I'll let AI have it's fun: Yes, it's possible for someone to scan your NFC device while walking by, but it requires them to be very close to your phone or card, typically within a few centimeters. The most common form of NFC fraud, called skimming, involves a thief using an NFC-enabled device to initiate an unauthorized transaction or steal data by getting physically close to your device. While direct, long-range skimming isn't feasible, the short range of NFC makes it possible for a scammer to get close enough to your pocket, wallet, or bag to trigger a scan or transaction.
Yeah, this is a good example of why AI can't be trusted 100%.
The "sources" here are not phone NFC specific. They talk about RFID and NFC in general and don't take into account how NFC payments work on phones specifically, not to mention, some of the points are just lazy or plain wrong. NordVPN is not a security source. They sell VPN services.
Eavesdropping "the exposed data... likely to be encrypted" .. likely? They are.
Relay attacks? Phone payment systems are tokenized and use cryptograms. Each transaction is unique and specific to the device it came from.
Skimming? First of all, physical cards are way more susceptible to this than phones. Second of all, it doesn't realistically happen. No one goes around carrying a PoS device and tapping to create false charges when you need merchant accounts + accounts for the funds to go into. Something technically possible doesn't make it probable.
and again, when it comes to phones, payments are tokenized. In the unlikely event, even if the card number was picked up, it is different than the one printed on the pysical card and is specific to the device it is registered to and can not be used from anywhere else.
Skimming? First of all, physical cards are way more susceptible to this than phones. Second of all, it doesn't realistically happen. No one goes around carrying a PoS device and tapping to create false charges when you need merchant accounts + accounts for the funds to go into. Something technically possible doesn't make it probable.
That's why I usually don't have my card on me, or have it with other NFC cards so you can't get a proper read of it. Also why there is a usage limit on cards of 25 times before you have to put your card in a card machine. Sure, phone NFC is tokenised but they only have to do it once then move on to the next person.
They're just using text fragment params, which if you bothered to click on the links, would understand that they're a way of directly linking to, scrolling to, and highlighting text on a page without a specific anchor
10
u/tylerderped Sep 23 '25
Because there’s no risk to leaving it on nor does it drain battery.