The fact that the Payment Card Industry association hasn't been pushing this for decades, and it's up to some random infosec nerds to invent it, is yet more evidence that our entire payment infrastructure is fundamentally flawed.
Well to be honest Honey Tokens is being used since beginning of the 2000s, https://en.wikipedia.org/wiki/Honeytoken . I personally implemented them in a Bank, 20 years ago, generating some fake credit cards number (and other information) and having them being monitored in AV, IDS, IPS, Antifraud solutions like browser extensions, google search and etc.. So maybe we can say that I'm a random infosec nerd, but i guess,…
Detect breaches with Canary credit cards
61–70 of 158 posts
Re: Detect breaches with Canary credit cards
#62Looks neat and thanks for sharing idea. Aren't professionnal going to just discard all numbers associated with this "bank", then ?
Re: Detect breaches with Canary credit cards
#63> Some places we recommend putting these include: Databases where you store customer payment information alarm klaxon sounds Why do you have a database containing customer payment information?
Re: Detect breaches with Canary credit cards
#64This idea has an obvious problem. It's a lot of hard work. How many people are going to be diligent in planting canaries etc? And if you are, can you be diligent for the next 1, 2, 3 decades? That's a lot of time spent on this. You know what would be better? If every bank provided as a service/feature the ability to create single-use (and single-merchant!) debit cards. Revolut can do it, why can't huge banks do it as…
Re: Detect breaches with Canary credit cards
#65> Some places we recommend putting these include: Databases where you store customer payment information alarm klaxon sounds Why do you have a database containing customer payment information?
Reducing friction in repeated transactions? Someone needs to store it.
Re: Detect breaches with Canary credit cards
#66> Some places we recommend putting these include: Databases where you store customer payment information alarm klaxon sounds Why do you have a database containing customer payment information?
Re: Detect breaches with Canary credit cards
#67I have uncovered flaws in online merchants this way, and notified them. They were usually grateful, especially so since the fraudulent charges failed.
Re: Detect breaches with Canary credit cards
#68> Some places we recommend putting these include: Databases where you store customer payment information alarm klaxon sounds Why do you have a database containing customer payment information?
Also, tons of companies have one-click payment options (ever order something from Chipoltle or Dominos app?)
Edit: It should be disincentivised, but look at any "punishment" for a data leak and it's cheaper for them to just lose the data
Re: Detect breaches with Canary credit cards
#69This idea has an obvious problem. It's a lot of hard work. How many people are going to be diligent in planting canaries etc? And if you are, can you be diligent for the next 1, 2, 3 decades? That's a lot of time spent on this. You know what would be better? If every bank provided as a service/feature the ability to create single-use (and single-merchant!) debit cards. Revolut can do it, why can't huge banks do it as…
Re: Detect breaches with Canary credit cards
#70> Some places we recommend putting these include: Databases where you store customer payment information alarm klaxon sounds Why do you have a database containing customer payment information?
Do you think companies avoid storing this data? There's no reason for them not to , so they do it. Look at the target hack for an example of real word credit card info stored. Also, tons of companies have one-click payment options (ever order something from Chipoltle or Dominos app?) Edit: It should be disincentivised, but look at any "punishment" for a data leak and it's cheaper for them to just lose the data
Individual retailers have no need to store actual cardholder information. All the payment platforms provide ways to persist cardholder information, in a way that allows it to be reused but never read.