Skip to content
The beaver is a proud and noble animal

The beaver is a proud and noble animal

Notes from a bemused canuck

  • Home
  • About
  • Bookmarks
  • Pictures
  • Resume
  • Wine
  • Random Recipe
  • Toggle search form

Well, that’s a big oopsie!

Posted on November 5, 2014 By admin

MoS2 Template Master

According to researchers at Newcastle University in the UK, the card system developed by VISA for use in the United Kingdom fails to recognize transactions made in non-UK foreign currencies and can therefore be tricked into approving any transaction up to 999,999.99.

What’s more, because the cards allow for contactless transactions, wherein consumers need only to have the card in the vicinity of a reader without swiping it, a thief carrying a card reader designed to read a card that’s stored in a wallet or purse could conduct fraudulent transactions without the victim ever removing their card.

Since the transaction is done offline without going through a retailer’s point-of-sale system, no other security checks are done.

“With just a mobile phone we created a POS terminal that could read a card through a wallet,” Martin Emms, lead researcher of the project that uncovered the flaw, noted in a statement about the findings. “All the checks are carried out on the card rather than the terminal so at the point of transaction, there is nothing to raise suspicions. By pre-setting the amount you want to transfer, you can bump your mobile against someone’s pocket or swipe your phone over a wallet left on a table and approve a transaction.”

In tests the researchers conducted, transactions took less than a second to be approved. In the UK, contactless payments are limited to a maximum value of £20, requiring a PIN for anything more than this. But the researchers found that the system doesn’t recognize foreign currency transactions and therefore doesn’t require a PIN for these.

“This lends itself to multiple attackers across the world collecting small transactions of perhaps €200 at a time for a central rogue merchant who could be located anywhere in the world,” Emms notes. “This previously undocumented flaw around foreign currency, combined with the lack of POS terminal authentication and the ease of skimming contactless credit cards, makes the system more vulnerable to high-value attacks.

It is not clear from reading the payment protocol how banks would deal with the inconsistencies we have found through our research, hence we believe the vulnerability poses a potential threat,” he said. “The fact that we can by-pass the £20 limit makes this new hack potentially very scalable and lucrative. All a criminal would need to do is set up somewhere like an airport or the London underground where the use of different currencies would appear legitimate.”

  • Click to share on WhatsApp (Opens in new window) WhatsApp
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on Threads (Opens in new window) Threads
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to email a link to a friend (Opens in new window) Email
uncategorized Tags:news from the stupid

Post navigation

Previous Post: Previous Post
Next Post: Scottish drinkers could be forgiven for crying into their drams after a single malt from Japan was named the best whisky in the world

Related Posts

  • It’s not broken, don’t fix it. news from the stupid
  • Touched by his noodly appendage brought to you by the fda
  • Reason #49,367 to not travel to the US anymore brought to you by the fda
  • Democracy works, kinda, except in the US. brought to you by the fda
  • A coronary on a bun, please! news from the stupid
  • At what point is a country bankrupt? brought to you by the fda

Power to the beaver!

Show me the beaver!
November 2014
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
« Oct   Dec »

Quote of the day

I once absend-mindedly ordered Three Mile Island dressing in a restaurant and, with great presence of mind, they brought Thousand Island Dressing and a bottle of chili sauce.
--(Terry Pratchett, alt.fan.pratchett)

Random Posts

  • Sleep is good for productivity
  • This is what the Liberal campaign needs
  • I don’t know what’s happening in this picture
  • Panic room
  • Christmas display at the garden center
reading leopard

Tags

bobble the little blue owl boobies brought to you by the fda cats chonk christmas comics computers are evil covid-19 dealing with idiots dilbert dog ducks galleries geek god bless the land of the free holidays house I am Canadian land of cheese and chocolate linked news lolcat london news from the stupid not my dog nsfw pets pictures potd2014 qotd random shit re-member recipes relationship shrill slice of life stress Tao the british way The Peanut things i miss travel video wine work

Archives

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Copyright © 2025 The beaver is a proud and noble animal.

Powered by PressBook Premium theme

 

Loading Comments...