At least with a credit card you have some fraud protection. Report it and the charge should be reversed. And chargebacks are possible. With a debit card you’re playing with your own money.
Credit cards are vulnerable to brute force kind attacks
11–20 of 201 posts
Re: Credit cards are vulnerable to brute force kind attacks
#12At least with a credit card you have some fraud protection. Report it and the charge should be reversed. And chargebacks are possible. With a debit card you’re playing with your own money.
That has not been my experience with debit cards in the US at major banks, at all , over decades. (I'm pathologically avoidant of credit cards, which I think are mostly pointless.)
Re: Credit cards are vulnerable to brute force kind attacks
#13At least with a credit card you have some fraud protection. Report it and the charge should be reversed. And chargebacks are possible. With a debit card you’re playing with your own money.
That has not been my experience with debit cards in the US at major banks, at all , over decades. (I'm pathologically avoidant of credit cards, which I think are mostly pointless.)
Re: Credit cards are vulnerable to brute force kind attacks
#14People should have a separate card for online payments and have just enough money on it for a payment. I know that I am naïve :) Back to the article: Weak point was a password that lead to another merchant not using 3D secure. It seems from the article that bad actors have fully automated system, so (big) merchants should have handle automatic login attempts from the same ip address with different accounts. I see it…
Re: Credit cards are vulnerable to brute force kind attacks
#15Some have speculated that the entire credit card system is compromised, end to end. I think the real question is why NSA didn't intervene in the early 1990s. Online commerce was just beginning, and the importance of electronic funds transfer was obvious, but the method wasn't set in stone. NSA knew about public key crypto well before the rest of us did. They could have helped set up very secure electronic payments, b…
NSA prefers compromised security so that answers your question Credit card system was already around for decades before though
Re: Credit cards are vulnerable to brute force kind attacks
#16> The data they took with the attempt of purchase is the card is still usable (not cancelled)
The payment flows should not distinguish between a nonexistent card, a cancelled card, and a valid card that needs 3D Secure. I bet the banks could even implement that without any cooperation on the part of the merchants.
Re: Credit cards are vulnerable to brute force kind attacks
#17At least with a credit card you have some fraud protection. Report it and the charge should be reversed. And chargebacks are possible. With a debit card you’re playing with your own money.
Re: Credit cards are vulnerable to brute force kind attacks
#18Earlier quoted context omitted.
That has not been my experience with debit cards in the US at major banks, at all , over decades. (I'm pathologically avoidant of credit cards, which I think are mostly pointless.)
You can reverse the charges on debit cards, but the money is withdrawn at the time the charge is made. This is not the case for credit cards.
Re: Credit cards are vulnerable to brute force kind attacks
#19Earlier quoted context omitted.
That has not been my experience with debit cards in the US at major banks, at all , over decades. (I'm pathologically avoidant of credit cards, which I think are mostly pointless.)
You can reverse the charges on debit cards, but the money is withdrawn at the time the charge is made. This is not the case for credit cards.
Re: Credit cards are vulnerable to brute force kind attacks
#20Some have speculated that the entire credit card system is compromised, end to end. I think the real question is why NSA didn't intervene in the early 1990s. Online commerce was just beginning, and the importance of electronic funds transfer was obvious, but the method wasn't set in stone. NSA knew about public key crypto well before the rest of us did. They could have helped set up very secure electronic payments, b…