Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments

As the controversial vehicle surveillance giant Flock Safety continues to expand,

Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments

Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments

As the controversial vehicle surveillance giant Flock Safety continues to expand, WIRED got the code for the company’s new AI policing tool and reconstructed the software to show that its capabilities go far beyond reading license plates and tracking vehicles. We also published the story this week of a Rhode Island police officer who was subjected to five internal affairs investigations in less than two years after he publicly questioned his department’s use of Flock cameras.

Following incidents of high-profile rogue activity by some of its AI agents, OpenAI said this week that it is halting model training runs and overhauling internal safety protocols. The company said that its upcoming Astra model may represent a turning point of “critical” cyber capabilities.

A reverse-lookup identification service exposed millions of photos of people’s faces in a database accessible through the open internet. Meanwhile, Meta ran advertisements for an app that promised to nudify female politicians, including one ad featuring a pornographic video that included a deepfake resembling a well-known US politician. Apple removed the app from the App Store after WIRED’s inquiry.

And WIRED spoke with Andy Yen, CEO of the privacy-focused digital services company Proton, about the privacy implications of AI and how access to encryption can continue to expand in this new technological era.

But wait, there’s more! Each week, we round up the security and privacy news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.

Fraudsters Could Use “Zombified” Expired Visa Cards to Make Contactless Payments

Many people know that any active credit card represents a fraud risk the minute a card is lost, stolen, or otherwise gets out of their hands. Less expected is that an expired Visa card, too, could serve as an errant key into their bank account if it’s left unattended or discarded intact, discovered by a fraudster, and “zombified” using a new technique researchers recently revealed.

At the Usenix Cybersecurity Conference last week, researchers at the University of Massachusetts Amherst warned that fraudsters could make contactless payments using expired credit cards issued by Visa by proxying them through a man-in-the-middle app that relays the credit card’s data through a pair of phones. Due to issues in the authentication chain of contactless payments, the researchers found that whether an expired card’s transaction would be disallowed was left to cryptography implemented differently by various card issuers. Visa’s had a particular flaw allowing out-of-date cards to pass its check. (Visa didn’t respond to requests for comment from tech news outlet the Register, which reported on the research this week.)

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.