Live data from Hacker News

Detect breaches with Canary credit cards

blog.thinkst.com

31–40 of 158 posts

Re: Detect breaches with Canary credit cards

#31

I find it crazy that making a payment requires giving your full details. Using a credit card is less writing a cheque, more handing over a chequebook and saying "help yourself". I dream of a payment system where payment generates some token, which the intended recipient can redeem, perhaps bearer ones for casual transactions, with support for periodic payments, revoking existing tokens or placing per-token limits. On…

iDeal is really nice and everywhere in the Netherlands. Giving out credit card details to websites is crazy to me. (https://www.ideal.nl/en/)

Re: Detect breaches with Canary credit cards

#32

I find it crazy that making a payment requires giving your full details. Using a credit card is less writing a cheque, more handing over a chequebook and saying "help yourself". I dream of a payment system where payment generates some token, which the intended recipient can redeem, perhaps bearer ones for casual transactions, with support for periodic payments, revoking existing tokens or placing per-token limits. On…

Use Privacy.com for that!

Re: Detect breaches with Canary credit cards

#33

I find it crazy that making a payment requires giving your full details. Using a credit card is less writing a cheque, more handing over a chequebook and saying "help yourself". I dream of a payment system where payment generates some token, which the intended recipient can redeem, perhaps bearer ones for casual transactions, with support for periodic payments, revoking existing tokens or placing per-token limits. On…

This is part of the reason that a lot of people are excited about stablecoins and blockchain payments.

Re: Detect breaches with Canary credit cards

#34

I find it crazy that making a payment requires giving your full details. Using a credit card is less writing a cheque, more handing over a chequebook and saying "help yourself". I dream of a payment system where payment generates some token, which the intended recipient can redeem, perhaps bearer ones for casual transactions, with support for periodic payments, revoking existing tokens or placing per-token limits. On…

Use Privacy.com for that!

I second this. In a year's worth of using Privacy.com, I've been very pleased with the service.

I like how you can set a budget for a particular card, as well.

Re: Detect breaches with Canary credit cards

#35

I find it crazy that making a payment requires giving your full details. Using a credit card is less writing a cheque, more handing over a chequebook and saying "help yourself". I dream of a payment system where payment generates some token, which the intended recipient can redeem, perhaps bearer ones for casual transactions, with support for periodic payments, revoking existing tokens or placing per-token limits. On…

A check contains your full account number that anyone can go and print a check with.

The new credit cards which chips generate a unique token for each merchant account. This is also how Apple pay works.

Re: Detect breaches with Canary credit cards

#37

I wonder if the BIN/IIN (Bank/Issuer Identification Number[0]) of canary cards give it away. For this to work against sophisticated attackers, I'd expect a canary card to be indistinguishable from a regular one, though I still love the ingenuity of it. edit: They mention this in the article, I missed it. [0] https://en.wikipedia.org/wiki/Payment_card_number#Issuer_ide...

The blog post specifically calls out BINs and their limitations and some things they are doing to improve it.

Re: Detect breaches with Canary credit cards

#38

The fact that the Payment Card Industry association hasn't been pushing this for decades, and it's up to some random infosec nerds to invent it, is yet more evidence that our entire payment infrastructure is fundamentally flawed.

I wouldn't say this is much of a solution to the problem, though. There's no guarantee that anyone will attempt to use your canary card before they use your actual card. For one-time purchases, a better approach is to generate ephemeral cards that can only be used for a short amount of time, where it doesn't matter if the card gets leaked. And plenty of credit cards do offer this service.

Re: Detect breaches with Canary credit cards

#39

I’m dying to know how they implemented this. In order to have Visa or MasterCard process this transaction, they’d need to have a bank partner to issue the credit credit card with an issuer processor. There’s usually a large cost to keeping open credit cards on file, even if there’s no line of credit.

Only Amex at the moment.

Re: Detect breaches with Canary credit cards

#40

I wonder if the BIN/IIN (Bank/Issuer Identification Number[0]) of canary cards give it away. For this to work against sophisticated attackers, I'd expect a canary card to be indistinguishable from a regular one, though I still love the ingenuity of it. edit: They mention this in the article, I missed it. [0] https://en.wikipedia.org/wiki/Payment_card_number#Issuer_ide...

[deleted]
Post reply on HN