Live data from Hacker News

Detect breaches with Canary credit cards

blog.thinkst.com

121–130 of 158 posts

Re: Detect breaches with Canary credit cards

#121
post #74

Earlier quoted context omitted.

It's also frankly absurd that no such service exists for European customers. I've been looking the past few days for someone who does something like this and it's just not available, for what I can only assume are regulatory reasons.

Its my understandingn that Visa does offer the service to banks, they just haven't implemented it. There is to my knowledge no regulatory red tape, it's just not seem as profitable. The banks here in Denmark har just less competitive and more entrenched than in the US

My Swedish bank (Swedbank) had this service from some time in the 00's up until 2017 when they discontinued it. So they were way ahead of the game but for some reason dropped it.

Re: Detect breaches with Canary credit cards

#122
post #107

Earlier quoted context omitted.

I'll give you a warning about them, they won't issue a chargeback for anything. Even blatant fraud. They'll give you a vague response about rules with their processor. I used them for a purchase, the company then blatantly lied about everything (tweeted that "everyone's order was shipped" 2 weeks before I even got a tracking number). They asked me for the following: - Order receipts - Email communication with the com…

I’ve been afraid of this because I’m pretty sure their protection level is the same as a debit card, which is to say nothing really.

That‘s really no longer true for most debit cards these days. Issuers can process disputes for debit and credit cards in the exact same way (at least for transactions on Visa and Mastercard, i.e. practically for all online payments).

Higher tier credit cards often have additional insurance that goes beyond what the chargeback mechanism is designed for, though, but for fraud, you shouldn’t need these.

Re: Detect breaches with Canary credit cards

#123
post #74

Earlier quoted context omitted.

It's also frankly absurd that no such service exists for European customers. I've been looking the past few days for someone who does something like this and it's just not available, for what I can only assume are regulatory reasons.

Credit card shouldn’t need to be shared with all and sundry. The concept is very old fashioned. We wouldn’t share out side project github keys like this!

Quite the opposite: It should, in an ideal world, be perfectly safe to share your credit card number with everyone, because all it should be is arguably an account number.

Payment initiation or confirmation can be an entirely separate layer (such as chip + PIN or 3D Secure).

This is actually the goal of European regulators right now (with some carve-outs for low value and low-risk transactions).

Re: Detect breaches with Canary credit cards

#124
post #74

Earlier quoted context omitted.

It's also frankly absurd that no such service exists for European customers. I've been looking the past few days for someone who does something like this and it's just not available, for what I can only assume are regulatory reasons.

What's absurd is that this is something I have to pay for or find a particular issuer of a visa/mastercard. It should be free and included with every visa and mastercard. They should demand that every issuer of their cards needs to offer virtual cards and 3d secure. If they don't then their fees should be significantly higher.

Capital One offers it on their certain credit cards. Somehow Google Chrome, when you save Capital One card in it, offers to generate virtual directly from Chrome.

Re: Detect breaches with Canary credit cards

#125
post #74
post #67

I use Privacy.com, which basically turns every card I use with them into a canary. The first time you charge on one of their virtual cards, they become merchant-locked. No other merchant can charge to that number, and if someone tries, I get an alert. I have uncovered flaws in online merchants this way, and notified them. They were usually grateful, especially so since the fraudulent charges failed.

It's also frankly absurd that no such service exists for European customers. I've been looking the past few days for someone who does something like this and it's just not available, for what I can only assume are regulatory reasons.

Regulations are indeed the reason that Europe does not have proxy cards, but pretty indirectly:

In the US, debit card interchange is heavily regulated for most issuers (to an extremely low rate of 0.05% plus a flat 0.24$ per transaction, which can be frustrating for microtransactions, but that's a different story).

Some issuers are exempt from this requirement, though – very likely including the one that Privacy/Lithic use. This gives them a very nice arbitrage opportunity which can pay for the product and even return a profit.

In Europe, there is no such exemption, so a proxy card can even theoretically never be profitable (you earn 0.2% but also pay 0.2% per debit transaction, and after network fees, you're in the red).

What would be possible is to offer single-used debit cards that are funded from a bank account via direct debit, which is effectively fee-free (but decidedly not risk-free). Privacy offers that option as well in the US.

But given the direction into which the EU is moving (heavily guided by regulation), which is to effectively mandate 3D Secure for almost all online transactions, it's questionable how much demand for such a product there really will be, going forward.

Re: Detect breaches with Canary credit cards

#126

Does anyone have a good alternative to Privacy.com where your virtual credit card transaction data isn't sold to Wall Street? If you're unfamiliar with what a "virtual [credit] card" is here's the page from Privacy.com's website: https://privacy.com/virtual-card I use the Privacy app on my mobile phone to create virtual cards (primarily for work subscriptions). Pro-tip: since each Privacy card can have its own name p…

> (1) Does anyone have a privacy-respecting alternative to Privacy.com's virtual credit cards? Capital One offers virtual cards through Eno ( https://www.capitalone.com/digital/eno/virtual-card-numbers/ ) that are merchant locked. They make it somewhat cumbersome to use, but I've really enjoyed using them. It doesn't block wall street knowing about what you're buying, but at least it's likely got one (or more) fewer…

Once I saved Capital One card in Google Chrome, Payment Methods in Chrome Settings offers a radio button Virtual Card On/Off. If switched on, Chrome directly generates a virtual card, removing the need of Eno extension.

Re: Detect breaches with Canary credit cards

#127

This idea has an obvious problem. It's a lot of hard work. How many people are going to be diligent in planting canaries etc? And if you are, can you be diligent for the next 1, 2, 3 decades? That's a lot of time spent on this. You know what would be better? If every bank provided as a service/feature the ability to create single-use (and single-merchant!) debit cards. Revolut can do it, why can't huge banks do it as…

Capital One does still have these: https://www.capitalone.com/digital/eno/ though caveat the feature is only available via a browser plugin, I assume because they want to be able to scrape your shopping habits/history in the process.

Now its available through their own app, and if/once you save actual card in Google Chrome, its directly available from Chrome in any credit card box. No need of Eno now.

Re: Detect breaches with Canary credit cards

#128
post #122

Earlier quoted context omitted.

I’ve been afraid of this because I’m pretty sure their protection level is the same as a debit card, which is to say nothing really.

That‘s really no longer true for most debit cards these days. Issuers can process disputes for debit and credit cards in the exact same way (at least for transactions on Visa and Mastercard, i.e. practically for all online payments). Higher tier credit cards often have additional insurance that goes beyond what the chargeback mechanism is designed for, though, but for fraud, you shouldn’t need these.

It kind of kills me how badly understood this is in /r/personalfinance.

I think something like 85%+ of banks now offer next day refund of fraudulent charges from debit card charges. But that statistic is kind of meaningless in that, if your bank offers it, there's not a lot of extra protection a CC card grants you unless there's a specific value-add to the card that is meant to retain you as a customer.

Re: Detect breaches with Canary credit cards

#129
post #74

Earlier quoted context omitted.

It's also frankly absurd that no such service exists for European customers. I've been looking the past few days for someone who does something like this and it's just not available, for what I can only assume are regulatory reasons.

What's absurd is that this is something I have to pay for or find a particular issuer of a visa/mastercard. It should be free and included with every visa and mastercard. They should demand that every issuer of their cards needs to offer virtual cards and 3d secure. If they don't then their fees should be significantly higher.

Issuers effectively do need to offer 3D secure, since they are liable for all fraud that happens on 3DS-enabled transactions. It's just their choice on whether they choose to require authentication at all, some, or no transactions.

The US has more of a free market approach here, and experience has shown that the conversion rate hit is often much more severe than the reduction in fraud. Consumers will just use the most convenient card, and that turns out to be the one that just lets them buy (almost) everything without additional challenges.

The EU is taking the approach of forcing all issuers to challenge cardholders for most (higher value/risk) transactions. Given that the rules are the same for everyone, cardholders have nowhere to "escape" to – and issuers finally were forced to invest into making their implementations more usable.

Re: Detect breaches with Canary credit cards

#130
post #74

Earlier quoted context omitted.

It's also frankly absurd that no such service exists for European customers. I've been looking the past few days for someone who does something like this and it's just not available, for what I can only assume are regulatory reasons.

Its my understandingn that Visa does offer the service to banks, they just haven't implemented it. There is to my knowledge no regulatory red tape, it's just not seem as profitable. The banks here in Denmark har just less competitive and more entrenched than in the US

I wouldn't say that banking is particularly competitive in the US when it comes to technological/product features such as this. Out of several of my cards, only one issuer offers virtual/one-time use card numbers themselves.
Post reply on HN