So what's the exploit here? Is it a bug in the cards or the protocol or what? Or is the card info considered "public" by the protocol (i.e. I could imagine an authentication scheme where the card could provide its number but the bank would only honor charges via the secure contactless scheme which came with a RSA cookie or whatenot).
Comments
So what's the exploit here? Is it a bug in the cards or the protocol or what? Or is the card info considered "public" by the protocol (i.e. I could imagine an authentication scheme where the card could provide its number but the bank would only honor charges via the secure contactless scheme which came with a RSA cookie or whatenot).