FlyerTalk Forums - View Single Post - USA contactless credit/debit/transit (2017 - 2021)
Old Aug 28, 2020 | 3:58 am
  #8692  
tmiw
FlyerTalk Evangelist
All eyes on you!
10 Years on Site
 
Join Date: Jan 2014
Location: San Diego, CA
Programs: GE, Marriott Platinum
Posts: 15,742
BTW, not that this would particularly matter for most Americans, but: Academics bypass PINs for Visa contactless payments

At the technical level, the researchers said the attack is possible because of what they describe as design flaws in the EMV standard and in Visa's contactless protocol.These issues allow an attacker to alter data involved in a contactless transaction, including the fields that control transaction details and if the card owner has been verified.

"The cardholder verification method used in a transaction, if any, is neither authenticated nor cryptographically protected against modification," researchers said.

"The attack consists in a modification of a card-sourced data object –the Card Transaction Qualifiers– before delivering it to the terminal," they added.

"The modification instructs the terminal that: (1) PIN verification is not required, and (2) the cardholder was verified on the consumer's device (e.g., a smartphone)."
I would think banks would see CDCVM happening on a non-tokenized PAN and instantly decline, but I guess not. It might not even be realistically possible to do that if biometric cards become more common (depending on how they're implemented).
tmiw is offline