Episode Transcript
[00:00:00] Speaker A: Picture this. You know, you walk out to your mailbox and there it is, that distinct unmarked envelope from your bank.
[00:00:06] Speaker B: Well, yeah, you always know exactly what that is, right?
[00:00:08] Speaker A: You tear it open and inside is a shiny, pristine new credit card.
You go through that little ritual we all know so well, right?
[00:00:16] Speaker B: Peeling off the activation sticker.
[00:00:18] Speaker A: Exactly. You dial the number or you know, log into your app, you confirm your identity and boom, the new card is alive.
[00:00:25] Speaker B: And then comes the next step.
[00:00:27] Speaker A: Yeah, you take your old card, the one with the scratched up magnetic stripe, the worn out numbers. Its expiration date passed like a few days ago.
[00:00:36] Speaker B: So you might cut it in half if you're feeling diligent, but let's be
[00:00:39] Speaker A: honest, you might just toss it straight into the kitchen trash can. Because, I mean, it's expired, right? It's just a useless piece of dead plastic now.
[00:00:46] Speaker B: Well, it is entirely intuitive to think so. I mean, we are conditioned to believe that an expiration date is an absolute deadline.
[00:00:53] Speaker A: Right. Like milk in the fridge.
[00:00:55] Speaker B: Exactly. Once that date hits, the utility of the object is completely gone. You toss in the trash and you don't give it a second thought.
It is comforting to think of it as binary, you know, alive one minute, dead the next.
[00:01:08] Speaker A: But what if I told you that piece of plastic in your trash can is not actually dead? What if it's just dormant?
[00:01:15] Speaker B: Yeah, that's where this gets interesting, right?
[00:01:17] Speaker A: What if someone could reach into your trash, pull up that expired card and use it to buy a flat screen TV on your active bank account, all without ever touching the shiny new card currently sitting securely in your wallet?
[00:01:30] Speaker B: It's wild. That is the exact nightmare scenario we are looking at today. And honestly, it completely shatters our assumptions about how the modern financial ecosystem actually works.
[00:01:39] Speaker A: It really does. So we have a really interesting stack of sources for our mission today on this deep dive, we are primarily looking at this wild, slightly terrifying new cybersecurity study.
[00:01:51] Speaker B: The one out of the University of Massachusetts Amherst. Right.
[00:01:53] Speaker A: It's the one. These researchers have uncovered a phenomenon they are calling zombie credit cards.
[00:01:58] Speaker B: Such a great term for it.
[00:02:00] Speaker A: Yeah, it perfectly describes it. But we are also pulling in some really fascinating commentary from Priyanshu Adethaka, who goes by Pre. Right, Pre. He's a commercial real estate and hotel investment advisor. And he wrote this analysis connecting this cyber vulnerability to the way we manage physical assets and legacy systems, which is
[00:02:20] Speaker B: a completely different angle, but it fits so well.
[00:02:22] Speaker A: Exactly. So our goal for this deep dive is to figure out what these undead pieces of plastic actually are. How Bad actors are actively reviving them. And really, what this massive blind spot teaches us about the hidden vulnerabilities in the systems we trust blindly every day.
[00:02:39] Speaker B: Yeah, it serves as a perfect case study in the dangers of legacy infrastructure. I mean, we tend to assume these massive trillion dollar payment networks are just impenetrable fortresses.
[00:02:49] Speaker A: You'd think they would be.
[00:02:50] Speaker B: You would. But the UMass Amherst research highlights glaring gaps in how point of sale systems and banking networks in general actually verify the lifecycle of a card.
[00:02:59] Speaker A: Okay, well, let's unpack this, because before we can understand the heist itself, we really need to understand the. The biology, or rather the technology of these cards.
[00:03:09] Speaker B: Right. The anatomy of the flaw.
[00:03:10] Speaker A: Yeah. I think most of us look at the date printed on the front. Let's say it says valid through 8226. And we just assume the whole physical object just shuts down on September 1, which makes sense, but why isn't an expire card actually dead?
[00:03:26] Speaker B: So to understand that, we have to separate the physical object from the digital identity it carries.
When you look at your credit card, you see a piece of plastic with a printed expiration date.
[00:03:35] Speaker A: Right.
[00:03:36] Speaker B: Usually that lifespan is about three to five years. And that physical date is what you, the consumer, focus on. But inside that card, embedded in that little metallic square you tap or insert at the store.
[00:03:47] Speaker A: The chip.
[00:03:47] Speaker B: Right, the chip. There is a completely different reality happening in there. That chip operates on a standard called emv.
[00:03:55] Speaker A: Wait, before we go further, what actually is an EMV chip? I mean, we see those letters thrown around all the time in banking, but we. What do they actually mean?
[00:04:02] Speaker B: EMV stands for Europay, MasterCard, and Visa.
[00:04:07] Speaker C: Oh, okay.
[00:04:08] Speaker B: Yeah. They were the three companies that originally created the standard back in the 1990s to secure payment transactions. Because before EMV, we just used magnetic
[00:04:17] Speaker A: stripes, which were incredibly easy to clone.
[00:04:19] Speaker B: Were extremely easy. You could just skim them. So the industry moved to these chips.
[00:04:23] Speaker A: Okay. I always just assumed that little gold square was basically a tiny flash drive. Like it just holds my account number, the machine reads the file, and that's it.
[00:04:33] Speaker B: A lot of people think that.
[00:04:34] Speaker A: Are you saying it's actually doing something more complex?
[00:04:36] Speaker B: Oh, absolutely. It is actually doing active computing. Those chips are literally microscopic computers. They execute complex cryptographic operations.
[00:04:46] Speaker C: Wow.
[00:04:47] Speaker B: And inside that chip are internal digital certificates and cryptographic keys. Here is the critical disconnect that the researchers pointed out.
Those digital certificates and keys are mathematically valid for far, far longer than the three to five years printed on the
[00:05:02] Speaker A: front of the plastic okay, wait, so the plastic has a shelf life of, say, four years just because it physically degrades in my wallet.
[00:05:10] Speaker B: Right, exactly.
[00:05:11] Speaker A: But the digital brain inside of it might be perfectly capable of doing the math and, you know, shaking hands with a bank for a decade.
[00:05:18] Speaker B: That is the exact core of the issue. The cryptographic lifespan outlives the physical lifespan.
And this leads us to the backend flaw the UMass Amherst researchers highlighted.
[00:05:29] Speaker A: Which is what?
[00:05:30] Speaker B: When a bank issues you that shiny new renewal card in the mail, they almost always use the exact same primary account number. Your pan.
[00:05:38] Speaker A: Right. It's a continuation of your existing account.
[00:05:40] Speaker B: Yes, which makes total sense from a consumer experience standpoint. I mean, it would be a massive headache to have to update my card number for my Netflix, my gym membership, my electric bill every three years.
[00:05:52] Speaker A: Oh, yeah, that would be a nightmare. The bank keeps the 16 digit pan the same, right?
[00:05:56] Speaker B: The user experience dictates the continuity. But here's the catch. When they activate that new card, the banks frequently fail to immediately revoke or blacklist the internal cryptographic credentials of the old chip on their backend authorization servers.
[00:06:12] Speaker A: Wait, seriously?
[00:06:13] Speaker B: Seriously. They just leave the old digital identity acted in their system. They assume that because the printed date has passed, the physical card is out of commission and nobody will use it.
[00:06:25] Speaker A: Wow. It's like, say you decide to upgrade the locks on your front door. You hire a locksmith. They put a brand new, beautiful lock on the door, but instead of taking the old tumbling mechanism out completely, they just shove it to the side inside the door frame.
[00:06:38] Speaker B: That is a highly accurate way to look at it.
[00:06:41] Speaker A: So technically, if someone finds your old discarded key, it. It still turns the lock. The back door is just left wide open.
[00:06:47] Speaker B: Exactly. The banking networks have essentially left the old lock tumbler fully functional, relying entirely on the assumption that nobody will try to use the old key once the new one is issued, simply because the date on it says it shouldn't work.
[00:07:00] Speaker A: But wait, this brings up a massive question for me. Let's say I take that old card out of the trash and try to tap it at a grocery store.
[00:07:08] Speaker B: Okay?
[00:07:08] Speaker A: The machine asks the card for its expiration date. The chip sends over the date programmed into it, which matches the printed date. Which is in the past.
[00:07:17] Speaker B: Right.
[00:07:17] Speaker A: If the chip is still mathematically valid, shouldn't the physical expiration date being sent to the machine still trigger an immediate rejection at the terminal?
Like, why doesn't the cash register just look at the date and say, no, thanks, this expired last week?
[00:07:33] Speaker B: Well, this raises an important point, and it Is the exact hurdle. That brings us to the exploit itself. Because if you just took the expired card and tapped it directly on the terminal, and it would normally decline.
[00:07:44] Speaker A: Okay, so it does catch it.
[00:07:45] Speaker B: Yeah. The terminal would see the expired day and reject the transaction locally. But the attackers are not tapping the card directly. They are manipulating the conversation between the card and the terminal.
[00:07:56] Speaker A: Ah, okay, here's where it gets really interesting.
Because the researchers didn't use some, you know, supercomputer in a hacker's basement. They did this using surprisingly accessible stuff.
[00:08:07] Speaker B: Very accessible.
[00:08:08] Speaker A: So walk us through this. We relay attack.
[00:08:10] Speaker B: Yeah. The researchers demonstrated this using just two standard smartphones connected over a regular WI FI network.
[00:08:17] Speaker A: Okay, I have to stop you. How are standard off the shelf smartphones doing hacker stuff with credit card chips? What is the actual mechanism there?
[00:08:26] Speaker B: It utilizes the built in hardware that most modern phones already have. I mean, almost every smartphone today is equipped with NFC near field communication.
[00:08:35] Speaker A: Right, that's the technology that lets me tap my phone to pay for groceries. Using Apple pay, right?
[00:08:41] Speaker B: Yes. NFC is just a very short range radio technology. It allows two devices to communicate when they are within a few centimeters of each other.
[00:08:48] Speaker A: Okay.
[00:08:49] Speaker B: Now usually your phone uses NFC to act like a credit card, but these researchers wrote custom software that flips the script entirely. They use the phone's NFC reader to act like a point of sale terminal.
[00:09:00] Speaker A: Oh, wow. So the phone is reading the card instead of the card reading the phone.
[00:09:03] Speaker B: Correct. So here is how the heist plays out. The attacker has one smartphone, let's call it phone A, physically near the discarded expired card.
[00:09:14] Speaker A: Maybe they went dumpster diving and found it.
[00:09:16] Speaker B: Exactly. They hold phone A up to the old card. Phone A acts as a card reader. Then an accomplice takes phone B into a store and holds it up to the actual point of sale terminal at the cash register. Okay, and phone B is acting as a proxy for the card.
[00:09:31] Speaker A: So phone A reads the chip on the card in the trash, sends that data over WI fi to phone B, and phone B feeds it to the cash register. It's like an invisible extension cord.
[00:09:42] Speaker B: That is part of it. Yeah, but there's a deeper layer. It's not just a passive relay. As the data travels from phone A to phone B, the attackers use their custom software to intercept it in transit.
[00:09:52] Speaker A: Intercept it?
[00:09:53] Speaker B: Yes. They locate the specific string of data that contains the expiration date, and they simply rewrite it. They alter it to a date in the future.
[00:10:00] Speaker A: They just change the date? Like fixing a typo in a text document.
[00:10:04] Speaker B: Basically, yes. And Then phone B presents this freshly altered future expiration date to the point of sale terminal.
[00:10:11] Speaker A: I am completely lost on how that is possible. I thought these EMV chips were incredibly secure. I mean, I thought every single byte of data they sent was locked down tight with heavy encryption.
[00:10:22] Speaker B: You assume so.
[00:10:23] Speaker A: How can an attacker just casually intercept and rewrite the expiration date without breaking the entire transaction?
[00:10:30] Speaker B: Well, that is the core blind spot the UMass Amherst researchers exposed. And to understand it, we really have to look at the history of the technology.
In a standard EMV tap to pay transaction, the primary account number in the cryptographic keys are heavily authenticated, but the expiration date transmitted to the terminal is not cryptographically authenticated.
[00:10:50] Speaker A: Wait, what?
[00:10:50] Speaker B: Yeah, it is sent as a plain, unprotected data field.
[00:10:54] Speaker A: You're telling me a trillion dollar industry left the one piece of data that confirms whether the card is actually still in its valid lifespan, flying through the air, completely unprotected?
[00:11:04] Speaker B: I know it sounds crazy.
[00:11:06] Speaker A: Why on earth would they design it like that?
[00:11:08] Speaker B: You have to remember when the EMV standard was built back in the 1990s, point of sale terminals were slow. They were often connected via dial up phone lines, and sometimes they were completely offline.
[00:11:20] Speaker A: Oh, right, the old screeching modems.
[00:11:22] Speaker B: Exactly. Bandwidth and computing power were highly constrained back then. The system was designed so the terminal could do a very fast local check of the basic details, like the expiration date in plain text.
[00:11:33] Speaker C: Ah.
[00:11:34] Speaker A: So the machine needed to be able to say, you know, is this card even worth trying to process before it tied up the phone line for two minutes trying to do the heavy cryptographic math?
[00:11:44] Speaker B: Yes, precisely. It needed to read the date quickly and easily before establishing a secure cryptographic handshape with the bank. And unfortunately, that legacy design decision carried over into the modern era of tap to pay.
[00:11:56] Speaker A: That is wild.
[00:11:57] Speaker B: So today the cash register asks, what's your expiration date? The phone, pretending to be the card, says, I'm good until 2028. The cash register says, great, you passed the first test. Now let's do the complex math to prove you're the real account.
[00:12:10] Speaker A: And because the bank never revoked the internal cryptographic keys of the old chip, the math still checks out.
[00:12:17] Speaker B: Exactly. The transaction is approved, the issuing bank authenticates the account, they authenticate the cryptographic keys, but they fail to strictly cross check the physical card's printed expiration status against what the terminal is suddenly claiming.
[00:12:31] Speaker A: Because they're just trusting the terminal.
[00:12:33] Speaker B: Right. The bank is so focused on the complex cryptographic puzzle that they accept the new fake date. Because the underlying math is still valid.
[00:12:42] Speaker A: So as a consumer, you don't even have to lose your active wallet to be robbed. Your current active account, the one tied to the shiny new card safely tucked in your pocket, can be drained by someone who literally just found your trash.
[00:12:55] Speaker B: Yeah, it essentially means dormant plastic is an act of liability. It's just waiting for a relay attacker to bridge the gap.
[00:13:01] Speaker A: Okay, well, if the front door is this easily bypassed by a couple of phones, why aren't we seeing billions of dollars drained every day? I mean, the banks must have a fallback. Let's look at the defenses. What is the immune system response to this zombie card virus?
[00:13:15] Speaker B: Well, the card networks and financial institutions point out that while this attack is theoretically sound and was proven by researchers in a controlled environment, there are multi layered defenses in place to mitigate mass abuse. They aren't just relying on the hardware anymore.
[00:13:29] Speaker A: Because banks are tracking behavior now, not just the math.
[00:13:32] Speaker B: Exactly. They employ massive fraud detection engines. They use location based heuristics and velocity checks. For instance, if your active card was used to buy a coffee in New York at 8.0am and suddenly your expired card is trying to buy electronics in Chicago via a relay attack at 8:05am
[00:13:52] Speaker A: that's going to throw a red flag.
[00:13:53] Speaker B: A huge one. The system's real time transaction monitoring is going to flag that anomaly instantly, regardless of whether the cryptographic keys check out.
[00:14:02] Speaker A: So they were relying on context to catch the fraud. Even if the technical front door is technically unlocked.
[00:14:08] Speaker B: They are. But what's fascinating here is that the ultimate defense against this specific relay attack isn't actually a better physical card.
[00:14:16] Speaker A: What is it then?
[00:14:16] Speaker B: It's moving away from the physical plastic altogether. The study highlights that tokenized mobile wallets, things like Apple Pay and Google Pay, are completely immune to this physical relay modification.
[00:14:29] Speaker A: Wait, completely immune? Nothing is completely immune. You're telling me having my card loaded onto a smart card smartphone, a device that is constantly connected to the Internet and constantly vulnerable to malware, is somehow safer than a disconnected piece of plastic
[00:14:43] Speaker B: against this specific vector of attack? Yes, it actually is fundamentally safer. And the reason comes down to how tokenized mobile wallets handle data compared to physical cards.
[00:14:55] Speaker A: Okay, how so?
[00:14:56] Speaker B: They don't rely on static data fields that can be intercepted and altered.
[00:15:00] Speaker A: How does that work in practice? Like when I tap my phone. What's different?
[00:15:03] Speaker B: When you use a mobile wallet, the system generates a unique dynamic cryptogram for every single transaction. It's essentially a one time use code.
[00:15:11] Speaker A: Oh, I see.
[00:15:11] Speaker B: There Is no static expiration date floating around in plain text for an attacker to modify.
If an attacker tries to intercept and alter any part of a mobile wallet transaction in transit, the dynamic cryptogram breaks, the math no longer aligns, and the transaction fails in instantly.
[00:15:28] Speaker C: Wow.
[00:15:29] Speaker A: So the irony is that the digital abstraction of your card is actually more structurally sound than the physical object issued
[00:15:36] Speaker B: by the bank in this case.
[00:15:38] Speaker A: Yeah, but I mean, not everyone uses mobile wallets. And we still have millions of physical cards circulating and expiring every day. What are the industry fixes for the cards themselves? What should we be watching for?
[00:15:48] Speaker B: In the near future, we are going to see a multi pronged approach to patch this vulnerability.
First, expect major issuer protocol updates. Card issuers and payment processors are going to have to patch their back end verification logic.
[00:16:02] Speaker A: Which means doing what exactly?
[00:16:04] Speaker B: They need to mandate strict asynchronous mashing between the transmitted card expiry date coming from the terminal and their own internal database records.
[00:16:12] Speaker A: Meaning the bank needs to look at the date the terminal is sending and say, hold on. Our internal server records say this specific physical card expired in 2024. Why is this cash register telling me it's 2020 and flag it?
[00:16:26] Speaker B: Exactly. The back end needs to stop trusting the terminal's word on the expiration date. Second, we are going to see point of sale firmware patches. Terminal software needs updates to enforce tighter cryptographic validation during that very first NFC handshake.
[00:16:41] Speaker A: And what about us, you know, the consumers? What are they going to ask us to do?
[00:16:45] Speaker B: We are definitely going to see a push for physical destruction guidance. Bants will likely have to launch awareness campaigns to remind customers that simply tossing an expired card is a real security risk.
[00:16:55] Speaker A: So no more just tossing it in the trash.
[00:16:57] Speaker B: Nope. They're going to tell you to physically destroy the chip. You need to get a pair of heavy duty scissors and cut right through the metallic square, physically severing the microscopic antenna and the computing chip itself.
[00:17:08] Speaker A: So an expired card is not a dead card until its chip is literally in pieces.
[00:17:13] Speaker B: Until banking networks fix their back end security models, that dormant plastic is an open connection to your bank account.
[00:17:21] Speaker A: Man.
So what does this all mean? We've talked about credit cards, we've talked about smartphones, NFC and cryptographic handshakes.
But it feels like there is a much larger principle at play here. And this is where those notes from our second source come in, right?
[00:17:36] Speaker B: Yeah. If we connect this to the bigger picture, it becomes clear that this isn't just a story about credit cards. It is a Story about the illusion of expiration across all our system.
[00:17:45] Speaker A: The illusion of expiration, yes.
[00:17:47] Speaker B: Priyanshu Edithakar, a commercial real estate and hotel investment advisor, looked at this cybersecurity vulnerability through the lens of operational asset management.
[00:17:56] Speaker A: That's such an interesting pivot. Like, how does a commercial real estate advisor look at a highly technical credit card hack and see a connection to building management?
[00:18:05] Speaker B: He identified a core operational truth that applies just as much to a skyscraper as it does to an EMV chip. Pre notes that security is only as strong as its weakest legacy assumption.
[00:18:16] Speaker A: The weakest legacy assumption, meaning we constantly implement new technology and just assume the old stuff magically stops working when we roll out the new stuff.
[00:18:27] Speaker B: We'll see this everywhere in both the physical and digital realms. I mean, we upgrade systems, we swap out hardware, we issue new credentials to employees, and we just blindly assume the old access points naturally terminate on their own.
[00:18:39] Speaker A: But they often don't.
[00:18:41] Speaker B: No, they don't.
[00:18:42] Speaker A: I can completely see how that applies to real estate or hotel management. I mean, imagine managing a massive commercial property or a hospitality asset.
You decide to upgrade the key card system for the entire building because the old one is outdated.
[00:18:57] Speaker B: A very common scenario, right?
[00:18:58] Speaker A: And you give everyone new badges. But if you don't actively go into the server and meticulously deauthorize every single one of the old badges, a former employee or someone who finds a discarded badge in the parking lot could still swipe into the building.
[00:19:12] Speaker B: It is the exact same structural vulnerability. The physical card expired in the minds of the management team. The calendar date passed, but the digital credential was never explicitly killed on the backend. The server still recognizes the math. Pry applies this to corporate financial accounts, operational software, and even personal data.
We constantly leave these digital backdoors open because we trust the illusion of expiration.
[00:19:37] Speaker A: We think because something is past its date, the universe just takes care of it for us, like leaves decaying in the fall.
[00:19:44] Speaker B: But the digital world doesn't decay naturally like biological matter. A cryptographic key doesn't rot. It stays perfectly pristine and mathematically valid until it is intentionally destroyed.
[00:19:56] Speaker A: That's a great way to put it.
[00:19:57] Speaker B: Pry's ultimate conclusion is that physical and digital retirement must be intentional and definitive.
Never assume an expired credential is safe.
[00:20:06] Speaker A: Right? It is not neutral.
[00:20:07] Speaker B: It is an active liability until it is physically destroyed or digitally eradicated.
[00:20:11] Speaker A: That really shifts the perspective. It makes you realize how many loose ends we leave trailing behind us in our digital lives.
So, just to wrap this up, the UMass Amherst researchers have shown us that an expired credit card is basically a zombie waiting to be woken up. Pretty much because of legacy tech debt from the 1990s.
A thief with two standard smartphones and a wi fi connection can read your discarded card, rewrite the unencrypted expiration date, bypass the point of sale terminal, and use your old card's still active cryptographic keys to drain your current account.
[00:20:44] Speaker B: It's quite the chain of events, but it's very real. And while fraud detection engines and dynamic mobile wallets offer strong defenses, the structural flaw remains. The banking backend is trusting old math over physical reality.
[00:20:57] Speaker A: It is definitely a wake up call to take matters into our own hands. Get out those scissors, find the metallic chip on your old cards and just cut it in half. Make the retirement of that card intentional and definitive.
[00:21:09] Speaker B: Because until you destroy the physical hardware, that card is fully capable of holding a financial conversation with your bank. You just aren't the one doing the talking anymore.
[00:21:18] Speaker A: Which leaves us with a lingering question for you to think about. Today we've seen how multi billion dollar financial institutions can completely forget to lock the back doors on their legacy payment system.
[00:21:28] Speaker B: They left the old tumblers in the
[00:21:29] Speaker A: lock exactly because they assumed the physical date was enough.
So what? Expired digital keys in your own life are sitting dormant right now? Think about your old passwords. You know, the lingering app permissions on your phone or the access granted to former colleagues on shared documents.
[00:21:48] Speaker B: It's a long list for most people.
[00:21:50] Speaker A: If a major bank can leave a zombie credit card alive in your kitchen trash can, what else in your life is just waiting for someone to revive it?
[00:21:57] Speaker B: It is definitely something to audit in
[00:21:59] Speaker A: your own those scissors handy? And stay curious.
[00:22:02] Speaker C: You've got the perspective. Now it's time to drive the news forward to ensure you never miss a market shift. Tap subscribe on Spotify, Apple Podcasts or wherever you listen.
If today's insights are going to impact your strategy, share this episode with a colleague or investment partner who needs to see the big picture.
For actionable guides, newsletter subscriptions and direct advisor consultation, head over to bearinvestors. Com.
Thank you for listening. We'll watch the market closely until next week.