Experts warn expired credit cards can be brought back from the dead to make contactless payments
Researchers show how an expired contactless card can still complete a real purchase because the expiry date the terminal reads is not covered by its signature The attack needs physical possession of the discarded card and two ordinary smartphones, and results vary per bank, with Visa cards being susceptible in testing Existing EMV protections can detect the relay, but they are optional and were not enabled on any card or terminal tested, and neither Visa nor the notified banks have confirmed a fix is in the works For a layman, the date printed on a credit card looks like a hard stop, but that might not always be the case.
Researchers at the University of Massachusetts Amherst found that a 'zombie card' past its expiration date can be persuaded to complete a contactless purchase at a real checkout terminal, creating a real security threat.
The irony is that it is not that EMV cryptography is not bypassed in any way, but rather that card expiry is enforced in a different way for contactless payments, as a policy check between two parties rather than as a fixed property of the card itself, and interestingly, the parties do not always know who is the one checking.
Dead plastic can still be used to pay under certain conditions Building on the last part, a contactless transaction involves a card, a point-of-sale terminal, the merchant's bank, a card network, and the issuer.
Each holds a fragment of the decision that eventually results in a successful or declined card transaction.
The EMV contactless flow is only selectively authenticated: some fields travel between the card and terminal in unencrypted text and are linked to cryptographic verification later, opening a potential attack vector for users with physical access to an expired card.
The exposure here is not that those fields can be read, since the expiry date is printed on the card anyway, but that it can be changed with relative ease.
The Application Expiration Date that the terminal reads sits in the unprotected portion.
In the Visa configuration the team tested, that field is not covered by the card's digital signature and is subsequently not cryptographically bound to the expiry value the issuer sees in the online authorization request.
While this should not be the case, it opens an attack vector for a device between the card and the terminal that processes the charge by simply modifying the expiry value to one that is still valid.
The issue is compounded by a second issue: cards carry an expiry date inside the digital certificate used to establish the card-to-terminal conversation, and researchers have found that the certificate outlasts the printed date on the plastic.
In essence, a check that might have caught the problem is looking at a clock set further ahead.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.