Live data from Hacker News

Japan facing credit card number shortage

mainichi.jp

221–230 of 360 posts

Re: Japan facing credit card number shortage

#221

Earlier quoted context omitted.

... at the risk of the store. The card holder just goes to the bank, says "I didn't do those transactions!" and gets all money back.

That's how it works for all credit card fraud. But do they treat 3D Secure transactions any differently?

Yes, 3D secure leads to a different liability layout. Stores that don't implement it face liability on chargeback, whereas stores that do use it are protected, and the banks themselves take liability.

At least that's my understanding of it, might not be that clearcut.

Re: Japan facing credit card number shortage

#222
post #164

Earlier quoted context omitted.

The problem isn’t the tools. It’s that there is no such thing as an operable PKI. The best PKI (by far) is the CA system, and the CA system is not a good PKI. It has so many holes, and the PKI evangelists don’t like it anyway, because it uses trusted authorities. The only other examples of remotely useful PKIs in existence are things like Signal/WhatsApp... and those are even worse PKIs, because TOFU PKIs are in prac…

The US DoD has a perfectly useful and operable PKI infrastructure https://www.cac.mil/Common-Access-Card/CAC-Security/

Yes it's very close. The only reason it will fail for private citizens is the device needs to be easily auditable for correctness. The auditing process needs to be at least simple enough that children in public schools can be taught how to assess their PKI dongle to make sure it's real and trustworthy.

Re: Japan facing credit card number shortage

#223
post #175
post #173

Earlier quoted context omitted.

Most of these "branded" cards will have an underlying issuing bank/acquirer, not their own identification on the card. The way that the 16 digits are allocated is defined as per https://en.wikipedia.org/wiki/Payment_card_number#Structure So of the 16 digits for the majority of cards: Digit 1-6(8): Scheme and issuer identification Digits 7-15: Account identification Digit 16: Check digit (Luhn algorithm) So most issue…

Sure, but if I have 8 different cards issued by SMBC then that's still 8 cards.

Seconding this. I have multiple cards by SMCC, some basically given to me.

There's also a lot of "virtual credit card" offerings right now to pair with peer-to-peer payment apps. I imagine that those need to get cycled through frequently.

8 is not an exageration.

Re: Japan facing credit card number shortage

#224
post #123

Earlier quoted context omitted.

Fraud results in higher prices for consumers through higher prices and credit card interest/fees.

Sure, but this is fundamentally the same deal as insurance: we distribute the cost across the whole population at a constant, low cost rather than ask individuals to take a big hit with low probability. Unless you can eliminate fraud, those are basically your two choices.

> Unless you can eliminate fraud

Which is exactly the purpose of good security measures.

Bad or nonexistent measures and an insurance against fraud slapped on all prices is a local maximum. Good security measures which really push back the fraud and allow prices to drop the insurance premium is obviously a better local maximum.

You also don't have to eliminate 100% of fraud, just make it so rare that you can basically ignore the risk because it happening to you is as unlikely as being struck by lightning (or any other risk of life that people are comfortable to ignore due to it being vanishingly small). The classic credit card fraud with magstripes was the exact opposite of that: there was almost no credit card owner who didn't get hit by it, and while people generally didn't lose money due to reimbursement by the cc companies, they still lost time and nerves over some stupid interruption in their lives that was entirely unnecessary in the first place.

I myself had one of my cards suddenly deactivated by the bank because of alleged fraud (it wasn't even real fraud, just some heuristic going crazy over an actually intended payment). I was on a cruise ship in the Caribbean sea when it happened and all of a sudden couldn't pay my beers with my ship card anymore. Fortunately I had a second card with me that was working so I continued using that, but in order to switch my onboard expenses account over to it I had to spend some time at the customer service desk on the ship, where there was a row of passengers standing at phones, occasionally speaking with someone in various languages, but most of the time they seemed to be waiting in silence for some kind of response. It took me a few minutes of overheard conversation until I realized that these guys were in the same spot that I was, but less well prepared; they didn't have another credit card with them and thus had to call their banks back home in order to get them to unlock their accounts again.

Re: Japan facing credit card number shortage

#225

Earlier quoted context omitted.

I think a government controlled PKI authority, especially one that required real identity authentication, would possibly be the solution that would make the least number of people happy.

without even broaching conspiracy theories or secret organizations it's not like government has a stellar track record of dealing with data it promises will be kept secret and single-purpose (for example SSNs).

Well, in PKI a CA doesn't keep much secret data. SSN is a symmetric shared secret, not PKI.

Re: Japan facing credit card number shortage

#226

What's crazy is that we've had public key encryption for over 40 years, and we're still publishing magic numbers on little pieces of plastic that give whoever sees them the power to take all our money without our consent.

I was shocked to hear that my mastercard which I always use with CVC and 2FA or PIN actually works like a normal third world mastercard in some places. So while the security problem is kind of solved where I live, if someone stole my CC details they can still skim my card!

Obviously I can block it for all transactions abroad but that doesn't seem like the best idea either.

The only working solution is to generate temporary card numbers for international transactions, but that leads to the shortage issue.

Re: Japan facing credit card number shortage

#227

Earlier quoted context omitted.

I think a government controlled PKI authority, especially one that required real identity authentication, would possibly be the solution that would make the least number of people happy.

Why? Even if you don't have to show government ID for every financial transaction, you need to show government ID (and, often, a lot more government paperwork) to open a financial account that can be used to make transactions. Your ability to move money is entirely predicated on the banks knowing who you are by linking your accounts to a tombstone government identity document. Using PKI controlled by government to au…

I'm afraid if the government ID becomes ubiquitous, there's a danger of abuse that all systems will require it for everything and I doubt government will certify pseudonymous IDs. I'd say have banks as independent CAs, one or several keys per bank.

Re: Japan facing credit card number shortage

#228

Earlier quoted context omitted.

then those merchants should use the widely popular 3d secure system, which lets you enter a pin. by using it, they are protected from reversals by the terms of service. so a system that prevents them losing a gazillion dollars is available, and they opt to instead lose the gazillion dollars. it's their fault, and they should lose that money. we don't need to tell them anything -we just need to point and laugh.

And then see customers complaining about the annoying extra steps. 3D Secure affects conversion rates adversely which means customers are generally happier without it and don't mind the fraud risk (as is consistent with the rest of this discussion on the thread).

> And then see customers complaining about the annoying extra steps.

PIN in stores and 2FA online is already the norm in the developed world. It didn't exactly cause a disaster for retail.

There are a few countries where it still isn't completely rolled out (US being the most notable one) but those are now outliers.

> customers are generally happier without it

Again I think this perspectivve is US centric and not global (?).

Re: Japan facing credit card number shortage

#229

What's crazy is that we've had public key encryption for over 40 years, and we're still publishing magic numbers on little pieces of plastic that give whoever sees them the power to take all our money without our consent.

The prevalence of credit cards has baffled me for decades now. I admit I have one, but the only thing I need it for is to buy things from webshops that don't cater to the Dutch market. Every webshop that's vaguely aware of the Dutch market supports iDeal, which is specifically designed to handle internet payment and doesn't involve sharing any sensitive information with merchants or other unknown parties; my bank handles authorization of the payment, and I tell my bank to authorize the payment.

I admit the ability to reverse a credit card payment is nice, but that mostly means that it's also a risky form of payment to accept for the merchant. They might send the goods and still have the customer challenge the transaction. And of course you still pay for this; credit card transactions are relatively expensive.

Re: Japan facing credit card number shortage

#230

What's crazy is that we've had public key encryption for over 40 years, and we're still publishing magic numbers on little pieces of plastic that give whoever sees them the power to take all our money without our consent.

I was shocked to hear that my mastercard which I always use with CVC and 2FA or PIN actually works like a normal third world mastercard in some places. So while the security problem is kind of solved where I live, if someone stole my CC details they can still skim my card! Obviously I can block it for all transactions abroad but that doesn't seem like the best idea either. The only working solution is to generate tem…

That's what you get with security that's been patched on after the fact. It's basically optional security, which isn't real security at all. We need something that's been designed from the ground up with security in mind.
Post reply on HN