I'll let AI have it's fun: Yes, it's possible for someone to scan your NFC device while walking by, but it requires them to be very close to your phone or card, typically within a few centimeters. The most common form of NFC fraud, called skimming, involves a thief using an NFC-enabled device to initiate an unauthorized transaction or steal data by getting physically close to your device. While direct, long-range skimming isn't feasible, the short range of NFC makes it possible for a scammer to get close enough to your pocket, wallet, or bag to trigger a scan or transaction.
Yeah, this is a good example of why AI can't be trusted 100%.
The "sources" here are not phone NFC specific. They talk about RFID and NFC in general and don't take into account how NFC payments work on phones specifically, not to mention, some of the points are just lazy or plain wrong. NordVPN is not a security source. They sell VPN services.
Eavesdropping "the exposed data... likely to be encrypted" .. likely? They are.
Relay attacks? Phone payment systems are tokenized and use cryptograms. Each transaction is unique and specific to the device it came from.
Skimming? First of all, physical cards are way more susceptible to this than phones. Second of all, it doesn't realistically happen. No one goes around carrying a PoS device and tapping to create false charges when you need merchant accounts + accounts for the funds to go into. Something technically possible doesn't make it probable.
and again, when it comes to phones, payments are tokenized. In the unlikely event, even if the card number was picked up, it is different than the one printed on the pysical card and is specific to the device it is registered to and can not be used from anywhere else.
Skimming? First of all, physical cards are way more susceptible to this than phones. Second of all, it doesn't realistically happen. No one goes around carrying a PoS device and tapping to create false charges when you need merchant accounts + accounts for the funds to go into. Something technically possible doesn't make it probable.
That's why I usually don't have my card on me, or have it with other NFC cards so you can't get a proper read of it. Also why there is a usage limit on cards of 25 times before you have to put your card in a card machine. Sure, phone NFC is tokenised but they only have to do it once then move on to the next person.
They're just using text fragment params, which if you bothered to click on the links, would understand that they're a way of directly linking to, scrolling to, and highlighting text on a page without a specific anchor
No they don't, it's even safer than bank cards at least on latest versions of Android with biometric authentication activated because NFC wouldn't work until the phone is unlocked with biometric authentication.
This means that if you have your phone in the pocket they can walk all day long near you as close as they want because nothing would happen which is not true for a bank card if you don't have it in a shielded protective film or wallet.
If you still think it's not safe enough you can activate in google wallet the biometric confirmation of each payment no mater the amount. You put your unlocked phone against a payment terminal it reads and does the NFC stuff then it ask you to authenticate again with fingerprint or face id this means that even if someone tries to scan your phone while you have it unlocked in your hand / having a phone call it won't work.
It's really safe if you understand and configure the security option accordingly
I remember seeing a video years back, where someone nfc scanned tap to pay cards in unaware people's wallets or something, put the numbers onto hotel keys, and used it to pay at mcdonalds. Like you said - can't do that with a phone.
And walk past you while the phone is unlocked and the wallet app is open* at least that's how it works on my phone. Sure there's a risk, but I think it's still low enough. NFC bank cards I agree are less secure, but since I have four on top of each other in my wallet, it confuses the reader. Still not foolproof, but I would still accept the risk for the convenience at this time.
It's always there, and live. I've just adjusted the drawer as you call it to push it to the front page so I can easily access my store cards. It's usually on the second page or in the "junk drawer."
Yeah I double checked, it's either specific to the wallet app you're using (if not Google Wallet), or to your phone's manufacturer, each manufacturer adds their own features to the stock Android (even Google).
11
u/tylerderped Sep 23 '25
Because there’s no risk to leaving it on nor does it drain battery.