4.9 • 696 Ratings
🗓️ 1 October 2021
⏱️ 15 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Friday, October 1st, 2021 edition of the Sandsenet Storm Center's Stormcast. |
0:07.1 | My name is Johannes Ulrich. |
0:08.7 | And I'm recording from Jacksonville, Florida. |
0:12.9 | BBC is reporting in an interview with security researchers that it's possible to launch a machine- a middle attack against Apple's Express Transit payments. |
0:26.3 | Quite a few larger cities around the world are supporting Express Transit. |
0:31.6 | And what it really means is that you're able to pay using your iPhone without having to actually unlock your iPhone. |
0:39.8 | So it's meant to be a low friction way to check in and check out as you enter and leave |
0:45.8 | a particular public transit system, similar to what in the past you would have done with |
0:51.2 | a paper ticket or sometimes with an RFID ticket specific to a particular |
0:56.7 | transit system. Now, the vulnerability here apparently only affects a visa. So if you have a visa |
1:03.6 | card registered with express transit and it's your classic machine in the middle vulnerability |
1:10.1 | where an attacker would place a device close to the victim's iPhone, then really the information across the internet to a second device that's close to a payment terminal. |
1:23.1 | The attacker would then modify the data and would be able to change the amount as well as the |
1:31.0 | destination of the money that is being withdrawn from the particular card. |
1:37.2 | Now, this was reported to Apple and Visa about a year ago. |
1:41.1 | At this point, it has not been fixed yet. |
1:43.2 | It appears to be more of a visa problem |
1:46.8 | versus an Apple problem. And visa states that the attack isn't really practical, given that it |
1:55.0 | does require the attacker to play essentially this machine in the middle attack. So lots of moving parts here, and they also point out that the attack was only |
2:04.5 | demonstrate in a lap. |
2:05.7 | Of course, you could also argue that it was demonstrated in the lab because it would |
2:09.3 | probably not be sort of safe and ethical to do it at an actual terminal using an actual |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.