Live data from Hacker News

5900 online stores found skimming

gwillem.github.io

81–90 of 104 posts

Re: 5900 online stores found skimming

#81
post #33

Earlier quoted context omitted.

I don't understand this at all. I really, really don't want to give my credit card details to some random webshop who are exceedingly unlikely to have solid security. If I can use PayPal or another well known payment provider, great, I don't even have to type in my details. But even a less well known PSP is more likely to get it right than a small business webshop. A slightly jarring user interface seems a small pric…

I am not liable for credit card fraud. The last thing in the world I want is inconvenience for me , when it's other people's money at risk (bank, merchant, CC company, whoever), not mine. On the other hand, Paypal itself is a liability. Blocking your account (and your money!) for months without recourse, randomly reducing expense limits to nothing (50 EUR) are not just some Internet stories, but things that have happ…

Some years ago I had a Bank of America credit card. My new card never arrived in the mail, and I discovered 3,000 in charges. When I reported it, Bank of America insisted that they had mailed me the card and that I was responsible for its use. I appealed, and they still insisted that I pay the bill. I don't know their logic - was it just some employees trying to increase profit - like Wells Fargo today? And what choice did I have? Hire a lawyer for $400/hour? Lose hours of work time fighting them? Allow my credit to be wrecked? So I paid them and got a different credit card. (They even fined me and charged me interest for the months I was contesting the charges.)

In the end, they hold an unfair power over those who they can extort. I wish we had much better consumer laws - to actually protect us.

Re: 5900 online stores found skimming

#82
post #64

Earlier quoted context omitted.

I don't understand this at all. I really, really don't want to give my credit card details to some random webshop who are exceedingly unlikely to have solid security. If I can use PayPal or another well known payment provider, great, I don't even have to type in my details. But even a less well known PSP is more likely to get it right than a small business webshop. A slightly jarring user interface seems a small pric…

Doesn't Apple Pay make this a non issue? Especially now that it can be deployed on websites?

Like so many other areas, it's really a shame that the industry can't co-operate here. Apple Pay works fine at the one location near me that supports it, but it's a headache for the merchant (I might be the only person who uses that payment system) and the consumer (lack of support elsewhere).

The equation for websites is similar given Mac users are a minority, and many Mac users use Chrome.

Re: 5900 online stores found skimming

#83

"We don’t care, our payments are handled by a 3rd party payment provider" "Thanks for your suggestion, but our shop is totally safe. There is just an annoying javascript error." please share the stores sending these negligent and insulting responses. they don't deserve any sort of protection.

I just contacted all .de-stores (except one or two, who had neither an email address nor a contact form).

So far received one response: "We do not even accept credit cards!". Tried to explain to her why foreign code on your site might still be a problem.

Expecting many similar responses. Where possible I contacted their developers directly, maybe they will do something.

Re: 5900 online stores found skimming

#84
post #70

This is not responsible disclosure [1], which raises an ethical issue. For victims added to the list and published within days, the victim is not allowed adequate time time to fix their vulnerability. That does real harm to the victims by inviting attacks before they can avoid the harm the disclosure invites. [1] https://en.wikipedia.org/wiki/Responsible_disclosure

Wrong. The report is not about an open exploit but about an actively used exploit spreading malware.

Re: 5900 online stores found skimming

#85
post #70

This is not responsible disclosure [1], which raises an ethical issue. For victims added to the list and published within days, the victim is not allowed adequate time time to fix their vulnerability. That does real harm to the victims by inviting attacks before they can avoid the harm the disclosure invites. [1] https://en.wikipedia.org/wiki/Responsible_disclosure

Wrong. The report is not about an open exploit but about an actively used exploit spreading malware.

The sites are victims of xploit as well. That is the issue I am raising.

Re: 5900 online stores found skimming

#86
post #59
post #36

Earlier quoted context omitted.

> Is this a minority view? I don't know, maybe. I have zero liability on credit card purchases, and while it's certainly an inconvenience I never don't buy something because my details might be leaked. Who cares, why put yourself through the constant mental effort for an event that happens maybe once or twice a decade if you are exceedingly careless? I absolutely despise being sent to a third party site - usually a b…

"I have zero liability on credit card purchases" Not quite right. Many banks make you liable for the first $50, for each occurrence of fraud. Also they typically require you to notice and report a fraudulent charge within 30-90 days or else you are liable for 100% of the amount.

Nope, if your credit card number is stolen and used online for a card-not-present transaction you have $0 liability by law.

Re: 5900 online stores found skimming

#87
post #81
post #33

Earlier quoted context omitted.

I am not liable for credit card fraud. The last thing in the world I want is inconvenience for me , when it's other people's money at risk (bank, merchant, CC company, whoever), not mine. On the other hand, Paypal itself is a liability. Blocking your account (and your money!) for months without recourse, randomly reducing expense limits to nothing (50 EUR) are not just some Internet stories, but things that have happ…

Some years ago I had a Bank of America credit card. My new card never arrived in the mail, and I discovered 3,000 in charges. When I reported it, Bank of America insisted that they had mailed me the card and that I was responsible for its use. I appealed, and they still insisted that I pay the bill. I don't know their logic - was it just some employees trying to increase profit - like Wells Fargo today? And what choi…

> I wish we had much better consumer laws

We have excellent consumers laws in this particular regard. If only consumers fought for their rights instead of paying the mafia!

> Hire a lawyer for $400/hour?

You don't need a lawyer for small claims court.

Re: 5900 online stores found skimming

#88
post #64

Earlier quoted context omitted.

I don't understand this at all. I really, really don't want to give my credit card details to some random webshop who are exceedingly unlikely to have solid security. If I can use PayPal or another well known payment provider, great, I don't even have to type in my details. But even a less well known PSP is more likely to get it right than a small business webshop. A slightly jarring user interface seems a small pric…

Doesn't Apple Pay make this a non issue? Especially now that it can be deployed on websites?

Apple Pay online is great for convenience and security, from a practical point of view, but on a more abstract point of view I think something is deeply flawed about the payment industry if the solution is to add yet another middle man.

I want a world where payment is convenient, security is excellent, and there's no mandatory mafia of middle man between my electronic money and the merchant. It's fine that people chose to use banks voluntary, banks provide many services people want. But it should not be mandatory to use banks, if you chose to do so, and most certainly it should not be necessary to implicate yet another 3rd party to the transaction (VISA/Mastercard). And now we are adding a 4th party!

Whether to use a 3rd, 4th, 5th party should be users' choice. Some people value security, others privacy, others convenience; some people want 2FA for every transaction, some people hate PINs and want just to swipe a card, etc. All this should be client side; user's side. Open payment protocol with multiple implementations. Merchant just uses the protocol. If some new payment revolution is coming, merchant should just update his software.

We have technical solutions to do all this, but most people do not understand that this is possible, what the existing system entails; and the people in charge of this don't want to lose the power.

Re: 5900 online stores found skimming

#89
post #74
post #3

As the article points out, if someone can inject Javascript into your checkout page, you're most likely also having other security issues. Still, and I'm pretty much being called an idiot every time I point this out: You should NEVER have the user enter credit card information on your site. That is something that is best left to your PSP. If you're Amazon or similar size, fine, I can accept that you most likely have…

> You should NEVER have the user enter credit card information on your site My app client sends the card info to Stripe, then forwards the Stripe token to my server to charge the card each month. So far this is a standard security model. The problem is that if PayPal come along to offer me a cheaper commission on processing subscription payments, I cannot simply switch my sever to use PayPal for all my existing custo…

I don't know about PayPal, but even if you just have the token for recurring payments/subscriptions you can still switch PSPs. Most PSPs are able to exchange tokens and information, enabling you to switch between them (at a price of cause).

Re: 5900 online stores found skimming

#90
post #3

As the article points out, if someone can inject Javascript into your checkout page, you're most likely also having other security issues. Still, and I'm pretty much being called an idiot every time I point this out: You should NEVER have the user enter credit card information on your site. That is something that is best left to your PSP. If you're Amazon or similar size, fine, I can accept that you most likely have…

I work in ecommerce consulting - most of my clients take CC info on their site, the forms on the checkout POST (over SSL) to the PSP who then return a token to the site, all future transactions use the token. Most people don't want to bounce customers to a third party site for payment, it really hurts conversions.

>it really hurts conversions

That has to be a local issue, because that is flat out wrong. The majority of all e-commerce sites does exactly that. I have yet to meet a PSP that believe send the entire credit card number, expiry and CVV was the right solution. I've talked to exactly one PSP that supported accepting credit cards in an iframe, and that was only available to existing customers, because they where discontinuing that service.

In most of northern Europe at least, customer have been use to credit card payments redirecting them to third party sites since at least 1999. It has zero effect on conversion.

Post reply on HN