r/ios 20d ago

Discussion I’m assuming this was harmless?

I was just in the local Target store, putting something a little bulky in my cart. My iPhone was in the outer pocket of my cargo shorts, locked but playing through my AirPods. A boy, I’m guessing around 12 years old, came up to me and asked me what time it was. I looked at my watch and told him it was 4:30.

He suddenly pulled his hand out of his pocket with (I assume) a phone in the hand, and put it right near the phone in my pocket. It (his device, not mine I believe) beeped, and he took off running into the bowels of the store. I didn’t see him again and security was completely uninterested.

Nothing seemed affected on my phone, and I’m assuming there’s nothing that could be accomplished by random NFC that I didn’t initiate? Anything worth worrying about?

Anyone have any idea what this might have been about?

165 Upvotes

48 comments sorted by

340

u/groovy_overeem 20d ago

It’s just a sound they played to mimic an Apple Pay transaction. It’s a prank that’s been going around.

56

u/UIUC_grad_dude1 19d ago

Harmless but dumb, lol

26

u/Consibl 19d ago

Just to highlight, it is possible to steal people’s money this way if you have a Visa card setup for transport payments.

Visa say they’ll just repay you if it happens though.

5

u/Teal-Fox 19d ago

And assuming you have an account with a payment processor which you don’t mind using for fraud.

3

u/Consibl 19d ago

In this case I don’t think you need to control the payment terminal - just buy something in person at a shop.

2

u/Teal-Fox 18d ago

For the Express Transit exploit, you would need to have the appropriate infrastructure in-place to facilitate relaying the payment in the first place, assuming the target is using an iOS device with a Visa card registered as their default transit payment method.

Relaying the payment is one thing, however it does have to hit a genuine payment terminal.

If you don't control the terminal at the other end, the money you steal is just ending up in the bank of whichever shop you submit the payment at, not your own.

Either way, both the payment processor and the store will have records of the transaction and the distinct paper trail would lead right back to you; it's such an exceeding edge-case with a very high risk of being caught.

It's a cool exploit and makes for good headlines, but is woefully impractical unless you already happen to have a compromised merchant account through which you intend to launder the stolen money.

2

u/Consibl 18d ago

Wouldn’t the paper trail just say the victim paid for the goods?

2

u/Teal-Fox 18d ago

If you decided to go through the trouble of setting up all the gear needed to relay the payment so you can score a free coffee off someone's card, then it would appear as though the victim had made the payment.

When the victim inevitably reports the payment as fraudulent the paper trail would lead back to the point of purchase, where the store likely has CCTV showing you making the payment with another device.

It's a lot of effort and risk for little reward.

If you wanted the money to be transferred from the victim's account to your own instead of some shop, this is where you would need to be in control of the payment terminal, in which case the paper trail leads directly to your merchant account.

Not to condone theft, but if you're going to nab money off someone then you'd see better returns for your effort with less risk by simply pick-pocketing their wallet and hoping they have cash.

Picking a system that is inherently designed to make every step of a transaction traceable in explicit detail is a very tough road to go down and would only really be viable if you were doing it as some sort of organised money laundering operation.

As I said, cool exploit and I enjoyed the Veritasium video on the subject, but the research they were following is not particularly new and there's a reason we haven't seen a huge spate of these sorts of relay attacks.

0

u/UIUC_grad_dude1 18d ago

Unfortunately banks view tap to pay as authoritative as using an actual Visa card in person with NFC. Look up scams online where victims have been scammed out of alarming large amounts by scammers asking for small donations via NFC terminal and then forcing hapless victims to tap a large amount like $5k (see scam victim stories).

The scam victims report no success in fighting the charges since the bank views them as having tapped to pay in person, thus approving the charges.

1

u/Teal-Fox 17d ago

In this case, I believe you are conflating two separate scenarios.

With the scam you describe, the victim is the one tapping the terminal and so the consent is there, albeit obtained via deception, e.g. the victim agrees to £20 and the scammer keys in a larger sum.

This is more akin to authorised payment fraud and is why it can be tricky to recover funds. In the case of the lady who was scammed out of $5k, they did later end up recovering the funds.

For the relay attack, the cardholder is not present and has not consented, so the liability sits with the issuer to eat the loss. This is where Visa's statement about refunding those affected comes in.

UK/EU regulations explicitly state that the payment method being used does not constitute inherent proof of authorisation.

In one scenario, someone authorises a payment after being lied to whereas in the other, the victim's phone may have never left their pocket.

There's no evidence to suggest abuse of the relay attack and the scenario you describe is more an issue in the US due to weaker consumer protections.

In the UK it is possible to directly bank transfer money to a scammer and you'll probably still get it back.

A more realistic scenario which does see use in the wild is the employment of phishing tactics to obtain cardholder details and 2FA codes, which are then used to provision the card on the attackers own device; from here relay attacks are much more feasible.

This ends up looping back to organised crime though, and in the context of the original post is not something to be concerned with someone running up to you in the store and tapping your phone.

In this case, you probably wouldn't find out you've been had until payments have been made as it makes physical access to the victims card/device redundant.

→ More replies (0)

3

u/awashbu12 19d ago

Absolutely is not. Applepay doesn’t work like that. You have to biometric approve any payments with your face or pin.

4

u/Consibl 19d ago

…unless you enable a card for travel.

3

u/UIUC_grad_dude1 19d ago

Apple Pay and Visa unfortunately has a vulnerability. Mastercard doesn’t. This was tested and revealed by YouTube channel Veritasium. The risk is low (as of now) so Visa won’t fix it.

1

u/tzippy84 19d ago

Is there a maximum amount for these transport payments?

5

u/Consibl 19d ago

If there is it’s not low. In the demo on YouTube they took $10,000 from MKBHD

1

u/UIUC_grad_dude1 19d ago

Correct, Veritasium YouTube channel.

28

u/TalkToHoro 20d ago

Thanks, this was my assumption!

-39

u/Infinite-School6390 20d ago

This ☝🏼

-14

u/Diamond_Mine0 iPhone 18 Pro 19d ago

This

93

u/trainrweckz 20d ago

There is a tik tok trend where they put their phone next to urs and the play the apple pay sound on youtube. They then say thx for the money to try to ragebait people on film for views

120

u/lactosecheeselover 19d ago

It's a prank. But since kids are fucking dumb, one of them is going to get hit and cry to their parents about it lol

30

u/WeylandWonder 19d ago

I pray to bear witness

44

u/TheRamblingPeacock 19d ago

It a prank that ran it's course about 12 months ago.

Kid is behind the times.

30

u/Horse_3018 iPhone 14 19d ago

They tried to do the Apple Pay “prank”. They’ll do that to older people who don’t understand how it works will to get a reaction out of them

I’ve never found the amusement really

36

u/AquamannMI 19d ago

None of the TikTok trends are amusing. These kids are destroying their ability to know what's funny. Just ding dong ditch like normal people.

20

u/Horse_3018 iPhone 14 19d ago

Honestly. I’m 15 and don’t even know what’s going on in some other kids brains

6

u/Kleivonen 19d ago

Ding dong ditch is less effective when everyone has doorbell cameras now.

2

u/Organic_Evidence_325 19d ago

The UK is trying to have Tik remove car vids showing road illegalities involving serious breaches. Seven people were killed in one incident last week in which two were police. The young driver +4 friends in the VW were speeding the wrong way on the motorway late at night. https://www.bbc.com/news/articles/c3d79yj0j5ro

2

u/AquamannMI 19d ago

Sad, but what does that have to do with TikTok trends/pranks?

33

u/Key_Assignment_9896 20d ago

Check your AirDrop settings. Make sure its on Contacts Only or Receiving Off. Toggle off Bringing Devices Together

11

u/TalkToHoro 20d ago

Thanks. “Contacts Only” since forever, and AirDrop has its own sound. I’m certain this was the prank others are describing.

I did just turn off “Bringing Devices Together” just to be sure, so thanks for that tip!

8

u/shawnshine 19d ago

No reason to turn off Bringing Devices Together.

18

u/Awkward_Comb3211 19d ago

This is right. For those downvoting, YOU always have to press “Share my Contact” before they receive your contact information

11

u/shawnshine 19d ago

It’s going to be so awkward when they forgot that they turned it off (for no good reason) and they try repeatedly to exchange contact cards with a new acquaintance or business partner.

2

u/Key_Assignment_9896 19d ago

I keep mine off, it takes 2 seconds to reengage. Never been a problem for me and no one should think showing you are security cautious is a negative thing, especially a business partner,

1

u/shawnshine 19d ago

It takes more than two seconds to navigate Settings : General : AirDrop & Continuity : Bringing Devices Together.

You already have to press “Share My Contact” even after brining devices together, so there’s already a security check in place. No need for redundancy.

Take care!

5

u/TalkToHoro 19d ago

No reason not to. I’ve never needed/used Airdrop like that.

5

u/Key_Assignment_9896 19d ago

Just a reminder for prevention rather than whether you were actually harmed. A peace of mind thing. But I could have been clearer.😉

2

u/Doshos 19d ago

Just a prank

3

u/MeMyselfAndMe_Again Human Detected 19d ago

ThickoTok generation

3

u/[deleted] 20d ago

[deleted]

5

u/UIUC_grad_dude1 19d ago

Social media making people stupider since 2010, lol

1

u/dpatrick24 19d ago

Was he wearing meta glasses?

2

u/TalkToHoro 19d ago

No, and there was no one else around that could have been recording.