Payment Systems: Magstripe, Tokenization, NFC and EMV
The 16-hour course taught at Black Hat, DEF CON and Troopers, extended to cover what changed since.
Foundations
- 01
The fundamentals: how a transaction is verified and processed against the terminal, why the APDU protocol is not encrypted, and what protects the transaction instead.
Read the module → - 02
Toolset environments
120 minThe laboratory: how it is organised, how to navigate it, and which tool suits each payment technology.
Read the module → - 03
Magnetic stripe data
60 minTrack encoding and the security thinking of the era — the ideas every later technology is a reaction against.
Read the module →
Practitioner
- 04
The APDU protocol end to end: packet generation, commands, responses, and the structure at the core of every transaction.
Read the module → - 05
EMV technology
120 minContact transactions and the advanced APDU mechanisms behind them, including emulating EMV data with dedicated hardware.
Read the module → - 06
Near field communication
120 minNFC transactions in detail: APDU exchanges, cryptogram analysis, and cardholder verification methods.
Read the module → - 07
Tokenization process
60 minThe opposite of static magstripe data: seeding and encryption for token generation, and how digital wallets implement it.
Read the module → - 10
DPAN versus FPAN, the Token Service Provider role, wallet provisioning and identification & verification, the token cryptogram, and Click to Pay.
Read the module → - 14
Pix, UPI, FedNow, SEPA Instant and EMVCo QR — static versus dynamic codes, and the fraud that followed the money out of the card rails.
Read the module → - 15
Scoping, segmentation and what an assessor actually looks for — framed for someone attacking the environment rather than documenting it.
Read the module →
Operator
- 08
Reversing transactions to understand attacks seen in the wild, and building proofs of concept for each.
Read the module → - 09
Relaying APDU data locally, over the internet and by MQTT, and analysing the time-bounding countermeasures meant to stop it.
Read the module → - 11
Commercial phones as contactless terminals: the PCI CPoC and MPoC standards, attestation, and what breaks when the terminal is an app on untrusted hardware.
Read the module → - 12
Mastercard's Relay Resistance Protocol, Visa's timing constraints, and where formal verification found bypasses anyway. The sequel to module 9.
Read the module → - 13
ISO 8583, switches and acquirer hosts, HSMs, DUKPT key derivation, ISO 9564 PIN block formats and key ceremonies — the other half of the rail.
Read the module →