What happened when Which? tested the security on contactless cards?

&Tab;&Tab;<div class&equals;"wpcnt">&NewLine;&Tab;&Tab;&Tab;<div class&equals;"wpa">&NewLine;&Tab;&Tab;&Tab;&Tab;<span class&equals;"wpa-about">Advertisements<&sol;span>&NewLine;&Tab;&Tab;&Tab;&Tab;<div class&equals;"u top&lowbar;amp">&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;<amp-ad width&equals;"300" height&equals;"265"&NewLine;&Tab;&Tab; type&equals;"pubmine"&NewLine;&Tab;&Tab; data-siteid&equals;"111265417"&NewLine;&Tab;&Tab; data-section&equals;"2">&NewLine;&Tab;&Tab;<&sol;amp-ad>&NewLine;&Tab;&Tab;&Tab;&Tab;<&sol;div>&NewLine;&Tab;&Tab;&Tab;<&sol;div>&NewLine;&Tab;&Tab;<&sol;div><p>Thieves could exploit a security flaw to steal key data from contactless debit and credit cards using equipment readily available online&comma; consumer group Which&quest; has warned&period;<br &sol;>&NewLine;It said it used &OpenCurlyDoubleQuote;easily and cheaply” acquired technology from a mainstream website to take enough information from cards to place orders for items including a £3&comma;000 television set&period;<br &sol;>&NewLine;Researchers tested six debit cards and four credit cards&comma; and Which&quest; said they all revealed some data&period;<&sol;p>&NewLine;<p><a href&equals;"http&colon;&sol;&sol;londonglossy&period;com&sol;wp-content&sol;uploads&sol;2015&sol;07&sol;1437645435-15b0f14bbb17ec603bf3bc894b38917c-600x385&period;jpg"><img src&equals;"http&colon;&sol;&sol;londonglossy&period;com&sol;wp-content&sol;uploads&sol;2015&sol;07&sol;1437645435-15b0f14bbb17ec603bf3bc894b38917c-600x385&period;jpg" alt&equals;"1437645435-15b0f14bbb17ec603bf3bc894b38917c-600x385" width&equals;"600" height&equals;"385" class&equals;"aligncenter size-full wp-image-77885" &sol;><&sol;a><&sol;p>&NewLine;<p>A spokesman said&colon; &OpenCurlyDoubleQuote;Contactless cards are coded to &OpenCurlyQuote;mask’ personal data&comma; but using an easily obtainable reader and free software to decode data&comma; we were able to read the card number and expiry date from all 10 cards&period;<br &sol;>&NewLine;&OpenCurlyDoubleQuote;We were also able to read limited details of the last 10 transactions&comma; although no cards revealed the CVV security code &lpar;the number on the back&rpar;&period;<br &sol;>&NewLine;&OpenCurlyDoubleQuote;We doubted we’d be able to make purchases without the cardholder’s name or CVV code – but we were wrong&period;<&sol;p>&NewLine;<p><a href&equals;"http&colon;&sol;&sol;londonglossy&period;com&sol;wp-content&sol;uploads&sol;2015&sol;07&sol;1437645438-d1d38f7089154f72bf2b41fc2d777ff0-600x909&period;jpg"><img src&equals;"http&colon;&sol;&sol;londonglossy&period;com&sol;wp-content&sol;uploads&sol;2015&sol;07&sol;1437645438-d1d38f7089154f72bf2b41fc2d777ff0-600x909&period;jpg" alt&equals;"1437645438-d1d38f7089154f72bf2b41fc2d777ff0-600x909" width&equals;"600" height&equals;"909" class&equals;"aligncenter size-full wp-image-77886" &sol;><&sol;a><&sol;p>&NewLine;<p>&OpenCurlyDoubleQuote;We ordered two items – one a £3&comma;000 TV – from a mainstream online shop using &OpenCurlyQuote;stolen’ card details&comma; combined with a false name and address&period;”<br &sol;>&NewLine;Contactless payment continues to grow rapidly in popularity&comma; with more than £2 billion spent through the system last year&comma; according to the UK Cards Association&period;<br &sol;>&NewLine;The limit for a single contactless transaction is £20 – but from September 1 onwards a higher limit of £30 will be rolled out&period;<&sol;p>&NewLine;<p>The Which&quest; spokesman said&colon; &OpenCurlyDoubleQuote;By touching volunteers’ cards to our card reader&comma; we got enough details to allow us to go on an internet shopping spree&period; With these card details&comma; the contactless transaction limit is irrelevant&comma; because online transactions aren’t contactless&period;”<&sol;p>&NewLine;<p>Richard Koch&comma; head of policy at the UK Cards Association&comma; said&colon; &OpenCurlyDoubleQuote;This is not a new story&period; Consumers are fully protected against any fraud losses on contactless cards and will never be left out of pocket&period;<br &sol;>&NewLine;&OpenCurlyDoubleQuote;Instances of fraud on contactless cards are in fact extremely rare&comma; with losses of less than a penny for every £100 spent on contactless – far lower even than overall card fraud&period;<&sol;p>&NewLine;<p>&OpenCurlyDoubleQuote;The method shown by Which&quest; is not a new discovery and was first reported two years ago&period; However&comma; any such technology can only obtain the card number and expiry date – information that has always been available simply by looking at the front of a card&period;<br &sol;>&NewLine;&OpenCurlyDoubleQuote;The vast majority of online retailers require additional data such as the card security code&comma; along with the cardholder’s address&comma; which cannot be harvested electronically&period; Any retailers that do not will do so at their own risk and will be liable for any fraudulent transactions&period;”<&sol;p>&NewLine;&Tab;&Tab;&Tab;<div style&equals;"padding-bottom&colon;15px&semi;" class&equals;"wordads-tag" data-slot-type&equals;"belowpost">&NewLine;&Tab;&Tab;&Tab;&Tab;<div id&equals;"atatags-dynamic-belowpost-68ed171b9fe16">&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;<script type&equals;"text&sol;javascript">&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;window&period;getAdSnippetCallback &equals; function &lpar;&rpar; &lbrace;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;if &lpar; false &equals;&equals;&equals; &lpar; window&period;isWatlV1 &quest;&quest; false &rpar; &rpar; &lbrace;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&sol;&sol; Use Aditude scripts&period;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;window&period;tudeMappings &equals; window&period;tudeMappings &vert;&vert; &lbrack;&rsqb;&semi;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;window&period;tudeMappings&period;push&lpar; &lbrace;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;divId&colon; 'atatags-dynamic-belowpost-68ed171b9fe16'&comma;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;format&colon; 'belowpost'&comma;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&rcub; &rpar;&semi;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&rcub;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&rcub;&NewLine;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;if &lpar; document&period;readyState &equals;&equals;&equals; 'loading' &rpar; &lbrace;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;document&period;addEventListener&lpar; 'DOMContentLoaded'&comma; window&period;getAdSnippetCallback &rpar;&semi;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&rcub; else &lbrace;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;window&period;getAdSnippetCallback&lpar;&rpar;&semi;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&rcub;&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;<&sol;script>&NewLine;&Tab;&Tab;&Tab;&Tab;<&sol;div>&NewLine;&Tab;&Tab;&Tab;<&sol;div>


Discover more from London Glossy Post

Subscribe to get the latest posts sent to your email.

- Advertisement -
Exit mobile version