How to secure your credit and debit cards in Portugal
This blog post could work for American immigrants or tourists visiting Portugal and the rest of Europe. No one wants to deal with a compromised credit or debit card. For folks on vacation, seeing fraudulent transactions pop up on their bank statement can potentially wreck a vacation. Unfortunately, I see so many people focus on the wrong solution at the expense of taking steps that would actually help. For me, the undisputed king of wrong solutions is the RFID-blocking wallet.
These RFID-blocking wallets might be one of the most wide-spread scams of all time.
So why do I get so wound up over these stupid wallets? Because I see people post in the various online communities nearly every day about how these wallets help, when they offer zero value. The story sounds plausible; a thief can take advantage of the same technology that allows contactless payment to work by using some sort of scanning device to read your card’s chip when walking past you. You will find tons of people who will swear up and down that they’ve been the victim of these RFID “walk by” thefts. They were not. This fake feature helps sell a lot of wallets, too.
So, instead of taking steps that actually help protect payment card data, people buy these stupid wallets and think they are safe. To understand why these wallets are a scam, you need to first understand how modern chip-based payment cards work.
When using contactless payment, the card or device sends encrypted data to the merchant’s terminal via Near Field Communication (NFC). The core of this transaction is a "digital handshake" that transmits a one-time, unique token rather than your actual account information.
Data Sent from the Card to the Machine:
- Unique Cryptogram/Token: A one-time-use digital code that acts as a placeholder for your real account number.
- Token Expiry & Purpose: This dynamic, encrypted code is valid only for that single transaction.
- Card Issuer Details: Information identifying your bank and card network (e.g., Visa, Mastercard).
- Expiry Date: Some systems may send the card's expiration date.
- Optional Data: In some cases, a transaction counter is transmitted to prevent fraud.
Apple Pay/Google Pay is even more secure because your real card number is replaced with a Device Account Number (DAN). This is stored in a secure element (a dedicated chip) on the phone. The phone then uses a biometric check (like Face ID or fingerprint) to authorize the release of the payment token to the terminal.
In all cases, your actual card number is never transmitted by NFC. The only data that does get sent is an encrypted, one-time-use token. So, worst-case theoretical risk is that someone can fraudulently charge you for the max transaction amount for contactless. In the EU, that is €50. But even that would take something close to a miracle to happen.
Near Field Communication (NFC) is a subset of RFID technology with some important limitations. First, the maximum range is 10cm (about 4 inches) and that is under ideal circumstances. Also, NFC can only read one card/tag at a time. So if you have 2 or more chip cards in your wallet, the scanner can, at most, read one of them, and would likely get confused as to which one. Also, it can take up to 3 seconds to receive that data.
Getting back to the range issue. If you had your cards in your pocket or purse, the thief would have to keep the reader within 4 inches for up to 3 seconds in order to capture any data (which, as I explained earlier is essentially worthless data). In reality, the NFC signal would struggle to get through your clothing or purse material, no matter what it is made of, requiring even shorter distance and likely more time to complete the fake transaction. So, unless you have a 4-inch purse, or place a sticker on the outside of your pants pocket to clearly show where your wallet it, there's no chance at all for anyone to even attempt a fake transaction. And, if that did happen, the thief would NOT get card data that would allow them to "compromise" your cards.
RFID wallets, covers, etc... are pure theater. They offer zero value, and in fact cause harm. People incorrectly assumed that their compromised card was scanned. It was not. But because they think that is the case, they fail to investigate the dozens of more likely and plausible causes of that breach, leaving them vulnerable again to the same problem.
Was your card exposed in a data breach? Did you use your card on a dodgy website? How secure is your computer? Do you use strong, unique passwords? I guarantee that most people's weak password management system is a much bigger risk. But instead of using a password manager, many people would rather buy some fake RFID shielding wallet and think they're safe. I haven't even gotten to the skimming devices and fake ATM machines. Not to mention good ol' fashioned social engineering where someone simply cons you out of your card details. These things happen all the time.
So, what can you do to protect your payment cards? My top piece of advice is to load your cards into your digital wallet on your smartphone and make Google/Apple Pay your primary, default way to pay. Make sure you are using a password manager, so all of your accounts use strong, unique passwords. If you aren’t using a password manager, that can be a significant security hole. Keep your computer updated and free of malware. Avoid visiting sketchy website. Learn to identify phishing scams. When traveling, but sure to have backup forms of payment. Use your credit card and banking apps to monitor suspicious transactions and be ready to deactivate your card if needed.
The risk you face is not someone near you, but likely someone on the other side of the planet who can access your banking details due to weak passwords or poor online security practices.
Member discussion