salmg/academy
Sign in

Payment Systems: Magstripe, Tokenization, NFC and EMV

The 16-hour course taught at Black Hat, DEF CON and Troopers, extended to cover what changed since.

Level 1

Foundations

  1. 01

    The fundamentals: how a transaction is verified and processed against the terminal, why the APDU protocol is not encrypted, and what protects the transaction instead.

    Read the module
  2. 02

    The laboratory: how it is organised, how to navigate it, and which tool suits each payment technology.

    Read the module
  3. 03

    Track encoding and the security thinking of the era — the ideas every later technology is a reaction against.

    Read the module
Level 2

Practitioner

  1. 04

    The APDU protocol end to end: packet generation, commands, responses, and the structure at the core of every transaction.

    Read the module
  2. 05

    Contact transactions and the advanced APDU mechanisms behind them, including emulating EMV data with dedicated hardware.

    Read the module
  3. 06

    NFC transactions in detail: APDU exchanges, cryptogram analysis, and cardholder verification methods.

    Read the module
  4. 07

    The opposite of static magstripe data: seeding and encryption for token generation, and how digital wallets implement it.

    Read the module
  5. 10

    DPAN versus FPAN, the Token Service Provider role, wallet provisioning and identification & verification, the token cryptogram, and Click to Pay.

    Read the module
  6. 14

    Pix, UPI, FedNow, SEPA Instant and EMVCo QR — static versus dynamic codes, and the fraud that followed the money out of the card rails.

    Read the module
  7. 15

    Scoping, segmentation and what an assessor actually looks for — framed for someone attacking the environment rather than documenting it.

    Read the module
Level 3

Operator

  1. 08

    Reversing transactions to understand attacks seen in the wild, and building proofs of concept for each.

    Read the module
  2. 09

    Relaying APDU data locally, over the internet and by MQTT, and analysing the time-bounding countermeasures meant to stop it.

    Read the module
  3. 11

    Commercial phones as contactless terminals: the PCI CPoC and MPoC standards, attestation, and what breaks when the terminal is an app on untrusted hardware.

    Read the module
  4. 12

    Mastercard's Relay Resistance Protocol, Visa's timing constraints, and where formal verification found bypasses anyway. The sequel to module 9.

    Read the module
  5. 13

    Beyond the terminal

    60 minPlanned

    ISO 8583, switches and acquirer hosts, HSMs, DUKPT key derivation, ISO 9564 PIN block formats and key ceremonies — the other half of the rail.

    Read the module