📺 How easy is it to steal $10,000 from a locked phone?
Cybersecurity researchers Ioana Boureanu and Tom Chothia join MKBHD to demonstrate how a man-in-the-middle NFC attack can authorize a $10,000 contactless payment from a locked iPhone. The explanation covers the conditions that make the exploit possible, the iPhone and Visa combination involved, and the responses from Apple and Visa.
■ Demonstration and attack setup
- A locked iPhone is tapped against a payment terminal; a small test charge and then a $10,000 charge are approved without unlocking.
- Researchers at the University of Surrey use a Proxmark, laptop, and burner phone to intercept and alter transaction data.
- The method relies on Express Transit Mode and three modified data points to bypass lock-screen, value-limit, and reader checks.
■ Why the iPhone + Visa combination is vulnerable
- An iPhone trusts the reader’s high-value or low-value label, while a Samsung phone checks the numerical amount.
- Visa’s online transactions avoid an asymmetric signature check that MasterCard applies in all transactions.
■ Responses and practical implications
- Apple and Visa comment on the likelihood of real-world fraud, refunds, and fraud rates; the researchers discuss disabling transit mode as mitigation.
- A sponsored segment presents Incogni’s personal-data removal service.
For viewers interested in cybersecurity, mobile payments, and consumer protection, the explanation focuses on this specific exploit rather than a broad survey of payment security. It offers a high-level understanding of how the attack works and what settings users can review.
📄 このページの紹介文は AI が独自に生成したものであり、著作権をはじめとする他者の権利(商標権・名誉権・プライバシー等)を侵害しないよう配慮しています。動画の著作権は各作成者に帰属します。