Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Hackers Can Now Bypass PIN Codes on Mastercard and Maestro Contactless Cards
#1
https://news.softpedia.com/news/hackers-...3911.shtml      Hackers Can Now Bypass PIN Codes on Mastercard and Maestro Contactless Cards
Threat actors can take money from flawy contactless cards
Aug 31, 2021 15:15 GMT  ·  By George Dascalu  ·         
Threat actors can take money from flawy contactless cards
Contacless Mastercard and Maestro PINs can be bypasses due to a new vulnerability discovered by Swiss College of Engineering in Zurich, according to Cybersecurity News.

The key aspect of the flaw is that it allows thieves to use a hacked Mastercard or Maestro card to make contactless payments without having to input the PIN to complete the transaction, if properly exploited.

Properly in this case entails first installing dedicated software on two Android smartphones. One device is used to simulate a point of sale terminal being installed, while the other acts as a card emulator that allows the modified transaction information to be transmitted to a real point-of-sale device. Once the card initiates a transaction, it reveals all related information.

To avert further attacks, security experts will not reveal the app in question
Experts from ETH Zurich confirmed that this is an isolated attack, but that can easily be exploited in real life as more loopholes in contactless payment methods are uncovered. In the past, the same team managed to successfully bypass Visa's contactless payment PINs, an experiment that is described in detail in the "The EMV Standard: Break, Fix, Verify" research paper.

The current experiment focused on PIN bypassing on cards that are not used for Visa's contactless payment protocol, but using the same strategy and known vulnerabilities. The team was able to intercept Visa's contactless payment specifications and transfer the transaction aspects into a real point-of-sale terminal that was already verified and confirmed the PIN along with the card purchaser's identification, so the PoS didn't need to perform further checks.

Regardless of whether it was Visa, Mastercard or Maestro, ETH managed to successfully carry out the experiment, which is not exactly what the millions of contactless card users out there want to hear. Due to the seriousness of the issue and its potential consequences, the researchers did not reveal the names of the apps used.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Hackers steal 50,000 credit cards from 300 U.S. restaurants mrtrout 0 726 07-20-2022 , 02:25 AM
Last Post: mrtrout
  Low-Detection Phishing Kits Increasingly Bypass MFA Mohammad.Poorya 0 924 02-04-2022 , 05:29 PM
Last Post: Mohammad.Poorya
  New Bugs Could Let Hackers Bypass Spectre Attack Mitigations On Linux Systems Bjyda 0 943 03-29-2021 , 05:07 PM
Last Post: Bjyda
  Mastercard Introduces Quantum-Resistant Specs to Enhance Contactless Security Bjyda 0 817 01-26-2021 , 11:55 PM
Last Post: Bjyda
  VPN bypass vulnerability in Apple iOS sidemoon 0 1,489 03-26-2020 , 08:53 PM
Last Post: sidemoon

Forum Jump:


Users browsing this thread: 1 Guest(s)