¿Qué Tan Fácil Es Robar $10,000 Dólares De Un Teléfono Bloqueado?

¿Qué Tan Fácil Es Robar $10,000 Dólares De Un Teléfono Bloqueado?

🎙 Veritasium en español 👥 2.9M 📅 May 11, 2026 ⏱ 26 min 👁 1.1M 📄 documentary 🧭 2026-08-13
Available in: English (current) Français

Keywords

NFCman-in-the-middleRSAExpress TransitVisa

Summary

The video demonstrates a sophisticated man-in-the-middle attack on Apple Pay using an iPhone and a Visa card, allowing the theft of $10,000 from a locked phone. The attack exploits the Express Transit mode, which allows payments without unlocking the phone, and manipulates transaction data to bypass security checks. The video explains the three lies told to the phone and the card reader: changing the transit bit, the high/low value bit, and the verification bit. It also highlights that this vulnerability is specific to Visa and iPhone, as Mastercard uses additional asymmetric cryptography (RSA) that would detect the tampering. The researchers who discovered the attack reported it to Apple and Visa in 2021, but it remains unfixed. The video includes interviews with Visa representatives who downplay the risk and emphasize customer reimbursement. The demonstration is conducted with the consent of MKBHD, and the video also includes a sponsored segment for Incogni, a data privacy service.

154 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable information about a real security vulnerability in contactless payment systems. The argumentation is solid, as the attack is demonstrated live with the participation of MKBHD and explained with the help of cybersecurity experts. The technical details are presented clearly, and the video effectively communicates the severity of the issue. The comparison to airline safety is compelling, highlighting the need for proactive security measures rather than reactive reimbursement.

Scientific Rigor, Source Quality, Title Accuracy

The video is scientifically rigorous, with the attack being developed and explained by professors Ioana Boureanu and Tom Chothia. The sources are credible, including academic research and direct communication with Visa. The title accurately reflects the content, and the video does not exaggerate the threat. The inclusion of a sponsored segment is clearly disclosed and does not detract from the scientific content.

148 words

Title / Content Match

The title accurately reflects the content, which demonstrates a real vulnerability in contactless payment systems.

Quality & Reliability

9/10

High reliability due to collaboration with cybersecurity experts, clear demonstration, and references to academic research. The video is well-documented and transparent about the attack's limitations.

Chapters

Cited Sources

Concurring Sources

  • TimeTrust project — Research project that collected initial data for the attack.

Dissenting Sources

  • Visa's response — Visa claims the attack is unlikely in the real world and that customers are protected by zero liability, but does not address the technical fix.

Contribution & Novelties

The video provides a detailed, practical demonstration of a known but underappreciated vulnerability in contactless payment systems. It explains the technical mechanisms clearly, making the attack understandable to a broad audience. The video also highlights the lack of action from Visa and Apple despite the vulnerability being known since 2021.

Pour aller plus loin :

103 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level, indicating a well-balanced and accessible presentation of complex material.

Reliability 9/10

💬 Très positif. Sur les 30 commentaires analysés, la majorité exprime admiration pour la qualité du contenu et l'humour, avec quelques critiques légères sur le sponsoring et la sécurité.