Find news published in the date range below
and and
and and
and and
Clear
Euro
Arrow
56,1422
Dollar
Arrow
48,0770
Sterling
Arrow
65,5862
Gold
Arrow
7309,6694
BIST 100
Arrow
14.506

Contactless payment risk with expired credit cards

Researchers at the University of Massachusetts Amherst have revealed that expired credit cards can be manipulated for contactless payments.

Don't leave your news choices to an algorithm - decide for yourself what you read. Add 12punto to your preferred sources!
Contactless payment risk with expired credit cards

The expiration date printed on credit cards typically signifies to users that the card is no longer functional. However, a study by researchers at the University of Massachusetts Amherst has shown that certain checks within the contactless payment infrastructure do not guarantee this limit in all cases.

Expired cards, which the researchers describe as "zombie cards," can be used to make payments at contactless POS terminals under specific conditions. According to the findings, the issue does not stem from cracking card passwords, but rather from the insufficient verification of certain information transmitted during the payment process.

Credit cards lying on a table in close-up.
According to the research, the expiration date on the card forms a critical control area in the contactless transaction flow.

RISK OF DATA TRANSMITTED IN PLAIN TEXT

A contactless payment transaction is completed through communication between the physical card, the POS device, the merchant's bank, the card network, and the issuing institution. Whether a transaction is approved or not is determined by the checks within this chain.

According to the study, some data in the contactless payment flow can be transmitted as plain text rather than being encrypted or subjected to cryptographic verification. The expiration date information, which also appears on the physical surface of the card, stands out as one of these unprotected areas.

A customer handing a card to a clerk next to a POS device.
In contactless payments, the data flow between the card and the terminal is important in terms of security checks.

It was stated that in the examined Visa infrastructure, the date information read by the POS device is not included in the card's digital signature protection. This situation can allow an external device inserted between the card and the terminal to modify the expiration date data.

According to the research, if the expired date information is replaced with a valid date during the transaction, the terminal may approve the payment. Even if the date on the plastic surface of the card has passed, if the digital certificate inside the card remains valid, this check can be bypassed.

Credit cards of different colors stacked on top of each other.
According to experts, the findings bring the importance of verification rules in contactless payment infrastructures back to the agenda.

The findings reveal that contactless payment systems require not only the physical information of the card but also the cryptographic verification of this information. The research points to the need to strengthen rule checks in payment infrastructures.


News Source: 12punto

contactless payment credit card Zombie card University of Massachusetts Amherst Visa Digital security POS device