ELSEIF
Your brief EB
389 stories from 111 feeds 404 clusters Refreshed 11 minutes ago next pull 23:22

TECH Signal 429

Visa contactless cards vulnerable to man-in-the-middle attack reviving expired cards for payments

Researchers from UMass Amherst demonstrated that Visa's contactless payment kernel does not cryptographically bind the expiration date, allowing an NFC proxy to alter the date a terminal sees while leaving the card's security checks intact.

WHY IT MATTERS

The flaw means expired Visa contactless cards can be used for unauthorized purchases when the issuing bank does not fully validate the expiration date during online authorization. Mastercard, American Express, and Discover kernels resisted the same attack, making this a Visa-specific protocol gap rather than a general EMV weakness.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

Visa's EMV kernel leaves the Application Expiration Date unsigned, so a man-in-the-middle can tamper with it without breaking the card's digital signature.

02

The attack uses mobile phones as NFC proxies between the expired card and the POS terminal, and its success depends on whether the issuing bank performs a full expiration check during online authorization.

03

Mastercard, American Express, and Discover contactless configurations all resisted the attack because their kernels bind the expiration date cryptographically.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
www.theregister.com - Articles Expired credit cards revived by researchers to make unauthorized payments Open ↗