user behaviour
- deliver and measure the performance of advertising
- enable sign-in
- personalise the Twitter experience across devices.
Statistical
ads_prefs
auth_token
csrf_same_site
csrf_same_site_set
dnt
eu_cn
external_referer
guest_id
kdt
personalization_id
remember_checked_on
tfw_exp
twid
act3 monthsYou have a Facebook account, these cookies will allow you to share content on the Inflectra site with your Facebook contacts. You will be also able to tell if you or your Facebook friends 'Liked' any content on the Inflectra site in the past. The cookies will also send some non personal data to Facebook to gather aggregate information on how people interact with websites that use the Like button.Statistical
c_user
datr
fr
locale
pl
presence
sb
spin
wd
xs