ÈóÀÜ¿¨·¿·èºÑ¥µ¡¼¥Ó¥¹¤ÎApple Pay¤Ï¡¢iPhone¤äApple Watch¤Ç¼ê·Ú¤Ë»Ùʧ¤¤¤¬²Äǽ¤Ë¤Ê¤ëµ¡Ç½¤Ç¤¹¡£Apple Pay¤Ç¤Ï´ðËÜŪ¤Ë»Ùʧ¤¤»þ¤Ë¤ÏFace ID¤äTouch ID¤Ç¥í¥Ã¥¯¤ò²ò½ü¤¹¤ë¤³¤È¤Ç¡¢¡ÖüËö¤Î»ý¤Á¼ç¤¬»Ùʧ¤¤¤ò¹Ô¤Ã¤Æ¤¤¤ë¤³¤È¡×¤ò¼¨¤¹É¬Íפ¬¤¢¤ê¤Þ¤¹¡£¤·¤«¤·¡¢°ìÉô¤Î¸òÄ̵¡´Ø¤Ê¤É¤Ç¤ÏüËö¤Î¥í¥Ã¥¯¤ò²ò½ü¤·¤¿¤êÆÃÄê¤Î¥¢¥×¥ê¤ò³«¤¤¤¿¤ê¤¹¤ë¤³¤È¤Ê¤¯¡¢±¿Ä¤λÙʧ¤¤¤¬²Äǽ¤Ç¤¹¡£¤³¤Îµ¡Ç½¤Ë¸ºß¤¹¤ëÀȼåÀ­¤òÍøÍѤ¹¤ë¤³¤È¤Ç¡¢Ç§¾Ú¤Ê¤·¤ÇApple Pay¤Î»Ùʧ¤¤¤¬²Äǽ¤Ë¤Ê¤ë¤È¥»¥­¥å¥ê¥Æ¥£¸¦µæ¼Ô¤¬·Ù¹ð¤·¤Æ¤¤¤Þ¤¹¡£

Practical EMV Relay Protection

https://practical_emv.gitlab.io/

Apple Pay with Visa Hacked to Make Payments via Unlocked iPhones | Threatpost

https://threatpost.com/apple-pay-visa-hacked-unlocked-iphones/175229/

Researchers discover security flaw with Apple Pay and Visa

https://www.siliconrepublic.com/enterprise/apple-pay-visa-contactless-hack-iphone

Apple Pay with VISA lets hackers force payments on locked iPhones

https://www.bleepingcomputer.com/news/security/apple-pay-with-visa-lets-hackers-force-payments-on-locked-iphones/

¡Öǧ¾Ú¤Ê¤·¤ÇApple Pay¤Ç¤Î»Ùʧ¤¤¤¬²Äǽ¤Ë¤Ê¤ëÀȼåÀ­¡×¤Ë¤Ä¤¤¤ÆÊó¹ð¤·¤¿¤Î¤Ï¡¢¥¤¥®¥ê¥¹¤Î¹ñ²È¥µ¥¤¥Ð¡¼¥»¥­¥å¥ê¥Æ¥£¥»¥ó¥¿¡¼(NCSC)¤¬»Ù±ç¤¹¤ë¥Ð¡¼¥ß¥ó¥¬¥àÂç³Ø¤È¥µ¥ê¡¼Âç³Ø¤Î¸¦µæ¥Á¡¼¥à¡£Æ±¸¦µæ¥Á¡¼¥à¤Ë¤è¤ë¤È¡¢Apple¤¬iPhone¤äApple Watch¸þ¤±¤ËÄ󶡤·¤Æ¤¤¤ëÈóÀÜ¿¨·¿·èºÑ¥µ¡¼¥Ó¥¹¤ÎApple Pay¤È¡¢¥¯¥ì¥¸¥Ã¥È¥«¡¼¥É²ñ¼Ò¡¦Visa¤Î¥·¥¹¥Æ¥à¤ÎξÊý¤Ë¸ºß¤¹¤ëÀȼåÀ­¤òÍøÍѤ¹¤ë¤³¤È¤Ç¡¢Ç§¾Ú¤Ê¤·¤ÇApple Pay¤Ç¤Î»Ùʧ¤¤¤¬²Äǽ¤Ë¤Ê¤ë¤È¤Î¤³¤È¡£

¸¦µæ¥Á¡¼¥à¤Ë¤è¤ë¤È¡¢Ç§¾Ú¤Ê¤·¤ÇApple Pay¤Ç¤Î»Ùʧ¤¤¤ò¹Ô¤¦¤Î¤ËɬÍפʾò·ï¤Ï¡¢Ã¼Ëö¤Î¥¹¥ê¡¼¥×¤ò²ò½ü¤·¤¿¤ê¥í¥Ã¥¯¤ò²ò½ü¤·¤¿¤ê¥¢¥×¥ê¤ò³«¤¤¤¿¤ê¤¹¤ë¼ê´Ö¤Ê¤¯Åż֤ʤɤθòÄ̵¡´Ø¤Ç±¿Ä¤λÙʧ¤¤¤¬²Äǽ¤Ë¤Ê¤ë¡Ö¥¨¥¯¥¹¥×¥ì¥¹¥«¡¼¥É¡×¤¬Í­¸ú¤Ë¤Ê¤Ã¤Æ¤¤¤ë¤³¤È¤Î¤ß¤Ç¤¹¡£Apple Pay¤Ç¤Ï¥¨¥¯¥¹¥×¥ì¥¹¥«¡¼¥É¤¬Í­¸ú¤Ë¤Ê¤Ã¤Æ¤¤¤ë¤«Èݤ«¤ò¥«¡¼¥É¼è°ú½¤¾þ»Ò(CTQ)¤ÇȽÊ̤¹¤ë¤Î¤Ç¤¹¤¬¡¢¤³¤ÎCTQ¤òÊѹ¹¤Ç¤­¤Æ¤·¤Þ¤¦¤¿¤á¡¢¸òÄ̵¡´Ø¤Ê¤É¤òÍøÍѤ·¤Æ¤¤¤ë¾ì¹ç¤Ç¤Ê¤¯¤È¤â¡Öǧ¾Ú¤Ê¤·¤ÇApple Pay¤Ç¤Î»Ùʧ¤¤¤¬²Äǽ¤Ë¤Ê¤Ã¤Æ¤·¤Þ¤¦¡×¤È¤¤¤¦¤ï¤±¤Ç¤¹¡£



¤³¤Î¥¨¥¯¥¹¥×¥ì¥¹¥«¡¼¥É¤òVisa¤Î¥¯¥ì¥¸¥Ã¥È¥«¡¼¥É¤ÇÍøÍѤ·¤Æ¤¤¤ë¾ì¹ç¡¢Èóɸ½à¤Î¥Ð¥¤¥È¥·¡¼¥±¥ó¥¹¤òÁ÷¿®¤¹¤ë¥«¡¼¥É¥ê¡¼¥À¡¼¤ò»ÈÍѤ¹¤ë¤³¤È¤ÇCTQ¤òÊѹ¹¤¹¤ë¤³¤È¤¬²Äǽ¡£¤³¤ì¤Ë¤è¤ê¡¢Ç§¾Ú¤Ê¤·¤Ç¤Î»Ùʧ¤¤¤¬²Äǽ¤È¤Ê¤Ã¤Æ¤·¤Þ¤¦¤È¤Î¤³¤È¡£Æ±¸¦µæ¤Ë·È¤ï¤Ã¤¿¥±¥ó¡¦¥Þ¥ó¥í»á¤Ï¡¢¡ÖÏÀÍýŪ¤Ë¤ÏÃϲ¼Å´¤Ê¤É¤Ë¾è¤Ã¤Æ¤¤¤ë¾èµÒ¤Î¥Ý¥±¥Ã¥È¤ËÆþ¤Ã¤Æ¤¤¤ëiPhone¤Ë¡¢ÈóÀÜ¿¨·¿¤Î·èºÑ¥Þ¥·¥ó¤ò¶á¤Å¤±¤ë¤À¤±¤Ç¶âÁ¬¤òÅð¤à¤³¤È¤¬²Äǽ¤Ë¤Ê¤ë¡×¤È»ØŦ¤·¤Æ¤¤¤Þ¤¹¡£

¹¶·â¤ËɬÍפʤΤϡ¢·èºÑ¥ê¡¼¥À¡¼¤Ç¤¢¤ëIC¥¯¥ì¥¸¥Ã¥È¥«¡¼¥É(EMV)Âбþ¥ê¡¼¥À¡¼(±¦¤«¤é1ÈÖÌÜ)¤È¡¢EMVÂбþ¥ê¡¼¥À¡¼¤ÈÄÌ¿®¤¹¤ë¤¿¤á¤ÎNFC¥Á¥Ã¥×¤òÅëºÜ¤·¤¿Android¥¹¥Þ¡¼¥È¥Õ¥©¥ó¤Ê¤É¤ÎüËö(±¦¤«¤é2ÈÖÌÜ)¡¢¤½¤·¤Æ¥¨¥¯¥¹¥×¥ì¥¹¥«¡¼¥É¤¬ÍøÍѲÄǽ¤ÊüËö¤Ç¤¢¤ë¤ÈiPhone¤Ë¸íǧ¤µ¤»¤ë¤¿¤á¤ÎProxmarküËö(º¸¤«¤é2ÈÖÌÜ)¤Î3¤Ä¡£



°Ê²¼¤Î²èÁü¤ò¥¯¥ê¥Ã¥¯¤¹¤ë¤ÈºÆÀ¸¤µ¤ì¤ëÆ°²è¤ÎÃæ¤Ç¡¢iPhone¤«¤é¸òÄ̵¡´Ø¤Ç¤Ï¤Ê¤¤Europay¡¢MasterCard¡¢Visa¤È¤¤¤Ã¤¿¥¯¥ì¥¸¥Ã¥È¥«¡¼¥É¥ê¡¼¥À¡¼¤Ë¡¢1000¥Ý¥ó¥É(Ìó15Ëü±ß)¤òÁ÷¶â¤¹¤ëÍͻҤ¬³Îǧ¤Ç¤­¤Þ¤¹¡£¸¦µæ¥Á¡¼¥à¤Ë¤è¤ë¤È¡¢»Ùʧ¤¤¤ËÀ©¸Â¤Ï¤Ê¤¤¤È¤Î¤³¤È¡£



¸¦µæ¥Á¡¼¥à¤Ï¤³¤Î¹¶·âÊýË¡¤Ë¤Ä¤¤¤Æ¡¢¡Öŵ·¿Åª¤ÊÃæ´Ö¼Ô¹¶·â¤Ç¤¢¤ê¡¢Proxmark¤¬iPhone¤Ë¡ØËâË¡¤Î¥Ð¥¤¥È¡Ù¤òÁ÷¿®¤¹¤ë¤³¤È¤Ç¡¢»Ùʧ¤¤¤ò¡Ø¥¨¥¯¥¹¥×¥ì¥¹¥«¡¼¥É¡Ù¤Ë¤è¤ë¤â¤Î¤È¿®¤¸¹þ¤Þ¤»¡¢Ç§¾Ú¤Ê¤·¤Ç¤Î»Ùʧ¤¤¤ò¾µÇ§¤·¤Æ¤·¤Þ¤¦¤ï¤±¤Ç¤¹¡×¤Èµ­¤·¤Æ¤¤¤Þ¤¹¡£

¤Ê¤ª¡¢¸¦µæ¥Á¡¼¥à¤Ï2020ǯ10·î¤È2021ǯ5·î¤Î2Å٤ˤ錄¤êApple¤ÈVisa¤ËÂФ·¤ÆÌäÂê¤òÊó¹ð¤·¤Æ¤¤¤Þ¤¹¤¬¡¢µ­»öºîÀ®»þÅÀ¤ÇÀȼåÀ­¤Ï½¤Àµ¤µ¤ì¤Æ¤¤¤Þ¤»¤ó¡£¤³¤ì¤Ë¤Ä¤¤¤ÆApple¤Ï¡ÖVisa¥·¥¹¥Æ¥à¾å¤Î·üÇ°¡×¤È»ØŦ¤·¤Æ¤ª¤ê¡¢Visa¤Ï¡ÖApple Pay¤Î»Ùʧ¤¤¥·¥¹¥Æ¥à¤Ï°ÂÁ´¤Ç¤¢¤ê¡¢¼ÂºÝ¤Î¹¶·â¤Ë¤³¤ÎÀȼåÀ­¤òÍøÍѤ¹¤ë¤³¤È¤ÏÆñ¤·¤¤¤À¤í¤¦¡×¤È½Ò¤Ù¤Æ¤¤¤Þ¤¹¡£

¼ÂºÝ¡¢¤³¤ÎÀȼåÀ­¤òÍøÍѤ·¤¿¹¶·â¤ò¹Ô¤¦¤Ë¤Ï¡¢¾åµ­¤ÎÁ°Äó¾ò·ï¤è¤ê¤âÊ£»¨¤ÊÍ×ÁǤ¬µá¤á¤é¤ì¤ë¤È¸¦µæ¥Á¡¼¥à¤âµ­¤·¤Æ¤¤¤Þ¤¹¡£¤½¤Î¡ÖÊ£¿ô¤ÊÍ×ÁǡפΤҤȤĤȤ·¤Æ¡¢¡Ö¤¤¤¯¤Ä¤«¤Î¥Ó¥Ã¥È¤òÊѹ¹¤¹¤ë¤³¤È¤Ç¥ª¥Õ¥é¥¤¥ó¥Ç¡¼¥¿Ç§¾Ú¤òÍ­¸ú¤Ë¤¹¤ë¡×¤³¤È¤¬µó¤²¤é¤ì¤Æ¤¤¤Þ¤¹¡£