News: 1633045132

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Revealed: How to steal money from victims' contactless Apple Pay wallets

(2021/10/01)


Apple's digital wallet Apple Pay will pay whatever amount is demanded of it, without authorization, if configured for transit mode with a Visa card, and exposed to a hostile contactless reader.

Boffins at the University of Birmingham and the University of Surrey in England have managed to find a way to remove the contactless payment limit on iPhones with Apple Pay and Visa cards if " [1]Express Transit " mode has been enabled.

Express Transit mode enables Apple Pay transactions without unlocking an iPhone or requiring authentication. It's intended as a convenience feature to facilitate charges when passing through public transit ticketing gates that support contactless readers like Europay, Mastercard, and Visa (EMV).

Our work shows a clear example of a feature ... backfiring and negatively impacting security

"Our work shows a clear example of a feature, meant to incrementally make life easier, backfiring and negatively impacting security, with potentially serious financial consequences for users," said Dr Andreea-Ina Radu, in the School of Computer Science at the University of Birmingham, in [2]a statement on Thursday.

The researchers involved – Andreea-Ina Radu and Tom Chothia at Birmingham and Ioana Boureanu, Christopher J.P. Newton, and Liqun Chen at Surrey – say they disclosed the flaw to Apple in October 2020 and to Visa in May 2021. However, they claim the two companies have been unable to cooperate on a fix due to finger-pointing.

[3]

“Our discussions with Apple and Visa revealed that when two industry parties each have partial blame, neither are willing to accept responsibility and implement a fix, leaving users vulnerable indefinitely," said Radu.

[4]

[5]

The research, to be presented at the 43rd IEEE Symposium on Security and Privacy in May, 2022, relies on an [6]MITM replay and relay attack on iPhones with a Visa card designated as the "transport card." In other words, the signaling between the iPhone and the transit payment system is spoofed by a rogue terminal to open Apple's digital wallet.

"If a non-standard sequence of bytes (Magic Bytes) precedes the standard ISO 14443-A WakeUp command, Apple Pay will consider this a transaction with a transport EMV reader," the researchers explain in [7]a write-up of their attack .

[8]

The Magic Bytes represent a code sequence broadcast by transit gates or turnstiles to unlock Apple Pay. What the researchers found after identifying this code with radio gear was that they could broadcast it with altered data fields to dupe appropriately configured iPhones. By altering specific fields in the wireless protocol, they can convince vulnerable iPhones to treat a transaction entered into a store-oriented contactless card reader as if it came from a transit gate, where no confirmation is expected.

[9]Apple Pay a haven for 'rampant' credit card fraud, say experts

[10]Apple says banks can't touch iPhone NFC without harming security

[11]Farewell, Android Pay. We hardly tapped you

Related data fiddling – setting a bit flag for the Consumer Device Cardholder Verification Method – tells the EMV reader participating in this interaction that on-device user authentication has authorized the amount, which allows transactions over the contactless payment limit without the victim's knowledge.

The primary requirement for this attack scenario is a stolen, active iPhone configured as described with a Visa card. The researchers claim funds could be pilfered from a vulnerable iPhone in a victim's bag, assuming proximity to the necessary hardware can be arranged.

"An attacker only needs a stolen, powered on iPhone," the team wrote. "The transactions could also be relayed from an iPhone inside someones bag, without their knowledge. The attacker needs no assistance from the merchant and backend fraud detection checks have not stopped any of our test payments."

The academics also developed a separate attack against the Visa-L1 protocol, intended as a defense against relay schemes of this sort. Visa-L1, the researchers explain, assumes the attacker cannot change the UID of a card or mobile phone and that relaying ISO 14443 messages is difficult due to timing constraints. Those are flawed assumptions.

Visa believes that rooting an Android smartphone is a difficult process, which requires high technical expertise

"The attack is possible because the protocol’s security relies on a random value sent only from the card side, which we can manipulate, and there is no randomness from the EMV reader," the academics explain.

"The protocol is meant to protect against attackers using unmodified devices, and Visa believes that rooting an Android smartphone is a difficult process, which requires high technical expertise."

[12]

In place of L1, the academics have proposed a new relay-resistant protocol, L1RP, that they claim to have proven via a security protocol verification tool called [13]Tamarin .

Radu et al suggest that while we wait for Apple and Visa to respond, no one should be using a Visa card as the transport card in Apple Pay.

Neither Apple nor Visa responded to requests for comment. ®

Get our [14]Tech Resources



[1] https://support.apple.com/en-us/HT209495

[2] https://www.birmingham.ac.uk/news/latest/2021/09/visa-and-apple-pay-vulnerabilities-leaves-iphone-users-open-to-payment-fraud.aspx

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YVaIDCaTL50Wq@dkxZot8AAAAEs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YVaIDCaTL50Wq@dkxZot8AAAAEs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YVaIDCaTL50Wq@dkxZot8AAAAEs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://en.wikipedia.org/w/index.php?title=Man-in-the-middle_attack&oldid=1045049805

[7] https://practical_emv.gitlab.io/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YVaIDCaTL50Wq@dkxZot8AAAAEs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2015/03/03/apple_pay_plastic_fraud/

[10] https://www.theregister.com/2016/08/10/apple_says_banks_cant_touch_iphone_nfc_without_harming_security/

[11] https://www.theregister.com/2018/02/21/android_pay_google_pay/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YVaIDCaTL50Wq@dkxZot8AAAAEs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://tamarin-prover.github.io/

[14] https://whitepapers.theregister.com/



A better solution...

Tron

...would be the global adoption of a Suica style pre-pay card for transport and other smaller payments.

Smartphones are unreliable. Cards just work. They cost less and require no batteries.

Colour me old fashioned

Winkypop

Relying only on one’s phone seems like a major and single point of failure.

Re: Colour me old fashioned

DS999

People must CHOOSE to rely only on their phone. Unless you choose to bring no cash and no cards with you, you will have alternatives.

Even if you are willing to accept the possibility you are moneyless if your phone is lost or broken that's really only a feasible choice if you know exactly where you're going, i.e. when I go to the grocery store I don't bother to grab my wallet because I know they take Apple Pay. You can't rely on that in general, and probably won't be able to for many years.

Re: Colour me old fashioned

alain williams

if your phone is lost or broken

or run out of battery - as happened to one unfortunate who then received a fine when unable to prove to a ticket inspector that he had paid for the train journey.

Looks like this can be disabled

Ace2

Settings -> Wallet & Apple Pay -> Express Transit Card -> None

Never used it though, I’ve no idea if you can still pay at a transit terminal without it.

Jon Splatz's Movie Review: "Lord of the Pings"

I've never walked out on a movie before. When I pay $9.50 to see a movie
(plus $16.50 for snacks), I'm going to sit through every single minute no
matter how awful. The resolve to get my money's worth allowed me to watch
Jar Jar Binks without even flinching last year.

But I couldn't make it through "Lord of the Pings". This movie contains a
scene that is so appalling, so despicable, so vile, so terrible, so
crappy, and so gut-wrenching that I simply had to get up, run out of the
theater, and puke in the nearest restroom. It was just that bad.

The whole thing is completely ruined by a scene that takes place only 52
seconds into the flick. Brace yourself: big letters appear on screen that
say "An AOL/Time Warner Production".

...

Because this film is brought to you by the letters A-O-L-T-W, I must give
it an F-minus even though I've only seen 53 seconds of it.