Hacker News new | ask | show | jobs
by notatoad 1431 days ago
the "server" in this case provides a one-time key to sign the transaction with, which is only valid for that transaction and that merchant. if you have a large antenna that can provide valid transaction keys for a trusted merchant, then yes, you have a significant exploit.

to my knowledge, nobody has ever successfully demonstrated an exploit of this nature.

1 comments

The "server" in this case is a rouge device.

It is trivially employed.

I’m not sure why the color of the device matters here