NYC subway security flaw and 'impossible' Apple Pay vulnerability

https://9to5mac.com/2023/08/31/nyc-subway-security-flaw/

An inexcusable NYC subway security flaw has been revealed, allowing anyone with knowledge of a user’s credit card number and...

4 points · 4 comments · view on lemmy.world

4 Comments

Pons_Aelius@kbin.social · 2 pts · 3y (1 reply)

anyone with knowledge of a user’s credit card number and expiry date to track all journeys made within the past seven days.

Honestly, if someone has your CC number and expiry date the last thing I would be worried about is them being able to see my history of subway trips.

sramder@lemmy.world · 0 pts · 3y

Probably, but I’d still argue that one of the things you shouldn’t have to worry about is that data easily revealing your location history. It’s just kind of a goofy feature for the transit system to offer that has a lot of abuse potential that most customers aren’t aware of.

kirklennon@kbin.social · 2 pts · 3y

If 9to5Mac were run by reputable journalists, this poorly-researched article with its conspiratorial conjectures would have been taken down already.

The explanation for the Apple Pay aspect is something called the Payment Account Reference (PAR). Mastercard has a brief overview. Everything is working exactly like it is designed and as advertised. Apple Pay is not (and cannot) send your full real card number, but if you give a merchant your real card number, they can look up a reference number shared by every token associated with the card.

isaachernandez@lemmy.world · 1 pts · 3y

Bot

reddig33@lemmy.world · 1 pts · 3y
[ removed ]