Live data from Hacker News

Japan facing credit card number shortage

mainichi.jp

201–210 of 360 posts

Re: Japan facing credit card number shortage

#201
post #78

Earlier quoted context omitted.

We should. There are so many adults who think it's cute to make up their own phonetics not realizing the whole purpose is to reduce ambiguity, not make it fun to spell things aloud.

As an adult who tries to remember the NATO phonetic alphabet but can't because I only use it once per month, I don't make up words "for fun" or "to be cute". I do it because I can't remember the NATO word. Compared to just saying the letters, the words I choose certainly do reduce ambiguity, even if using the NATO alphabet would go even further.

Some good advice I got from a HAM was to read license plates in your head using the NATO alphabet. Their letters are mostly random so you tend to see each letter at roughly the same frequency and it can be done daily without taking away time from your schedule. Being random also prevents you from just remembering the order of the words and actually associating them with their respective letters.

After doing that for a week or two (I was bike commuting at the time), I had it pretty much memorized.

Re: Japan facing credit card number shortage

#202

Earlier quoted context omitted.

Fraud liability usually falls on the business. Maybe the credit card companies shoulder the responsibility in some cases but I think its unlikely.

The liability is usually with the card issuer (bank), unless the merchant fails to meet liability shift requirements - like processes a card via the manually entered numbers or magstripe, rather than the chip in the card if the terminal supports it. This the way card networks have encouraged migration to systems that support tokens and cryptograms to limit fraud. See https://www.creditcards.com/credit-card-news/under…

I wish it were so.

For card-not-present transactions (i.e., all online credit card transactions) the liability is the merchant's. There is no recourse for a merchant who is a victim of a stolen card, the money is simply removed from their account.

Re: Japan facing credit card number shortage

#203
post #30

This is a ridiculous story. Japan has a population of 150M. If you can't give folks a number from SIXTEEN digits - something is wrong with the folks giving out the numbers. Some answers to the excuses. The 6 digits at front, if a company legit runs out of numbers, ask for another prefix. The reality. Instead of using the numbers properly (random ID to tie to a user account) they are probably putting some kind of stru…

> If you can't give folks a number from SIXTEEN digits - something is wrong with the folks giving out the numbers.

I hate saying this but I'll say it anyway, as someone who has spent considerable amounts of time trying to get things done in Japan, I would say that you're right.

There is likely some ridiculously inefficient process which obviously requires changing but for cultural reasons it's hard to change things so they're stuck in this strange situation.

Re: Japan facing credit card number shortage

#204
post #187

Earlier quoted context omitted.

How does that chip work online? As far as I know, CCs around the world still depend on numbers. For what it’s worth, in the US, chip is pretty much everywhere. Main difference is that it’s chip and signature vs chip and pin. I wish we’d switch to pins as well, but it’s not like it’s the dark ages or anything.

It's called 3D Secure and requires a PIN to verify transaction(typically with SMS), or a security device provided by bank.

Except that 3D Secure is opt-in by the merchant. All you need to do is find a web store that is more than 2 years old and you can use stolen/skimmed cards all day long.

Re: Japan facing credit card number shortage

#205

Earlier quoted context omitted.

It only works if you have a chip inside, like Yubikey and other HSMs do. You can't do crypto with dumb block storage. But if you have a chip you should absolutely do _something_ smarter than storing and reciting the number verbatim.

At that point why even show the number? It would be useless without the encryption. And if you have some way to enter the numbers so online transactions still work, then what is the point of the encryption? I don't believe the majority of fraud is stolen physical credit cards

> And if you have some way to enter the numbers so online transactions still work, then what is the point of the encryption?

Why not allow plugging the card into the computer just like a yubikey for online payments? It would be quite difficult to pull off, but credit card companies can save a lot on fraudulent transactions if it is implemented.

Re: Japan facing credit card number shortage

#208
post #187

Earlier quoted context omitted.

It's called 3D Secure and requires a PIN to verify transaction(typically with SMS), or a security device provided by bank.

Except that 3D Secure is opt-in by the merchant. All you need to do is find a web store that is more than 2 years old and you can use stolen/skimmed cards all day long.

... at the risk of the store. The card holder just goes to the bank, says "I didn't do those transactions!" and gets all money back.

Re: Japan facing credit card number shortage

#209

Earlier quoted context omitted.

the us has had nfc and chip for years. we still support swiping too. your statement was true for a few short years when europe did chip first. which was much easier there, since credit cards were not as common, and didn't exist since 1950 like in america. we don't use a pin, because that doesn't help with fraud. most fraud is either online, or someone at the store, who can easily skim or see your pin. online you can…

In US, with over 270,000 reports, credit card fraud was the most common type of identity theft last year and more than doubled from 2017 to 2019.

Credit card fraud, as in transaction fraud, usually online. It's a lot less common for your physical card to be the issue in a fraud situation, so improving security there is moot

Re: Japan facing credit card number shortage

#210
post #135

Earlier quoted context omitted.

Chip and PIN cards are based on a PKI with the payment networks acting as CAs. Used by millions of people every day. https://www.cryptomathic.com/hubfs/docs/cryptomathic_white_p...

That only works because it’s hidden from the user, and can only work on highly regulated approved devices. Try giving a user a private key for making CNP transactions, and all you will have achieved is replicating the user experience of bitcoin.

> Try giving a user a private key for making CNP transactions,

I have that!

> and all you will have achieved is replicating the user experience of bitcoin.

I've never used bitcoin or any other cryptocurrency. What's the user experience like?

Post reply on HN