Samsung has issued a statement calling recent reports that highlighted a security flaw in its Samsung Pay service "inaccurate."
The multiple media reports are based on the Black Hat 2016 presentation of security researcher Salvador Mendoza, who detailed a method of extracting tokens from the Samsung Pay application and using them to carry out fraudulent transactions.
Attackers can extract payment tokens from the Samsung Pay app
Mendoza's research focuses on how the Samsung Pay app generates and uses tokens to authorize and perform financial transactions. He says that an attacker could predict future tokens based on past tokens the app generated.
He also explains that the app generates tokens that linger around for at least 24 hours if the user fails to use them, even after the user generates a second token to authorize o...
Intelligence View
⚡ tsecurity.de Intelligence
Samsung Calls Reports of Samsung Pay Security Flaw "Inaccurate"
Samsung has issued a statement calling recent reports that highlighted a security flaw in its Samsung Pay service "inaccurate." The multiple media reports are…