Earlier quoted context omitted.
You're missing the point entirely. I'm not saying that chip & pin has no value. I'm saying that the value it has is finite (i.e. it saves money equal to the amount of fraud it eliminates) and needs to be weight against the cost of replacing all the card reader infrastructure. And I argue that the fact the US has not upgraded is an existence proof that the upgrade cost[1] outweighs the savings. [1] Really the amortize…
"cost of replacing all the card reader infrastructure" I'm not sure how many PoS are already equipped to deal with chip cards. In the USA/Canada it's hit or miss (most misses), and in Europe it was the standard 10 years ago (but most readers take swipe cards). Replacing cards is cheap and they can be replaced as they expire What would be the upgrade cost for each PoS? $100? Some systems are more integrated than other…
IAmA a malware coder and botnet operator, AMA
101–110 of 203 posts
Re: IAmA a malware coder and botnet operator, AMA
#102Let's play 33 bits on this guy, my guess is that he's German, Austrian or Swiss based on the settings for his IRC client, that should knock about 6 bits off, 27 to go.
oh I was doing that while reading the AMA. the giveaway is being the 4th customer of a bank that provides HBCI: > My bank had around 20,000 customers using smsTAN and 3 (I was the 4th lol) using HBCI. He is German, of college age and an early customer at one of 2 or 3 banks that provide HBCI. Consider him nailed. I also bet he has published security related work under his real name at some point, especially since he…
Re: IAmA a malware coder and botnet operator, AMA
#103Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…
I've only used VbV once or twice, years ago. Do they still use iframes? I've never understood why they try to make the site more "secure" by using these services, but then use an iframe so the average user can't easily confirm if the login screen is legit or not.
It really peeves me that they are training people to accept entering sensitive information into something it would be so very easy to fake. There's nothing to prove that it is actually what it says it is. On top of that, if you forget your phrase the security question (the usual researchable ones) and answer sequence happens within the iframe without recourse to any external site or emails.
As other comments have said, none of this is for the customers benefit.
Re: IAmA a malware coder and botnet operator, AMA
#104Earlier quoted context omitted.
They can't store the CVV2 either. Doing so, even encrypted, violates PCI-DSS.
You'd be surprised how many vendors and merchants simply do not care. I was employed with an e-commerce vendor that indefinitely stored CVV2 in plaintext (among other numbers).
Re: IAmA a malware coder and botnet operator, AMA
#105Let's play 33 bits on this guy, my guess is that he's German, Austrian or Swiss based on the settings for his IRC client, that should knock about 6 bits off, 27 to go.
Re: IAmA a malware coder and botnet operator, AMA
#106Magnetic stripes are the most hilarious thing ever, but still work almost everywhere on the globe. I am amazed that magnetic stripes are still the norm for credit cards in the US. Europe has managed to move all but completely to chip-based cards, but the US hasn't. Does the cost of fraud due to magnetic stripes outweigh the cost to upgrade the entire US system, or is the market just too fragmented to coordinate such…
Re: IAmA a malware coder and botnet operator, AMA
#107Earlier quoted context omitted.
I really wouldn't be surprised. The security group at my university do a lot of stuff on banking security, and from what I've heard, this was one of the main reasons behind the switch to chip-and-PIN in the UK --- the user is now liable when his card gets stolen and used.
That's not really true. The user is liable if the card is stolen, and it is used to conduct fraud using the PIN code. If the card is stolen, and the fraudster simply uses it online, or via some place that doesn't ask for a PIN, then you are not liable for that fraud. I'm sure there are rare edge cases, but my experience with Barclays has always been very good in this regard.
Re: IAmA a malware coder and botnet operator, AMA
#108Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…
In Canada it pops up a browser window that prompts for various personal information and its URL points at ... drumroll ... https://secureserver.net. If that's not by the book appearance of a phishing site, I don't know what is.
Re: IAmA a malware coder and botnet operator, AMA
#109Great nugget: > a US credit card costs 2$ on the black market and a UK starts at 60$, americans are all in debt.
Re: IAmA a malware coder and botnet operator, AMA
#110Earlier quoted context omitted.
Nothing. This 'feature' is entirely designed to reduce the banks' liability. It shifts the onus of security onto you (from the banks and the merchants).
It sounds like in principle it might also reduce fraud overall. Thus, maybe 80% of the fraud goes away and 20% remains, but that liability is shifted to the consumer rather than the bank (who otherwise passes it to the merchant anyway). If the merchant has reduced fraud liability, they may be able to offer lower prices. So, in principle there might be a long-term win for the consumer. In practice, who knows.