Earlier quoted context omitted.
Except that 3D Secure is opt-in by the merchant. All you need to do is find a web store that is more than 2 years old and you can use stolen/skimmed cards all day long.
My primary card declines all non 3D Secure internet purchases unless I click the scary sounding "Open card to all internet purchases for 60 minutes" button in the bank app.
Japan facing credit card number shortage
231–240 of 360 posts
Re: Japan facing credit card number shortage
#232What's crazy is that we've had public key encryption for over 40 years, and we're still publishing magic numbers on little pieces of plastic that give whoever sees them the power to take all our money without our consent.
The prevalence of credit cards has baffled me for decades now. I admit I have one, but the only thing I need it for is to buy things from webshops that don't cater to the Dutch market. Every webshop that's vaguely aware of the Dutch market supports iDeal, which is specifically designed to handle internet payment and doesn't involve sharing any sensitive information with merchants or other unknown parties; my bank han…
Re: Japan facing credit card number shortage
#233Earlier quoted context omitted.
That's how it works for all credit card fraud. But do they treat 3D Secure transactions any differently?
Yes, 3D secure leads to a different liability layout. Stores that don't implement it face liability on chargeback, whereas stores that do use it are protected, and the banks themselves take liability. At least that's my understanding of it, might not be that clearcut.
Re: Japan facing credit card number shortage
#234Re: Japan facing credit card number shortage
#235Earlier quoted context omitted.
At that point why even show the number? It would be useless without the encryption. And if you have some way to enter the numbers so online transactions still work, then what is the point of the encryption? I don't believe the majority of fraud is stolen physical credit cards
> And if you have some way to enter the numbers so online transactions still work, then what is the point of the encryption? Why not allow plugging the card into the computer just like a yubikey for online payments? It would be quite difficult to pull off, but credit card companies can save a lot on fraudulent transactions if it is implemented.
Re: Japan facing credit card number shortage
#236>the company decided to take makeshift measures such as reusing credit card numbers of discontinued cards after a certain period had passed since cardholders canceled their memberships. However, there are considerable risks of fraudulent usage What are the risks here, and why aren't they already present by someone generating credit card numbers with a RNG? AFAIK credit card transactions are authenticated by at least…
Credit card numbers can be easily generated, there are tons of generators online. The right solution is not to have a number that you give out to random people who then gain access to your money. Also the righ way is not to trust the few giant credit card corporations to move all the money in the world The right way (EU is introducing it) is that you get a payment request that you can paste into your bank app and the…
Re: Japan facing credit card number shortage
#237Earlier quoted context omitted.
This story is ridiculous for another reasons. I worked for card payment (implemented credit card terminal application, internalized couple thousand pages of requirements). Credit card numbers are assigned by payment organizations in the form of prefixes (BINs -- https://binlist.net/ , https://www.bindb.com/bin-list.html ) The worst that will happen is that Visa/Mastercard will issue more BINs to those organizations.…
Exactly, but the idea that with a billion numbers to issue they can't get 100 million folks into the structure - that's also silly.
The difference is that Credit Card numbers are much easier to manage. The routing tables for Credit Cards are distributed by Visa/Mastercard to acquirers in the form of BIN files and it is extremely easy to add arbitrary mapping. So if someone gets an unnecessarily large prefix like "1" then the next day you can change it easily to ten prefixes "10", "11", "12" and so on and have a different organization for each.
Re: Japan facing credit card number shortage
#238Earlier quoted context omitted.
The prevalence of credit cards has baffled me for decades now. I admit I have one, but the only thing I need it for is to buy things from webshops that don't cater to the Dutch market. Every webshop that's vaguely aware of the Dutch market supports iDeal, which is specifically designed to handle internet payment and doesn't involve sharing any sensitive information with merchants or other unknown parties; my bank han…
The Dutch system is not on the side of the consumer. It's simply a bank transaction before they send you the goods.
Re: Japan facing credit card number shortage
#239What's crazy is that we've had public key encryption for over 40 years, and we're still publishing magic numbers on little pieces of plastic that give whoever sees them the power to take all our money without our consent.
Re: Japan facing credit card number shortage
#240What's crazy is that we've had public key encryption for over 40 years, and we're still publishing magic numbers on little pieces of plastic that give whoever sees them the power to take all our money without our consent.
Why on earth would we want this? Right now all of the burden is on the credit card companies. Any fraud is their liability. If we switch things up, and implement something like passwords or pins, WE get the liability. That’s worse than our current situation. And given how badly people get hacked or phished, all it means is that consumers lose. Right now, those “magic little numbers” work great, and in the case of fra…
If you don't keep your card safe, it's your liability, just like with passwords. Read the manual.