3 ms·
couple of countermeasures In CDA, the responses are encrypted by the card, which means a they can no longer be spoofed. The only lingering possibility of this
by JimmaDaRustla 11y ago
couple of countermeasures
In CDA, the responses are encrypted by the card, which means a they can no longer be spoofed.
The only lingering possibility of this type of attack occurring is in regions where offline transactions are still permitted, and if you can find a terminal which still does not have CDA capabilities or if you have a card which doesn't have CDA. Totally possible, but the opportunities are diminishing rapidly as the issued has been RESOLVED.
Edit: Found a decent write up on the CDA differences over DDA: http://www.infonomics-society.org/IJICR/Fraud%20Reduction%20on%20EMV%20Payment%20Cards%20by%20the%20Implementation%20of%20Stringent%20Security%20Features.pdf http://www.infonomics-society.org/IJICR/Fraud%20Reduction%20...
The CDA cards have this advantage over the DDA cards, in that the message signed by the ICC which includes an additional Application Cryptogram (AC), which is used to protect and validate the specific transaction messages (amount, time, etc) generated during the transaction. The ICC uses the AC Session Keys (derived from the ICC AC Master Key, shared only between the ICC and the card issuer) to place this MAC on the transaction details.