Expired credit cards revived by researchers to make unauthorized payments
ID: ff392bef-65b4-51ef-8d72-9e6c41b040c4
STIX ID: report--ff392bef-65b4-51ef-8d72-9e6c41b040c4
Feed Name: The Register (Security)
Researchers at UMass Amherst demonstrated that certain Visa contactless EMV configurations do not cryptographically bind the expiration date used by the POS terminal to the date sent in the online authorization request, enabling an NFC man-in-the-middle proxy to make expired cards appear valid and complete transactions. The proof-of-concept affected Visa contactless cards in tests (Mastercard, AmEx, and Discover resisted the technique), banks showed mixed responses during authorization, and the authors disclosed the issue to Visa with no public confirmation of fixes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
