Payment Systems: Magstripe, Tokenization, NFC and EMV
The 16-hour course taught at Black Hat, DEF CON and Troopers, extended to cover what changed since.
Foundations
- 01
The fundamentals: how a transaction is verified and processed against the terminal, why the APDU protocol is not encrypted, and what protects the transaction instead.
Read the module → - 02
Toolset environments
120 minThe laboratory: how it is organised, how to navigate it, and which tool suits each payment technology.
Read the module → - 03
Magnetic stripe data
75 minTrack encoding and the security thinking of the era — then MagSpoof, part by part, and the unsigned field on the stripe that tells a terminal to prefer the chip.
Read the module →
Practitioner
- 04
The APDU protocol end to end: packet generation, commands, responses, and the structure at the core of every transaction.
Read the module → - 05
EMV technology
120 minContact transactions and the advanced APDU mechanisms behind them, including emulating EMV data with dedicated hardware.
Read the module → - 06
The CVM List in tag 8E, how a terminal walks it to choose a method, what tag 9F34 records afterwards — and the man-in-the-middle that let a terminal believe a PIN was verified while the card was never asked for one.
Read the module → - 07
The part of EMV that decides rather than authenticates: the TVR in tag 95, Terminal and Issuer Action Codes, the zero floor limit, and Visa's published action codes decoded bit by bit — then the 2026 result showing one of those bits was never bound to anything.
Read the module → - 08
Near field communication
120 minNFC transactions in detail: APDU exchanges, cryptogram analysis, and cardholder verification methods.
Read the module → - 09
Tokenization process
60 minThe opposite of static magstripe data: seeding and encryption for token generation, and how digital wallets implement it.
Read the module → - 10
DPAN versus FPAN, the Token Service Provider role, provisioning, and where the keys live — then the 2021 research that paid from locked phones by flipping one byte, and the signed field that said so and was never read.
Read the module → - 11
Pix, UPI, FedNow, SEPA Instant and EMVCo QR — static versus dynamic codes, and the fraud that followed the money out of the card rails.
Read the module → - 12
Scoping, segmentation and what an assessor actually looks for — framed for someone attacking the environment rather than documenting it.
Read the module →
Operator
- 13
Reversing transactions to understand attacks seen in the wild, and building proofs of concept for each.
Read the module → - 14
Tag 9F37 is the terminal's only contribution of freshness, and some terminals supplied a counter. What that made possible, why it is neither a replay nor a clone, and how to measure a terminal for yourself.
Read the module → - 15
Why tapping stops asking for a PIN after five times, where that counter really lives, and two pieces of published research that got past it — one resetting the counter without ever knowing a PIN, one making a plastic card present as a phone to an offline reader anyone can buy.
Read the module → - 16
Relaying APDU data locally, over the internet and by MQTT, and analysing the time-bounding countermeasures meant to stop it.
Read the module → - 17
Mastercard's Relay Resistance Protocol, Visa's very different Level 1 approach, and where formal verification broke both. The sequel to module 16.
Read the module → - 18
Commercial phones as contactless terminals: the PCI CPoC and MPoC standards, attestation, and what breaks when the terminal is an app on untrusted hardware.
Read the module → - 19
ISO 8583, switches and acquirer hosts, HSMs, DUKPT key derivation, ISO 9564 PIN block formats and key ceremonies — the other half of the rail.
Read the module → - 20
Anyone can buy a certified EMV reader now, and some of them take a payment with no network. A protocol-level walkthrough of four 2025 attacks — a loyalty protocol standing in for identity, a status word misread for years, and a signature over the copy nobody compares.
Read the module →