Live data from Hacker News

Detect breaches with Canary credit cards

blog.thinkst.com

91–100 of 158 posts

Re: Detect breaches with Canary credit cards

#91
Does anyone have a good alternative to Privacy.com where your virtual credit card transaction data isn't sold to Wall Street? If you're unfamiliar with what a "virtual [credit] card" is here's the page from Privacy.com's website: https://privacy.com/virtual-card I use the Privacy app on my mobile phone to create virtual cards (primarily for work subscriptions). Pro-tip: since each Privacy card can have its own name put a tag such as `[WORK_RECURRING]` into the card name and then you can search your email inbox for `[WORK_RECURRING]`, quickly and easily finding all of the transactions / charges that you may want to submit to your workplace for reimbursement.

Privacy is owned / created by Lithic, but if you look at Lithic's investors you'll see that the plurality of the company's investors are in the private equity or VC space: Bessemer Ventures, Tusk Partner Ventures, Index Ventures, etc. You can see the Privacy.com / Privacy mobile app's funders here: https://www.crunchbase.com/organization/lithic-pay

Thus, I have no doubt that my transactions on cleverly-named Privacy app are being gifted or sold to Wall Street so that hedge funds can squeeze out a few addition drops of 'signal' from consumer purchase pattern data that would otherwise remain dark. (I'd imagine that many folks use the Privacy app to buy things that they'd rather not have show up on their regular credit card bills: 'adult websites', marijuana or tobacco products, etc.

So, two questions:

(1) Does anyone have a privacy-respecting alternative to Privacy.com's virtual credit cards?

(2) Does anyone know of a recent blog post where these virtual credit card services are compared / contrasted by

- the services that they offer, - the cost: free, paid, etc., - the terms of service: how your data is re-sold / who your data is transmitted to

Re: Detect breaches with Canary credit cards

#92
post #5

Looks neat and thanks for sharing idea. Aren't professionnal going to just discard all numbers associated with this "bank", then ?

> Savvy attackers may start looking for patterns in the bank identification numbers (BINs) that we issue, and proactively deleting or excluding them from their dumps. For this reason we are in discussions with a number of banks to onboard their BINs to the system too, further mixing in legitimate cards with tokens. > It’s a compelling argument: “Would you like attackers to first remove your bank’s cards from dumps th…

I've thought about something similar for spam calls: I can play whack-a-mole blocking individual numbers, but it won't scale fast enough and scammers will always get to me. I can rely on iphone's "scam likely" notification and just not answer those, which helps.

If the latter (and whatever similar feature android has) were somehow perfect, scammers would have a bad time. But.. if they convinced (paid) some (more-)legitimate companies to have their outgoing calls show up as the same number as the scammers use, people would eventually learn that they have to pick up scam calls or else miss calls from their bank/pharmacy/whatever.

Re: Detect breaches with Canary credit cards

#93
post #2

Very neat! I can definitely see that adding a couple of these to ones password manager would be hugely valuable!

True, but if your password vault becomes compromised, you have significantly bigger problems than credit cards being compromised.

In that case you're almost completely screwed... but you would want to know sooner rather than later, right?

Re: Detect breaches with Canary credit cards

#94

Earlier quoted context omitted.

Do you think companies avoid storing this data? There's no reason for them not to , so they do it. Look at the target hack for an example of real word credit card info stored. Also, tons of companies have one-click payment options (ever order something from Chipoltle or Dominos app?) Edit: It should be disincentivised, but look at any "punishment" for a data leak and it's cheaper for them to just lose the data

PCI-DSS compliance auditing is not cheap. There’s the incentive right there. Individual retailers have no need to store actual cardholder information. All the payment platforms provide ways to persist cardholder information, in a way that allows it to be reused but never read.

> All the payment platforms provide ways to persist cardholder information, in a way that allows it to be reused but never read.

This is usually called tokenization, if you want to search for it.

Re: Detect breaches with Canary credit cards

#95
post #90

> Mix it in with your store of saved card data or on payment gateways. An attacker who plans to test the cards (as they normally do when obtaining them) or attackers who try to use them will immediately advertise their presence, and your response team can spring into action. Spring into action, to shut the barn door after the cows already got out? Getting alerted is good, but it's unfortunate that infosec practice st…

It's not a replacement for any prevention you apply first. It's not a band-aid. It's one more layer of what you can do and it is valuable to know when you were breached.

It's basically an answer to: do you want to know that things went bad shortly after they did, or months later?

Re: Detect breaches with Canary credit cards

#96
post #83
post #25

Earlier quoted context omitted.

Bounty hunters are not really a thing in the way you’re thinking - they can’t just go to Japan, investigate someone, arrest them and bring back someone from there for instance. They’re for returning someone already arrested who jumped bail somewhere. And they typically don’t work internationally, as their legality is dubious even within a specific jurisdiction. For something major, it’s generally already possible to…

You wouldn’t send a bounty hunter to Japan. You’d hire a Japanese bounty hunter who operates in Japan. Or, more specifically, you’d put up a bounty for someone’s arrest in Japan, and one or more Japanese bounty hunters would “take on” the bounty. Also, the goal of hiring a bounty hunter, presumably, wouldn’t be to get them arrested for things that are crimes in some other country, but rather to get them arrested for…

What would the Japanese bounty hunter arrest the person in Japan for and on who’s authority?

Re: Detect breaches with Canary credit cards

#97
post #90

> Mix it in with your store of saved card data or on payment gateways. An attacker who plans to test the cards (as they normally do when obtaining them) or attackers who try to use them will immediately advertise their presence, and your response team can spring into action. Spring into action, to shut the barn door after the cows already got out? Getting alerted is good, but it's unfortunate that infosec practice st…

It's not a replacement for any prevention you apply first. It's not a band-aid. It's one more layer of what you can do and it is valuable to know when you were breached. It's basically an answer to: do you want to know that things went bad shortly after they did, or months later?

I didn't like the connotation of "spring into action". That sounded like sitting on butts before.

Re: Detect breaches with Canary credit cards

#98
post #83
post #25

Earlier quoted context omitted.

Bounty hunters are not really a thing in the way you’re thinking - they can’t just go to Japan, investigate someone, arrest them and bring back someone from there for instance. They’re for returning someone already arrested who jumped bail somewhere. And they typically don’t work internationally, as their legality is dubious even within a specific jurisdiction. For something major, it’s generally already possible to…

You wouldn’t send a bounty hunter to Japan. You’d hire a Japanese bounty hunter who operates in Japan. Or, more specifically, you’d put up a bounty for someone’s arrest in Japan, and one or more Japanese bounty hunters would “take on” the bounty. Also, the goal of hiring a bounty hunter, presumably, wouldn’t be to get them arrested for things that are crimes in some other country, but rather to get them arrested for…

This isn’t Star Wars or the Wild West btw.

Bounties in the US are issued by the court. You can’t issue one as a private person.

For it to be legal for a bounty hunter to do anything, they need to comply with some laws while doing it. Otherwise, it’s false arrest and/or kidnapping.

Which I’m sure with some work, and a lot of money, some folks would be willing to do for you. However, I doubt it would go well for anyone, and certainly wouldn’t result in the person being taken going to jail if all they did was scam someone.

Targeted International kidnapping (human trafficking?) is one of the ‘quite serious’ things likely to get whoever initiated it tracked down and thrown in jail though.

Near as I can tell, only the Philippines has a similar system.

It gets a lot of press and there are a lot of legends around it, but it isn’t what you think.

The formal system for having someone arrested and sent to another county is extradition, and it works rather differently. It’s slow, expensive, and rarely used outside of serious crimes.

Having someone arrested, tried, and penalized in another country for committing a crime against you somewhere else is also not easy.

1) often the courts in the attackers country will say they have no jurisdiction to try them, as the crimes were committed elsewhere. This can also happen if you try it in the victims country.

2) you run across all sorts of ‘meh, don’t care’ issues when the attacker is bringing in good money locally and the victims are seen as ‘not here/not anyone we care about’

3) good luck collecting evidence, making a case, getting them arrested, etc. in a foreign county, speaking a foreign language, with a legal system that you don’t understand. It’s hard enough doing it when it’s local.

4) if the local legal system is known for corruption, good luck figuring out which buttons to push. The attacker almost certainly is already familiar with them.

Not impossible. But the costs can easily be > $100k, sometimes in the millions.

Hence the ‘serious enough’ bar too.

Re: Detect breaches with Canary credit cards

#99

Does anyone have a good alternative to Privacy.com where your virtual credit card transaction data isn't sold to Wall Street? If you're unfamiliar with what a "virtual [credit] card" is here's the page from Privacy.com's website: https://privacy.com/virtual-card I use the Privacy app on my mobile phone to create virtual cards (primarily for work subscriptions). Pro-tip: since each Privacy card can have its own name p…

I would bet that all of your electronic transactions end up in some pool of data, no matter what you try. I believe only cash at a swap meet while wearing dark sunglasses and a hat is really private.

Re: Detect breaches with Canary credit cards

#100
post #74
post #67

I use Privacy.com, which basically turns every card I use with them into a canary. The first time you charge on one of their virtual cards, they become merchant-locked. No other merchant can charge to that number, and if someone tries, I get an alert. I have uncovered flaws in online merchants this way, and notified them. They were usually grateful, especially so since the fraudulent charges failed.

It's also frankly absurd that no such service exists for European customers. I've been looking the past few days for someone who does something like this and it's just not available, for what I can only assume are regulatory reasons.

Credit card shouldn’t need to be shared with all and sundry. The concept is very old fashioned. We wouldn’t share out side project github keys like this!
Post reply on HN