Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Visa and Apple Pay vulnerabilities leaves iPhone users open to payment fraud
https://techxplore.com ^ | 30 SEPTEMBER 2021 | by University of Birmingham

Posted on 10/01/2021 7:46:34 AM PDT by Red Badger

Vulnerabilities in Apple Pay and Visa could enable hackers to bypass an iPhone's Apple Pay lock screen and perform contactless payments, according to research by the University of Birmingham and University of Surrey.

Experts in the University of Birmingham's School of Computer Science and the University of Surrey's Department of Computer Science found their approach could also be used to bypass the contactless limit allowing transactions of any amount to be performed. Their results will be presented in a paper at the 2022 IEEE Symposium on Security and Privacy.

The researchers discovered the vulnerability occurs when Visa cards are set up in 'Express Transit mode' in an iPhone's wallet. Transit mode is a feature on many smartphones that enables commuters to make a swift contactless mobile payment at, for example, an underground station turnstile, without fingerprint authentication.

The weakness lies in the Apple Pay and Visa systems working together and does not affect other combinations, such as Mastercard in iPhones, or Visa on Samsung Pay.

Using simple radio equipment, the team identified a unique code broadcast by the transit gates, or turnstiles. This code, which the researchers nicknamed the 'magic bytes' will unlock Apple Pay. The team found they were then able to use this code to interfere with the signals going between the iPhone and a shop card reader. By broadcasting the magic bytes and changing other fields in the protocol, they were able to fool the iPhone into thinking it was talking to a transit gate, whereas actually, it was talking to a shop reader.

VIDEO AT LINK...................

At the same time, the researchers' method persuades the shop reader that the iPhone had successfully completed its user authorisation, so payments of any amount can be taken without the iPhone's user's knowledge.

Dr. Andreea Radu, in the School of Computer Science at the University of Birmingham, led the research. She said: "Our work shows a clear example of a feature, meant to incrementally make life easier, backfiring and negatively impacting security, with potentially serious financial consequences for users.

"Our discussions with Apple and Visa revealed that when two industry parties each have partial blame, neither are willing to accept responsibility and implement a fix, leaving users vulnerable indefinitely."

Co-author Dr. Ioana Boureanu, from the University of Surrey's Centre for Cyber Security, added: "We show how a usability feature in contactless mobile payments can lower security. But, we also uncovered contactless mobile-payment designs, such as Samsung Pay, which is both usable and secure. Apple Pay users should not have to trade-off security for usability, but —at the moment— some of them do."

VIDEO2 AT LINK.....................

Co-author Dr. Tom Chothia, also in the School of Computer Science at the University of Birmingham, said: "iPhone owners should check if they have a Visa card set up for transit payments, and if so they should disable it. There is no need for Apple Pay users to be in danger but until Apple or Visa fix this they are."

More details of a £1000 payment being taken from a locked iPhone are available at practical_emv.gitlab.io

Explore further

Driver's license on your iPhone? These are the states where you can add ID to your Apple device Provided by University of Birmingham


TOPICS:
KEYWORDS: applepay; iphone; iphoneapplepay; visa

1 posted on 10/01/2021 7:46:34 AM PDT by Red Badger
[ Post Reply | Private Reply | View Replies]

To: Swordmaker; dayglored; bitt; ShadowAce

Pingy!.....................


2 posted on 10/01/2021 7:47:03 AM PDT by Red Badger (Homeless veterans camp in the streets while illegal aliens are put up in hotels.....................)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

Tech sure has made life easy.


3 posted on 10/01/2021 7:49:01 AM PDT by ImJustAnotherOkie (All I know is The I read in the papers.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

electronic gadgets open to security issues


4 posted on 10/01/2021 7:51:38 AM PDT by Pollard (Some people like to argue just to argue.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

Fear fear fear.... but let me guess, there is some cool solution they have in store for us?


5 posted on 10/01/2021 7:51:38 AM PDT by DesertRhino (Dogs are called man's best friend. Moslems hate dogs. Add it up....)
[ Post Reply | Private Reply | To 1 | View Replies]

To: DesertRhino

Why yes! iPhone 14!........................


6 posted on 10/01/2021 7:56:24 AM PDT by Red Badger (Homeless veterans camp in the streets while illegal aliens are put up in hotels.....................)
[ Post Reply | Private Reply | To 5 | View Replies]

To: ImJustAnotherOkie

Yes, for crooks.....................


7 posted on 10/01/2021 7:58:02 AM PDT by Red Badger (Homeless veterans camp in the streets while illegal aliens are put up in hotels.....................)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Red Badger

Not surprising, that’s why I never use Apple.


8 posted on 10/01/2021 8:11:32 AM PDT by BobL (I shop at Walmart and eat at McDonald's, I just don't tell anyone, like most here.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

I have never used Apple Pay. Never sounded safe to me.


9 posted on 10/01/2021 8:12:37 AM PDT by Sans-Culotte (11/3-11/4/2020 - The USA became a banana republic.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

bookmark


10 posted on 10/01/2021 8:40:33 AM PDT by GOP Poet (Super cool you can change your tag line EVERYTIME you post!! :D. (Small things make me happy))
[ Post Reply | Private Reply | To 1 | View Replies]

To: Sans-Culotte
"I have never used Apple Pay. Never sounded safe to me."

If you knew the Rube Goldberg mess behind a credit card transaction you'd never use one of those again.

;)

11 posted on 10/01/2021 8:45:37 AM PDT by MV=PY (The Magic Question: Who's paying for it?)
[ Post Reply | Private Reply | To 9 | View Replies]

To: MV=PY; All

I think it was at a recent visit to Walmart that terminals advised E-payments only. A nationwide coin shortage was the reason.

Another technique/excuse to end cash transactions ?....another step closer to a cashless society.


12 posted on 10/01/2021 9:12:55 AM PDT by chiller (Davey Crockett said: "Be sure you're right. Then go ahead'. I'm going ahead.)
[ Post Reply | Private Reply | To 11 | View Replies]

To: Red Badger

Use Cash, no worries


13 posted on 10/01/2021 9:20:58 AM PDT by wetgundog
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger; ~Kim4VRWC's~; 1234; 5thGenTexan; AbolishCSEU; Abundy; Action-America; acoulterfan; ...
First ever vulnerability demonstrated by researchers in ApplePay uncovered between ApplePay and Visa in a function using Quickpass functionality to grab more than intended payment amounts by potential hackers. Not yet seen in the wild.—PING!


APPLEPAY VULNERABILITY PING!

If you want on or off the Apple/Mac/iOS Ping List, Freepmail me.

14 posted on 10/02/2021 12:16:58 AM PDT by Swordmaker (My pistol self-identifies as an iPad, so you must accept it in gun-free zones, you hoplophobe bigot!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: DesertRhino

“Upgrades security features” is the phrase I see most when I’m prompted to update an app or OS.


15 posted on 10/02/2021 5:52:27 AM PDT by BradyLS (DO NOT FEED THE BEARS!)
[ Post Reply | Private Reply | To 5 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson