Live data from Hacker News

What happens when you swipe a credit card

tech.affirm.com

111–120 of 178 posts

Re: What happens when you swipe a credit card

#111
post #93
post #77

Earlier quoted context omitted.

The way I see it, this is describing the system exactly as much as it needs to make its case that 'banking system is bad and expensive, use our stuff'. Covering security, or the lower fees in Europe (thanks mostly to the security features), goes against the narrative. An interesting tidbit: An extra reason US fees are so high are premium credit cards choke full of rewards: Not every card has the same fees, and the hi…

Well if we really believed in the free market and consumer protection, there'd be a law requiring the total transaction cost be printed on the sales slip. Whether the merchant pays it or passes it onto the consumer would be up to the merchant, but the amount would appear on the slip so the consumer sees these costs and who is paying for it. What we really have is mercantilism, where the issuer by contract disallows f…

> Well if we really believed in the free market and consumer protection, there'd be a law requiring the total transaction cost be printed on the sales slip.

So "if we really believed in the free market", we should regulate the details of how a private transaction can take place?

Leaving aside any other aspects of that proposal, whether positive or negative, it doesn't seem reasonable to describe it as "free market".

Re: What happens when you swipe a credit card

#112
post #30

Earlier quoted context omitted.

Yes, this! At least in the US, there is zero benefit to me as a consumer from chip cards. The banks have not increased rewards, or lowered interchange fees (thereby lowering retail prices). Federal law protects me from fraud no matter the card input method. Due to the risk of online fraud, I still have to check my statement for fraudulent charges. There are, however, noticeable downsides. Including everything coin me…

While federal law protects you from fraud, it's still extremely inconvenient to have your credit card skimmed and then likely automatically cancelled by your bank at an inconvenient time when someone tries to use it, and left without that credit card until the replacement shows up. Chip & Pin solves this particular issue fairly well. This is even more critical for debit cards being skimmed where it's actually a non-t…

Not so, the new chip skimmers are even smaller than the mag readers due to the tech.

Re: What happens when you swipe a credit card

#113

What annoys me is the expiry date and CVV. It seems like their solution to "more secure" is just to add more numbers. How about put the last 3 digits on the back, and call it the cvv ? How about use alphanumeric card numbers so we dont have to use as many digits ? Get rid of the expiry date used as validation. It's just more entropy, if you need more entropy then add another digit. It's just annoying having to type t…

I think we can all agree the correct model is a card that generates a globally unique card number for each and every transaction (e.g. coin failed , final). It should also have a 2nd factor authorization like CVV which is not embedded in the magnetic strip (can't be read by swipers).

I think the correct model has the customer authorize (sign) the specific transaction through a channel not controlled by the merchant.

An object which signs every transaction it's asked to sign is an improvement (can only be in one place at a time) but still broken (evil terminals).

Re: What happens when you swipe a credit card

#114

Earlier quoted context omitted.

I think we can all agree the correct model is a card that generates a globally unique card number for each and every transaction (e.g. coin failed , final). It should also have a 2nd factor authorization like CVV which is not embedded in the magnetic strip (can't be read by swipers).

Which is (roughly) exactly how EMV chips work. Crypographic challenges that result in unique tokens for every transaction.

Of course, EMV is still a broken piece of crap, because the signer can't actually verify the transaction being signed.

Re: What happens when you swipe a credit card

#115
post #54

It doesn't say if the data ends up with advertisers, but I wouldn't be surprised.

Sure they do, it's not a secret: http://www.mastercardadvisors.com/information-services.html https://www.americanexpress.com/uk/content/merchant/business... https://usa.visa.com/run-your-business/commercial-solutions/...

The data doesn't really end up with advertisers though, does it? I can't call up AMEX and ask for a list of all the places my member of Congress uses his card, can I?

Re: What happens when you swipe a credit card

#116
post #71

Earlier quoted context omitted.

CVV is not just more entropy, it's handled differently: https://randomoracle.wordpress.com/2012/08/25/cvv1-cvv2-cvv3... The whole point is that you can't skim the CVV2 from the magnetic data and then use it to make purchase.

In addition to not being on the magnetic stripe, merchants are also not allowed to save it, so if you steal a merchant's database of stored CCs, you don't get the CVVs.

Requiring CVV's for online transactions invalidates this security feature.

Re: What happens when you swipe a credit card

#117

Earlier quoted context omitted.

I think we can all agree the correct model is a card that generates a globally unique card number for each and every transaction (e.g. coin failed , final). It should also have a 2nd factor authorization like CVV which is not embedded in the magnetic strip (can't be read by swipers).

The first part is basically what Final claims to be doing: https://getfinal.com/

I have a Final card. You have three options:

1. Use your real card number. I never do this. 2. Use a merchant-locked card number. I use this commonly for online pizza and other online shops I don't trust much. Once a merchant uses it, only that merchant can use it. 3. Use a one-time card. The number is used once and disabled. Good for one-off orders or skeezy purchases.

Overall I've been pretty pleased. I think the idea that card numbers should be disposable is awesome.

Re: What happens when you swipe a credit card

#120
The OP has things mixed up quite a bit. For starters, Point Of Sale flow should be described separately from the Card Not Present (as in online purchases) flow (protip there really is no such thing as transaction void in POS world). There are also things like auth reversals, partial captures etc.
Post reply on HN