Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments

Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments

你的过期 Visa 卡可能会被“僵尸化”以进行非接触式支付

As the controversial vehicle surveillance giant Flock Safety continues to expand, WIRED got the code for the company’s new AI policing tool and reconstructed the software to show that its capabilities go far beyond reading license plates and tracking vehicles. We also published the story this week of a Rhode Island police officer who was subjected to five internal affairs investigations in less than two years after he publicly questioned his department’s use of Flock cameras.

随着备受争议的车辆监控巨头 Flock Safety 的持续扩张,WIRED 获取了该公司新型人工智能警务工具的代码,并重构了该软件,结果显示其功能远不止读取车牌和追踪车辆那么简单。本周,我们还报道了一名罗德岛州警察的故事,他在公开质疑其部门使用 Flock 摄像头后,在不到两年内遭受了五次内部事务调查。

Following incidents of high-profile rogue activity by some of its AI agents, OpenAI said this week that it is halting model training runs and overhauling internal safety protocols. The company said that its upcoming Astra model may represent a turning point of “critical” cyber capabilities.

继其部分人工智能代理出现高调的违规行为后,OpenAI 本周表示将暂停模型训练运行,并全面修订内部安全协议。该公司称,其即将推出的 Astra 模型可能代表了“关键”网络能力的一个转折点。

A reverse-lookup identification service exposed millions of photos of people’s faces in a database accessible through the open internet. Meanwhile, Meta ran advertisements for an app that promised to nudify female politicians, including one ad featuring a pornographic video that included a deepfake resembling a well-known US politician. Apple removed the app from the App Store after WIRED’s inquiry.

一个反向查找身份识别服务在可通过开放互联网访问的数据库中泄露了数百万张人脸照片。与此同时,Meta 为一款承诺将女性政治人物“裸体化”(nudify)的应用程序投放了广告,其中一则广告包含一段色情视频,视频中使用了酷似某位知名美国政治人物的深度伪造(deepfake)影像。在 WIRED 询问后,苹果公司已将该应用从 App Store 下架。

And WIRED spoke with Andy Yen, CEO of the privacy-focused digital services company Proton, about the privacy implications of AI and how access to encryption can continue to expand in this new technological era.

WIRED 还采访了专注于隐私的数字服务公司 Proton 的首席执行官 Andy Yen,探讨了人工智能对隐私的影响,以及在这个新的技术时代,加密技术的普及如何能够持续扩大。

But wait, there’s more! Each week, we round up the security and privacy news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.

还没完!每周,我们都会汇总那些我们未进行深度报道的安全与隐私新闻。点击标题即可阅读完整报道。祝大家保持安全。

Fraudsters Could Use “Zombified” Expired Visa Cards to Make Contactless Payments

诈骗者可能利用“僵尸化”的过期 Visa 卡进行非接触式支付

Many people know that any active credit card represents a fraud risk the minute a card is lost, stolen, or otherwise gets out of their hands. Less expected is that an expired Visa card, too, could serve as an errant key into their bank account if it’s left unattended or discarded intact, discovered by a fraudster, and “zombified” using a new technique researchers recently revealed.

许多人都知道,任何有效的信用卡一旦丢失、被盗或脱离掌控,就会带来欺诈风险。但鲜为人知的是,如果一张过期的 Visa 卡被随意放置或完整丢弃,并被诈骗者发现,通过研究人员最近揭示的一种新技术进行“僵尸化”,它也可能成为进入银行账户的非法钥匙。

At the Usenix Cybersecurity Conference last week, researchers at the University of Massachusetts Amherst warned that fraudsters could make contactless payments using expired credit cards issued by Visa by proxying them through a man-in-the-middle app that relays the credit card’s data through a pair of phones. Due to issues in the authentication chain of contactless payments, the researchers found that whether an expired card’s transaction would be disallowed was left to cryptography implemented differently by various card issuers. Visa’s had a particular flaw allowing out-of-date cards to pass its check.

在上周的 Usenix 网络安全会议上,马萨诸塞大学阿默斯特分校的研究人员警告称,诈骗者可以通过中间人应用程序,利用两部手机中转信用卡数据,从而使用过期的 Visa 信用卡进行非接触式支付。由于非接触式支付认证链中存在问题,研究人员发现,过期卡的交易是否会被拒绝,取决于不同发卡机构所采用的加密实现方式。Visa 的系统存在一个特定缺陷,允许过期卡通过其验证。

In fact, as the researchers describe it, Visa’s essentially passed on the task of authenticating these transactions to the cardholder’s bank—and while some banks prevented the use of the zombified cards, others didn’t. The result is that fraudsters could in some cases dumpster dive for an expired card and use it to make payments from the unwitting owner’s account—particularly at point-of-sale terminals where no human is present to look askance at their phone-based proxy setup.

事实上,正如研究人员所描述的那样,Visa 本质上将这些交易的认证任务转嫁给了持卡人的银行——虽然有些银行阻止了此类“僵尸卡”的使用,但其他银行却没有。结果是,诈骗者有时可以通过翻找垃圾桶获取过期卡,并利用它从不知情的持卡人账户中进行支付——特别是在没有人工值守、无法察觉其基于手机的代理设置的销售终端(POS机)上。

The lesson: When that Visa card expires, a pair of scissors can ensure it doesn’t reanimate in someone else’s hands.

教训是:当 Visa 卡过期时,一把剪刀可以确保它不会在别人手中“复活”。