Stories
Slash Boxes
Comments

SoylentNews is people

posted by chromas on Wednesday April 11 2018, @03:01PM   Printer-friendly
from the a-bluetooth-dong'l-do-ya dept.

Fuze card is wide open to data theft over Bluetooth. A fix is on the way.

The makers of the programmable Fuze smart card say it's powerful enough to be your wallet in one card yet secure enough to be used the same way as traditional payment cards—including trusting it to restaurant servers when paying the bill. But it turns out that convenience comes with a major catch. A flaw makes it possible for anyone with even brief physical control of the card to surreptitiously siphon all data stored on the device.

Fuze representatives said they're aware of the vulnerability and plan to fix it in an update scheduled for April 19. They also thanked the two researchers who, independent of one another, discovered the vulnerability and privately reported it. So far, however, Fuze officials have yet to fully inform users of the extent of the risk so they can prevent private data stored on the cards from being stolen or tampered with until the critical flaw is repaired.

Mike Ryan, one of the two researchers, said he created attack code that impersonated the Android app that uses a Bluetooth connection to load credit card data onto the smart cards. While the official Fuze app takes care to prevent pairing with cards that have already been set up with another device, Ryan's rogue app had no such restrictions. As a result, it allowed him to take complete control of a card, including reading, changing, or adding payment card numbers, expiration dates, and card-verification values.

https://arstechnica.com/?p=1290811

-- submitted from IRC


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2, Funny) by Anonymous Coward on Wednesday April 11 2018, @03:55PM (2 children)

    by Anonymous Coward on Wednesday April 11 2018, @03:55PM (#665402)

    Let us know when it's powerful enough to be a purse. Some of us need to store tampons, eyeliner, and other necessities in our wallets.

    Starting Score:    0  points
    Moderation   +2  
       Funny=2, Total=2
    Extra 'Funny' Modifier   0  

    Total Score:   2  
  • (Score: 2, Funny) by Anonymous Coward on Wednesday April 11 2018, @04:13PM (1 child)

    by Anonymous Coward on Wednesday April 11 2018, @04:13PM (#665412)

    There's a better solution than a purse for that kind of thing. It's called a "backpack".

    In addition to feminine things, you can keep things like a tablet or laptop computer, power supply, a charger for your phone, extra batteries for your phone or laptop, a rain jacket, gloves, hat (in case it gets cold), some extra socks (this came in handy when we were caught in a downpour on vacation and my girlfriend got her feet soaking wet), some food, books, and lots more. They also come in different sizes so you can use a tiny, lightweight one if you don't need to haul around a laptop or books that day. And unlike a purse or briefcase or something like that, a backpack sits symmetrically on your back so it's better for your spine.

    • (Score: 0) by Anonymous Coward on Wednesday April 11 2018, @04:46PM

      by Anonymous Coward on Wednesday April 11 2018, @04:46PM (#665430)

      .......