Live data from Hacker News

Credit cards are vulnerable to brute force kind attacks

metin.nextc.org

31–40 of 201 posts

Re: Credit cards are vulnerable to brute force kind attacks

#31
Related story and wondering if the OP may have been chasing red herrings. I recently noticed an unauthorized charge for a small amount on my credit card (something about FB/Meta). Likely someone probing the card to see if anyone would notice. I called the CC company, had them removed the charge, canceled the card and had them send me a new card (5-7 business days). With the brand new unused card (new CC number, new expiration date, new CVV), the fraudulent payments resumed (again FB/Meta). How is this possible? The reason: digital wallets. Your credit card number, etc. transfers via digital wallets even when you cancel the card. I again called the credit card company and this time, told them to cancel all the digital wallets (there were 99 of them!). There is no way to do this online. You have to speak to a human in a call center. You then have to sit through a lecture about how all your renewing payments are going to reset and you will have to re-establish them will all merchants. "Yes, I understand that. Please cancel the card and all digital wallets!" Then you have to hold for twenty minutes (why? what are they doing? manually canceling all the digital wallets?). The lesson I learned here is that canceling your credit card may not be what you think. Also recurring payments must be incredibly lucrative and canceling them must amount to a big loss in revenue. (Edited for grammar.)

Re: Credit cards are vulnerable to brute force kind attacks

#32
post #2

People should have a separate card for online payments and have just enough money on it for a payment. I know that I am naïve :) Back to the article: Weak point was a password that lead to another merchant not using 3D secure. It seems from the article that bad actors have fully automated system, so (big) merchants should have handle automatic login attempts from the same ip address with different accounts. I see it…

Mercury now offers personal bank accounts. You can create virtual debit cards just like companies can with Brex/Mercury/Ramp etc.

Re: Credit cards are vulnerable to brute force kind attacks

#34
post #17

Earlier quoted context omitted.

how is it not also your money when using a credit card? It's in the name, "credit" card. you have to pay it off, no? (i have never ever used a credit card)

It comes with fraud protection and your money does not move anywhere until the end of the next month. With a debit card your money moves immediately.

[deleted]

Re: Credit cards are vulnerable to brute force kind attacks

#35
post #28
post #9

Earlier quoted context omitted.

That has not been my experience with debit cards in the US at major banks, at all , over decades. (I'm pathologically avoidant of credit cards, which I think are mostly pointless.)

Well good for you. Us poors in the US like them for what they’re worth.

Like what? That banks will make you instantly whole on card fraud to debit cards, and are legally required to do so? I like that too.

Re: Credit cards are vulnerable to brute force kind attacks

#36
Okay but... so what? Authentication is a means, not an end. They seem to be missing that what matters at the end of the day is how much money/time/resources actually get lost, and who's on the hook for it. If that's negligible then isn't that mission accomplished? If we could live in a society where your name was enough and you didn't need a card number at all, and yet theft was still low and you still got your money back, that would be even better, not worse.

Re: Credit cards are vulnerable to brute force kind attacks

#37
post #17

At least with a credit card you have some fraud protection. Report it and the charge should be reversed. And chargebacks are possible. With a debit card you’re playing with your own money.

how is it not also your money when using a credit card? It's in the name, "credit" card. you have to pay it off, no? (i have never ever used a credit card)

As I understand it, debit cards do have some fraud protection too, but even if it's the same (I don't think it is), it's a way different power dynamic if you're begging for a bank to give you money back (debit card) vs just disputing your credit card bill.

In practice credit cards just have way better fraud protections.

Re: Credit cards are vulnerable to brute force kind attacks

#38
post #8

Earlier quoted context omitted.

NSA prefers compromised security so that answers your question Credit card system was already around for decades before though

I heard a rumor that NSA suggested changes to DES encryption that strengthened it from differential cryptanalysis attacks that the public cryptologists weren't aware of yet.

That isn't a rumor? It's a pretty well documented fact that the NSA was involved in the design of DES and that the magic numbers that people initially assumed were a back door of some sort turned out to make differential cryptanalysis more difficult than randomly chosen ones would have.

Re: Credit cards are vulnerable to brute force kind attacks

#39
>As a consumer, I thought I was safe; when saving my credit card to a billion dollar valued european merchant, or when i purchase something from supermarket and ignore the receipt, but the reality is slightly different from that.

>I got the money back via chargeback in short time.

So as evidenced, you are protected by the fraud infrastructure. The bank ate the loss for the fraud and you were made whole. In the end, the banking system cares about fraud loss. And they are exceptionally good at finding the fraud. Making changes to the card payment system is extremely difficult, due to the vast scale of the systems, so without a very good justification that a particular change will move the needle on fraud rates, the banks will opt to not make the changes.

Post reply on HN