
DEF CON 33 - How Extra Features In Contactless Payments Break Security, What We Can Do - Tom Chotia
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 35:05
The speaker reveals critical vulnerabilities in contactless payment systems caused by companies adding undocumented features that compromise security 5:43.
Key Takeaways:
• European contactless payments have stricter security rules compared to the US, requiring PIN verification for transactions over $100 1:55
• The team discovered a major Visa vulnerability allowing attackers to bypass Apple Pay authentication in transit mode, enabling unauthorized payments of any amount by manipulating protocol flags 15:30
• Square's offline payment system also contained vulnerabilities where plastic cards could impersonate phones, making unauthorized high-value transactions 26:55
• The team is working with ISO to implement timing checks at the protocol level to prevent relay attacks, though standardization is challenging 31:10
The vulnerabilities highlighted demonstrate how payment companies' race to add features without proper security coordination puts consumers at risk of financial fraud.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Hi. Okay. So, as you're aware, there are no screens whatsoever. >> Um, but can everyone hear me? >> Cool. So, yeah. Um, there are no screens whatsoever. I did have a talk on a whole lo of contactless card attacks. Um, I might as well try and do it without slides. It probably won't make any sense. If anyone wants to get up and leave while I'm talking, feel free. I probably would. Um, so is everyone here for a payment talk or did people just wander in as a place to sit down? >> So payments. >> Excellent. So I'm part of a group from the University of Birmingham. I've got to mention my colleagues Andrea, George, Iona, and Anna have done a lot of this work. I've got pictures of them on the slide which you won't see, but this is very much joint work. So I like contactless payment. I think it's g…