Live data from Hacker News

Verified by Visa and Mastercard SecureCode are broken and need to be fixed

cxpartners.co.uk

41–50 of 64 posts

Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed

#41
post #11

Every now and then when I purchase something from a Verified by Visa-"friendly" site (Newegg comes to mind), I often find that I'm able to complete the purchase without entering my password. It's disturbing to say the least.

I recall creating my password for Verified by Visa, but never successfully entering it again. It's never stopped me from getting the goods and getting charged, though.

I think I've ended reseting the password word everytime I've bought something online.

Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed

#43
post #32

Earlier quoted context omitted.

In defense of debit cards, in the event you do lose it and someone's emptying your account, your bank should still restore your funds after the theft. I say this because it happened to my wife; Chase's fraud prevention kicked in after about $300, all of which was refunded as soon as she figured out what had happened.

Thanks, good to know. I've been waiting for these policies to kick in as debit cards become more popular.

It has actually been that way for awhile. Back about 9-10 years ago someone used my wife's debit card number and after reporting it the bank restored the funds.

Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed

#44
post #40

Earlier quoted context omitted.

While we are in public-service-announcement mode: I believe that the above protections are still a lot smaller for debit cards than credit cards. You still have $50 limit on liability with debit cards, but you must report the theft very quickly indeed and the thief is emptying your personal account in the meantime: http://banking.about.com/od/checkingaccounts/a/stolendebitca... This is why I never use a debit card fo…

It's worth noting that the mere _existence_ of a debit card on a checking account still opens a fraud vector, even if you never use it. If the physical card is stolen, or the bank has a security breach where the number is obtained, those are both enough information to make fraudulent transactions. Of course, using a debit card will greatly enlarge the attack surface, but not using it does not make you immune.

Back before the "cvv" number on the back of the card you could download a bit of software of the net that would generate random account numbers with valid ICA/BIN and check digit. You just picked the name of the bank you wanted the card to appear to be from.

Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed

#45
There's an open secret in the Information Security industry (at least here in the UK), which is that the Payment Card Industry don't care about your security. What they care about is shifting as much of the liability onto the consumer, the merchant, anyone other than themselves as is possible.

We have a system in place here called Chip and Pin (http://en.wikipedia.org/wiki/Chip_and_PIN) which was supposed to protect people by requiring them to type in a personal PIN code. The only problem was that there were plenty of ways to commit fraud without knowing the PIN, and until new regulations came into force the banks would reject claims of fraudulent transactions and require the victim to prove that such transactions weren't fraudulent.

If you want to see how bad the card industry and banks can 'do security', just look here: http://www.cl.cam.ac.uk/research/security/banking/

Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed

#46
post #13

Even though there's no choice (here at least, when you want to use your Visa over the internet) I HATE, HATE, HATE the concept and here's why: For starters I thought it's a phishing attack, when the frame popped up for the first time. But the worst is that I don't feel it protects me, despite the marketing crap dished out by CC companies. The only reason is to protect Visa. What happens if I book a flight at a badly…

What happens if I book a flight at a badly infected internet cafe computer in Chiang Mai and a key logger reads my password Does VbV make this any worse? It's very difficult to protect against (other than "never use untrusted computers").

This is why two-factor authentication should be required.

Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed

#47
post #38

Could someone tell me why this idea wouldn't work?: Your credit card comes with a simple communication port (usb, bluetooth, whatever) and a two line B&W text LCD display (like on cryptocards or cheap electronic watches). Every time you want to buy something, you connect the card with the merchant. (This works in person and over the internet.) The merchants sends the card an official merchant name ("Delta Airlines"),…

> slightly less durable That might be the deal-breaker here. People with wallets sit on their credit cards daily. I've split the plastic on mine a few times, even though I've gotten into the habit of taking my wallet out when I sit down. Credit card purchase authorization over SMS might be more sturdy, although that has its own security considerations (I think this exists somewhere already though).

> That might be the deal-breaker here.

I would think it's surmountable, but point taken.

>Credit card purchase authorization over SMS might be more sturdy

How is this supposed to work? They send you a text, and you reply to confirm? The inability to make purchases without a signal seems fatal.

Thanks for the feedback.

Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed

#48
post #36

Could someone tell me why this idea wouldn't work?: Your credit card comes with a simple communication port (usb, bluetooth, whatever) and a two line B&W text LCD display (like on cryptocards or cheap electronic watches). Every time you want to buy something, you connect the card with the merchant. (This works in person and over the internet.) The merchants sends the card an official merchant name ("Delta Airlines"),…

A very similar system is already in use in the UK and other parts of Europe. It's called "chip & pin". You plug your card in to a card reader and check the LCD display and type in your PIN to authorise a transaction. In a shop, the card reader is owned by the shop and is similar to point-of-sale card readers used in the USA. However, most banks now provide customers with a small reader (that looks like a calculator)…

I see three problems.

> most banks now provide customers with a small reader (that looks like a calculator) for logging on to online banking, or authorising payments made via internet banking.

This means you can only make online purchases easily and securely at home. If I want to be able to make purchases at someone else's computer, an insecure back door must necessarily be left open even when you're not away.

> To authorise a payment you: put your card into the reader, type in the account number you want to pay, type in the amount, and type in your pin.

This doesn't solve the problem (which people may not care about) that the merchant could now have your pin.

>You then get an cryptographic authorization code to type into online banking.

This seems like a huge burden. Physically typing in long cryptographic codes? Do people actually subject themselves to this?

Thanks very much for the perspective.

EDIT: I retract the second criticism for reasons explained below.

Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed

#49
post #38

Earlier quoted context omitted.

> slightly less durable That might be the deal-breaker here. People with wallets sit on their credit cards daily. I've split the plastic on mine a few times, even though I've gotten into the habit of taking my wallet out when I sit down. Credit card purchase authorization over SMS might be more sturdy, although that has its own security considerations (I think this exists somewhere already though).

> That might be the deal-breaker here. I would think it's surmountable, but point taken. >Credit card purchase authorization over SMS might be more sturdy How is this supposed to work? They send you a text, and you reply to confirm? The inability to make purchases without a signal seems fatal. Thanks for the feedback.

> How is this supposed to work? They send you a text, and you reply to confirm? The inability to make purchases without a signal seems fatal.

Yes, that sounds about right. You have a mobile number associated with your account, and your bank texts you when you make a purchase. I don't think it would be required that you confirm every purchase - it would be more of a notification system. You could require it, but there's a balance of convenience and security that people are already used to.

As for not being able to purchase without a signal, I posit that in the case where you need to authorize purchases, it has the same limitations as your credit-card-communication concept :)

Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed

#50

Earlier quoted context omitted.

3DS doesn't work that way. It's not mandatory. Newegg isn't using it to fight friendly fraud. They are using it to fight actual fraud. You've done it once, why should they force it on you again? You are who you say you are, and if their is a problem with your purchase, they're confident that they can resolve it without a chargeback.

But then why bother using it at all? Do they assume that no one malicious could ever get into my account (for argument's sake)? If you're going to make me set a password, make me enter it each time I "use" your service. My gripe isn't with the vendors per sé, but with how Verified by Visa and SecureCode operate. I'd much rather type an extra password during the checkout process instead of being charged $700 for hardw…

> But then why bother using it at all? Do they assume that no one malicious could ever get into my account (for argument's sake)? ... instead of being charged $700 for hardware and Windows Vista DVDs

You're making an awful lot of assumptions you shouldn't be making.

First, 3DS doesn't provide you any more security than you really had before. It helps the merchant secure their transactions, however. But even if someone did charge $700 to your card, it's an easy phone call to get it resolved. Not only this, but I'm sure Newegg would require another check if something was amiss with the transaction. Any sizable operation will work to make sure that legit users can make purchases as fast as possible with as little hassle, but that doesn't mean it's not verifying things in the background.

So why would Newegg use 3DS? Simple. They want to verify that a new account is who they say they are, and not a stolen card. You're a legit user. You make a purchase. Next time you come back, you'll probably be making the purchase using the same billing address and the same shipping address. Even if you didn't make the order, you'll call up Newegg to complain, and they'll work to refund the order and resolve the matter as quickly as possible.

But you as a cardholder have always been safe. A simple call to the bank, and "No, I don't recognize the transaction" and you get your chargeback and you owe no money. However, with 3DS, you can't just say it wasn't you. If the merchant doesn't provide the service, then yes, you can still get it. 3DS for legit users prevents them from committing friendly fraud.

Post reply on HN