DEF CON 33 - How Extra Features In Contactless Payments Break Security, What We Can Do - Tom Chotia

DEF CON 33 - How Extra Features In Contactless Payments Break Security, What We Can Do - Tom Chotia

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 35:05

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The speaker reveals critical vulnerabilities in contactless payment systems caused by companies adding undocumented features that compromise security 5:43.

Key Takeaways:
• European contactless payments have stricter security rules compared to the US, requiring PIN verification for transactions over $100 1:55
• The team discovered a major Visa vulnerability allowing attackers to bypass Apple Pay authentication in transit mode, enabling unauthorized payments of any amount by manipulating protocol flags 15:30
• Square's offline payment system also contained vulnerabilities where plastic cards could impersonate phones, making unauthorized high-value transactions 26:55
• The team is working with ISO to implement timing checks at the protocol level to prevent relay attacks, though standardization is challenging 31:10

The vulnerabilities highlighted demonstrate how payment companies' race to add features without proper security coordination puts consumers at risk of financial fraud.

Sources:

  • 1:55 Differences between European and US payment security rules
  • 5:43 New payment features introducing vulnerabilities
  • 15:30 Visa transit mode attack details
  • 26:55 Square offline vulnerability
  • 31:10 Proposed timing solution to prevent relay attacks

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hi. Okay. So, as you're aware, there are no screens whatsoever. >> Um, but can everyone hear me? >> Cool. So, yeah. Um, there are no screens whatsoever. I did have a talk on a whole lo of contactless card attacks. Um, I might as well try and do it without slides. It probably won't make any sense. If anyone wants to get up and leave while I'm talking, feel free. I probably would. Um, so is everyone here for a payment talk or did people just wander in as a place to sit down? >> So payments. >> Excellent. So I'm part of a group from the University of Birmingham. I've got to mention my colleagues Andrea, George, Iona, and Anna have done a lot of this work. I've got pictures of them on the slide which you won't see, but this is very much joint work. So I like contactless payment. I think it's g…