News

Researcher reveals flaws in Samsung Pay tokenization

Wednesday 10 August 2016 09:04 CET | News

The researcher Salvador Mendoza has said he discovered flaws in Samsung Pays tokenization mechanism that could allow hackers to steal users tokens and make fraudulent purchases.

According to Mendoza, Samsungs tokenization process, which replaces payment card data with random symbols during transactions to render the data useless to thieves, is not as randomized as it could be, potentially allowing malicious hackers to ultimately guess future tokens.

Additionally, the researcher showed that attackers can steal tokens from a users phone using a device that steals over-the-air signals from Samsungs MST technology, which mimics the magnetic stripes of payment cards in order to enable purchases at older point-of-sale terminals.

Samsung disputed the findings, noting that the report regarding the security of Samsung Pay is inaccurate.


Free Headlines in your E-mail

Every day we send out a free e-mail with the most important headlines of the last 24 hours.

Subscribe now

Keywords: tokenization, mobile security, Token, fraud, Samsung Pay, Salvador Mendoza, Black Hat
Categories: Fraud & Financial Crime
Companies:
Countries: World
This article is part of category

Fraud & Financial Crime






Industry Events