1. Card-not-present transaction fraud is so easy that there's no point in putting any effort into making card-present transactions secure.
2. Vendors pay for card-not-present transaction fraud
It's like worrying about the quality of your door lock, when the door is right next to a picture window, and someone else is paying for your insurance.
apparent•1h ago
al_borland•1h ago
This takes 3 things to work.
Setting Express Transit Card to None will stop it, as will using a Mastercard instead of Visa.Visa's position on this is that in-person fraud accounts for 2¢ out of every $100 spent. For them, it doesn't seem worth the investment for a very unlikely event, and the user is not responsible for fraudulent charges. The knowledge of this vulnerability has been out in the wild for several years, so it doesn't seem like it's been much of an issue in the real world. It sounds like they believe their efforts are better spent on other more impactful fraud.
Though it is a neat demo of what is possible, the tech behind it is interesting, and it does give some idea of red flags to lookout for.