Live data from Hacker News

Credit cards are vulnerable to brute force kind attacks

metin.nextc.org

11–20 of 201 posts

Re: Credit cards are vulnerable to brute force kind attacks

#11

At least with a credit card you have some fraud protection. Report it and the charge should be reversed. And chargebacks are possible. With a debit card you’re playing with your own money.

In the US at least, there are still federal protections for debit card fraud: https://uslawexplained.com/debit_card

Re: Credit cards are vulnerable to brute force kind attacks

#12
post #9

At least with a credit card you have some fraud protection. Report it and the charge should be reversed. And chargebacks are possible. With a debit card you’re playing with your own money.

That has not been my experience with debit cards in the US at major banks, at all , over decades. (I'm pathologically avoidant of credit cards, which I think are mostly pointless.)

You can reverse the charges on debit cards, but the money is withdrawn at the time the charge is made. This is not the case for credit cards.

Re: Credit cards are vulnerable to brute force kind attacks

#13
post #9

At least with a credit card you have some fraud protection. Report it and the charge should be reversed. And chargebacks are possible. With a debit card you’re playing with your own money.

That has not been my experience with debit cards in the US at major banks, at all , over decades. (I'm pathologically avoidant of credit cards, which I think are mostly pointless.)

[deleted]

Re: Credit cards are vulnerable to brute force kind attacks

#14
post #2

People should have a separate card for online payments and have just enough money on it for a payment. I know that I am naïve :) Back to the article: Weak point was a password that lead to another merchant not using 3D secure. It seems from the article that bad actors have fully automated system, so (big) merchants should have handle automatic login attempts from the same ip address with different accounts. I see it…

Not affiliated, but Capital One Eno virtual cards work well for this purpose.

Re: Credit cards are vulnerable to brute force kind attacks

#15
post #8

Some have speculated that the entire credit card system is compromised, end to end. I think the real question is why NSA didn't intervene in the early 1990s. Online commerce was just beginning, and the importance of electronic funds transfer was obvious, but the method wasn't set in stone. NSA knew about public key crypto well before the rest of us did. They could have helped set up very secure electronic payments, b…

NSA prefers compromised security so that answers your question Credit card system was already around for decades before though

I heard a rumor that NSA suggested changes to DES encryption that strengthened it from differential cryptanalysis attacks that the public cryptologists weren't aware of yet.

Re: Credit cards are vulnerable to brute force kind attacks

#16
Another mistake:

> The data they took with the attempt of purchase is the card is still usable (not cancelled)

The payment flows should not distinguish between a nonexistent card, a cancelled card, and a valid card that needs 3D Secure. I bet the banks could even implement that without any cooperation on the part of the merchants.

Re: Credit cards are vulnerable to brute force kind attacks

#17

At least with a credit card you have some fraud protection. Report it and the charge should be reversed. And chargebacks are possible. With a debit card you’re playing with your own money.

how is it not also your money when using a credit card? It's in the name, "credit" card. you have to pay it off, no? (i have never ever used a credit card)

Re: Credit cards are vulnerable to brute force kind attacks

#18
post #9

Earlier quoted context omitted.

That has not been my experience with debit cards in the US at major banks, at all , over decades. (I'm pathologically avoidant of credit cards, which I think are mostly pointless.)

You can reverse the charges on debit cards, but the money is withdrawn at the time the charge is made. This is not the case for credit cards.

That's true, but it's not the claim the parent commenter made.

Re: Credit cards are vulnerable to brute force kind attacks

#19
post #9

Earlier quoted context omitted.

That has not been my experience with debit cards in the US at major banks, at all , over decades. (I'm pathologically avoidant of credit cards, which I think are mostly pointless.)

You can reverse the charges on debit cards, but the money is withdrawn at the time the charge is made. This is not the case for credit cards.

Most US banks will credit your account for the amount of the dispute immediately upon starting the investigation, so it is functionally equivalent from a consumer perspective.

Re: Credit cards are vulnerable to brute force kind attacks

#20

Some have speculated that the entire credit card system is compromised, end to end. I think the real question is why NSA didn't intervene in the early 1990s. Online commerce was just beginning, and the importance of electronic funds transfer was obvious, but the method wasn't set in stone. NSA knew about public key crypto well before the rest of us did. They could have helped set up very secure electronic payments, b…

"The RSA algorithm was publicly described in 1977 by Ron Rivest, Adi Shamir, and Leonard Adleman at MIT"
Post reply on HN