Live data from Hacker News

Detect breaches with Canary credit cards

blog.thinkst.com

81–90 of 158 posts

Re: Detect breaches with Canary credit cards

#81
post #67

I use Privacy.com, which basically turns every card I use with them into a canary. The first time you charge on one of their virtual cards, they become merchant-locked. No other merchant can charge to that number, and if someone tries, I get an alert. I have uncovered flaws in online merchants this way, and notified them. They were usually grateful, especially so since the fraudulent charges failed.

Worth mentioning that several banks offer virtual credit card numbers as a built-in feature so you don't need a separate service: https://www.doctorofcredit.com/list-of-banks-which-offer-vir...

I've only used this for the sketchiest of vendors though. Chargebacks are pretty easy for the once-a-decade event where I get billed for something incorrectly.

Re: Detect breaches with Canary credit cards

#82
post #18

I have wanted something like this to give to scammers, to help aid in their detection and capture. This is part of that puzzle. Now if only law enforcement would give a shit and do something about all of the rampant fraud. Sadly, I do not believe that will ever happen.

Near as I can tell, a lot of the fraud is exploitation of the known and not yet solved ‘remote jurisdiction’ issue. When someone is far away, and in a different jurisdiction, it’s hard to track them down and do anything to them. Not likely to get better anytime soon, unfortunately.

And even if you can both track them down and hand evidence of wrongdoing on a silver platter to law enforcement in their jurisdiction, often the places these criminals operate out of were selected specifically because their justice system is corrupt and easily bribed. Often, these fraudsters can even talk local politicians into seeing their (cover) businesses as “important local industries, employing local citizens, generating taxable income, and making charitable donations.”

This is the strategy used by the harder-to-kill scam call-centres in India; certain cities in India (I believe Hyderabad?) have been repeatedly handed damning evidence of criminal acts by scammers operating there, but it gets swept under the rug every time. When a big-enough stink is made that it makes their own local news, they just give the criminals a slap on the wrist or lest (e.g. an arrest on low bail that they easily afford to pay, with the case then being dropped before it ever goes to trial, as soon as it’s out of the news.)

Re: Detect breaches with Canary credit cards

#83
post #25

Earlier quoted context omitted.

I thought bounty hunters were supposed to solve that. They ignore our laws, we ignore theirs. This leads to a hell of a dystopia, but spammers have left me no choice but to contemplate dystopias.

Bounty hunters are not really a thing in the way you’re thinking - they can’t just go to Japan, investigate someone, arrest them and bring back someone from there for instance. They’re for returning someone already arrested who jumped bail somewhere. And they typically don’t work internationally, as their legality is dubious even within a specific jurisdiction. For something major, it’s generally already possible to…

You wouldn’t send a bounty hunter to Japan. You’d hire a Japanese bounty hunter who operates in Japan. Or, more specifically, you’d put up a bounty for someone’s arrest in Japan, and one or more Japanese bounty hunters would “take on” the bounty.

Also, the goal of hiring a bounty hunter, presumably, wouldn’t be to get them arrested for things that are crimes in some other country, but rather to get them arrested for things that are crimes in their own country (or in whatever country they happen to be hiding it.)

Re: Detect breaches with Canary credit cards

#84
post #63

Earlier quoted context omitted.

Reducing friction in repeated transactions? Someone needs to store it.

Unless you’re an actual payment platform, that someone should not be you.

There's a tradeoff. Card numbers in your db are a lot easier to move between payment platforms than tokenized card numbers. So many merchants get screwed by payment platforms that lock them out right in the middle of a large sale because the sudden increase in transactions looks like fraud. You gotta look out for number one.

Re: Detect breaches with Canary credit cards

#85

Very interesting tool. I'm going to write the canary CC onto a physical card and swipe it first when shopping. If I ever see it randomly accessed, I'll know my 2nd card (actual payment card) is burnt. >Credit Card Rate-Limiting currently in place. Please try again later. Maybe tomorrow.

Hmmm … I like the idea but my hunch was that disposable card numbers would fail at POS because the network knows that card should never have been issued physically?

If you run this experiment, would you do a tell HN ?

Re: Detect breaches with Canary credit cards

#86
post #78
post #74

Earlier quoted context omitted.

It's also frankly absurd that no such service exists for European customers. I've been looking the past few days for someone who does something like this and it's just not available, for what I can only assume are regulatory reasons.

My understanding was that privacy.com is just a “detached service” implementation of something that many European banks offer natively as a feature of having a credit card (or even just a chequing account) with them; and that privacy.com was only viable as a business because, for some reason, American banks are (or were at the time) totally unwilling to build anything like this, so people were willing to settle for a…

I know my french bank offers a service like this, it is an extra though.

Re: Detect breaches with Canary credit cards

#87
post #78
post #74

Earlier quoted context omitted.

It's also frankly absurd that no such service exists for European customers. I've been looking the past few days for someone who does something like this and it's just not available, for what I can only assume are regulatory reasons.

My understanding was that privacy.com is just a “detached service” implementation of something that many European banks offer natively as a feature of having a credit card (or even just a chequing account) with them; and that privacy.com was only viable as a business because, for some reason, American banks are (or were at the time) totally unwilling to build anything like this, so people were willing to settle for a…

My Indian Bank, HDFC offers this since 2008, virtual cards with custom amount, one time use. On creation, the amount equal to limit gets set aside. If merchant charges less than max limit, the excess comes back.

Thier at-time debit cards were good only for domestic transactions, but this virtual was good for international, & used to come up as Visa Prepaid. I used it for registering domains & amazon international shopping.

Re: Detect breaches with Canary credit cards

#88
post #67

I use Privacy.com, which basically turns every card I use with them into a canary. The first time you charge on one of their virtual cards, they become merchant-locked. No other merchant can charge to that number, and if someone tries, I get an alert. I have uncovered flaws in online merchants this way, and notified them. They were usually grateful, especially so since the fraudulent charges failed.

I had heard of this service before and assumed it costed money, but thanks to your comment checked it out, and apparently they have a free tier allowing you to create 10 cards per month. Cool!

The only downside which stops me from using privacy.com us that I will lose the chance to earn points or Cashback, as privacy charges directly to your checking account (understandably).

Re: Detect breaches with Canary credit cards

#89
post #74
post #67

I use Privacy.com, which basically turns every card I use with them into a canary. The first time you charge on one of their virtual cards, they become merchant-locked. No other merchant can charge to that number, and if someone tries, I get an alert. I have uncovered flaws in online merchants this way, and notified them. They were usually grateful, especially so since the fraudulent charges failed.

It's also frankly absurd that no such service exists for European customers. I've been looking the past few days for someone who does something like this and it's just not available, for what I can only assume are regulatory reasons.

Its my understandingn that Visa does offer the service to banks, they just haven't implemented it. There is to my knowledge no regulatory red tape, it's just not seem as profitable.

The banks here in Denmark har just less competitive and more entrenched than in the US

Re: Detect breaches with Canary credit cards

#90
> Mix it in with your store of saved card data or on payment gateways. An attacker who plans to test the cards (as they normally do when obtaining them) or attackers who try to use them will immediately advertise their presence, and your response team can spring into action.

Spring into action, to shut the barn door after the cows already got out?

Getting alerted is good, but it's unfortunate that infosec practice still has so much band-aids, theatre, and reacting after that doesn't work.

Post reply on HN