Live data from Hacker News

Detect breaches with Canary credit cards

blog.thinkst.com

111–120 of 158 posts

Re: Detect breaches with Canary credit cards

#111
post #74

Earlier quoted context omitted.

It's also frankly absurd that no such service exists for European customers. I've been looking the past few days for someone who does something like this and it's just not available, for what I can only assume are regulatory reasons.

What's absurd is that this is something I have to pay for or find a particular issuer of a visa/mastercard. It should be free and included with every visa and mastercard. They should demand that every issuer of their cards needs to offer virtual cards and 3d secure. If they don't then their fees should be significantly higher.

How is that absurd? There is approximately zero consumer demand for stuff like this. Remember when chip cards were deployed 10 years ago and everyone was annoyed at how chip readers forced them to have the card out longer? Or how Amazon often doesn't check CVV numbers because doing do would increase attrition?

Of course a few of the largest banks find it worthwhile to add a page to their website where you can generate virtual card numbers, but it's not a huge win for them by any means even when they're liable for stolen cards.

Re: Detect breaches with Canary credit cards

#112
This is a very shortsighted and short-lived idea - cyber criminals will find out the first digits of all these canary credit cards and never bother to test them. Even if multiple prefixes come into existence, unless they are mixed with normal credit cards, this won't ever make practical sense.

Re: Detect breaches with Canary credit cards

#113
post #107
post #67

I use Privacy.com, which basically turns every card I use with them into a canary. The first time you charge on one of their virtual cards, they become merchant-locked. No other merchant can charge to that number, and if someone tries, I get an alert. I have uncovered flaws in online merchants this way, and notified them. They were usually grateful, especially so since the fraudulent charges failed.

I'll give you a warning about them, they won't issue a chargeback for anything. Even blatant fraud. They'll give you a vague response about rules with their processor. I used them for a purchase, the company then blatantly lied about everything (tweeted that "everyone's order was shipped" 2 weeks before I even got a tracking number). They asked me for the following: - Order receipts - Email communication with the com…

Their processor is Lithic. Which is them. Haha.

Re: Detect breaches with Canary credit cards

#114
post #74

Earlier quoted context omitted.

It's also frankly absurd that no such service exists for European customers. I've been looking the past few days for someone who does something like this and it's just not available, for what I can only assume are regulatory reasons.

Credit card shouldn’t need to be shared with all and sundry. The concept is very old fashioned. We wouldn’t share out side project github keys like this!

The system works because it's mostly reversible. If my card gets leaked and someone tries to use it. I just disable my card in the app, contact the bank, they refund the money and issue a new card. Perhaps sometimes the bank has to eat the loss but it works out perfect for the consumer.

Re: Detect breaches with Canary credit cards

#115

This is a very shortsighted and short-lived idea - cyber criminals will find out the first digits of all these canary credit cards and never bother to test them. Even if multiple prefixes come into existence, unless they are mixed with normal credit cards, this won't ever make practical sense.

From the article:

"Savvy attackers may start looking for patterns in the bank identification numbers (BINs) that we issue, and proactively deleting or excluding them from their dumps. For this reason we are in discussions with a number of banks to onboard their BINs to the system too, further mixing in legitimate cards with tokens."

Re: Detect breaches with Canary credit cards

#117

Does anyone have a good alternative to Privacy.com where your virtual credit card transaction data isn't sold to Wall Street? If you're unfamiliar with what a "virtual [credit] card" is here's the page from Privacy.com's website: https://privacy.com/virtual-card I use the Privacy app on my mobile phone to create virtual cards (primarily for work subscriptions). Pro-tip: since each Privacy card can have its own name p…

> (1) Does anyone have a privacy-respecting alternative to Privacy.com's virtual credit cards? Capital One offers virtual cards through Eno ( https://www.capitalone.com/digital/eno/virtual-card-numbers/ ) that are merchant locked. They make it somewhat cumbersome to use, but I've really enjoyed using them. It doesn't block wall street knowing about what you're buying, but at least it's likely got one (or more) fewer…

I can confirm this works pretty well. The Capital One mobile app will also give you a single virtual card number (without the merchant lock or any other extra features) if you don’t want the browser extension or just need it once.

Re: Detect breaches with Canary credit cards

#118
post #115

This is a very shortsighted and short-lived idea - cyber criminals will find out the first digits of all these canary credit cards and never bother to test them. Even if multiple prefixes come into existence, unless they are mixed with normal credit cards, this won't ever make practical sense.

From the article: "Savvy attackers may start looking for patterns in the bank identification numbers (BINs) that we issue, and proactively deleting or excluding them from their dumps. For this reason we are in discussions with a number of banks to onboard their BINs to the system too, further mixing in legitimate cards with tokens."

True. But this only mitigate the problem, doesn't solve it. Whatever BINs they use, there must be some noticeable patterns, simply because these cards are NOT regular cards.

Re: Detect breaches with Canary credit cards

#119

Earlier quoted context omitted.

> Savvy attackers may start looking for patterns in the bank identification numbers (BINs) that we issue, and proactively deleting or excluding them from their dumps. For this reason we are in discussions with a number of banks to onboard their BINs to the system too, further mixing in legitimate cards with tokens. > It’s a compelling argument: “Would you like attackers to first remove your bank’s cards from dumps th…

I've thought about something similar for spam calls: I can play whack-a-mole blocking individual numbers, but it won't scale fast enough and scammers will always get to me. I can rely on iphone's "scam likely" notification and just not answer those, which helps. If the latter (and whatever similar feature android has) were somehow perfect, scammers would have a bad time. But.. if they convinced (paid) some (more-)leg…

> if they convinced (paid) some (more-)legitimate companies to have their outgoing calls show up as the same number as the scammers use

In the US the STIR/SHAKEN[1] protocol adds source-verification. If/when this finally gets fully rolled out, spoofing caller ID without it being blocked is going to get much harder.

But, I'm sure the next step for them is to just go after the millions of small-medium business IP telephony systems that are either poorly configured with default/guessable passwords, or have wide-open security holes.

[1] https://en.wikipedia.org/wiki/STIR/SHAKEN

Re: Detect breaches with Canary credit cards

#120

Does anyone have a good alternative to Privacy.com where your virtual credit card transaction data isn't sold to Wall Street? If you're unfamiliar with what a "virtual [credit] card" is here's the page from Privacy.com's website: https://privacy.com/virtual-card I use the Privacy app on my mobile phone to create virtual cards (primarily for work subscriptions). Pro-tip: since each Privacy card can have its own name p…

> (1) Does anyone have a privacy-respecting alternative to Privacy.com's virtual credit cards? Capital One offers virtual cards through Eno ( https://www.capitalone.com/digital/eno/virtual-card-numbers/ ) that are merchant locked. They make it somewhat cumbersome to use, but I've really enjoyed using them. It doesn't block wall street knowing about what you're buying, but at least it's likely got one (or more) fewer…

Citi also offers unlimited virtual card numbers for credit cards, and it is a bit easier than Eno since you can manage directly from the website without needing to install anything.
Post reply on HN