VISA 1FA EMV?

Date: 2020-09-08
Author: Martin Scholz, Versasec R&D Manager

Next >> Expand WHfB

Previous << NIST ZTA

Using strong authentication, two-factor authentication based on smart cards and PIN, EMV enabled a game changing shift in liability from the credit card companies, to the card holder. Is this still the case if the PIN is not used?

The popular NFC-based payment procedure enables payments of smaller amounts (below 50 EURO), by just tapping the credit card on the PoS without entering a PIN. Now it has been discovered that Visa’s EMV cards can by a simple man-in-the-middle (MITM) attack, be used also for larger amounts, without a PIN.

Researchers at ETH Zurich discovered a critical gap in a protocol used by the credit card company Visa. Other companies, such as Mastercard, American Express and JCB, don’t use the same protocol as Visa, so these cards are not affected by the security loophole.

An example of the attack can be seen on the YouTube video below.

The convenience of not having to enter PINs for smaller transactions, is noticeable for everyone who has used this technology. But already there, alarms should be going off for every CISO. If you add a small bug on top of that, the security level of the whole system is drastically lowered. Basically making a 2-factor authentication system, 1-factor!

More about how the security researchers from ETH Zurich found the attack vector and other details can be found here:

Versasec Support

Versasec customers with an existing support and maintenance contract can access the Versasec Support Portal, offering extensive professional support and maintenance services. The Versasec Support Portal offers a variety of services, allowing for customers and any site visitor to communicate directly with support engineers.

Support

Company Blog

Our blog addresses the latest security trends and stories and how identity and access management is playing a larger role in keeping corporate data safe and brand reputations intact. To learn more, bookmark our blog! [more]