Live data from Hacker News

Credit cards are vulnerable to brute force kind attacks

metin.nextc.org

41–50 of 201 posts

Re: Credit cards are vulnerable to brute force kind attacks

#41
post #17

At least with a credit card you have some fraud protection. Report it and the charge should be reversed. And chargebacks are possible. With a debit card you’re playing with your own money.

how is it not also your money when using a credit card? It's in the name, "credit" card. you have to pay it off, no? (i have never ever used a credit card)

You are making a purchase ON credit, and unless you are wildly negligent the merchant who accepts payment for the fraudulent purchase eats the costs. You may have to pay the balance owed while the chargeback works through the system but you will not ultimately pay for it.

Plus - like it or not - our society builds your credit based on your use of a credit card. And if you pay your balance in full every month I'm not sure why anyone would prefer paying up front (debit) vs. free financing.

Re: Credit cards are vulnerable to brute force kind attacks

#42

Credit cards as a while use a security model from...what, the 1970s? Sure, they've patched by adding the 3-digit CVC, but really? A huge industry can't do better than that? Honestly, it's pathetic...

https://en.wikipedia.org/wiki/3-D_Secure

Re: Credit cards are vulnerable to brute force kind attacks

#43
post #35
post #28

Earlier quoted context omitted.

Well good for you. Us poors in the US like them for what they’re worth.

Like what? That banks will make you instantly whole on card fraud to debit cards, and are legally required to do so? I like that too.

In addition to nominal fraud prevention (and how is any debit card better) there’s nothing better to claw back transaction fees, so what the fuck am I supposed to do?

Re: Credit cards are vulnerable to brute force kind attacks

#44
Virtual credit cards have been a thing for years. I remember bank of america or Citi providing them to me 15+ years ago. If I recall it was a java app or maybe even a standalone exe. Shocked they never took off more broadly.

Robinhood absolutely nails this. Best virtual credit card system I have ever used. So seamless. Can auth a card for one time use, 24 hours, or indefinite until you cancel. Such a great UI / UX

Re: Credit cards are vulnerable to brute force kind attacks

#46

>As a consumer, I thought I was safe; when saving my credit card to a billion dollar valued european merchant, or when i purchase something from supermarket and ignore the receipt, but the reality is slightly different from that. >I got the money back via chargeback in short time. So as evidenced, you are protected by the fraud infrastructure. The bank ate the loss for the fraud and you were made whole. In the end, t…

It's my experience that the bank will give up against a motivated chargeback counterparty.

My experience with ebay (stolen credit card) in particular was that things were going well until e-bay sent their stack of paperwork to my bank. Then my chargeback was reversed and shortly after that even my bank account was closed.

So you're not in the clear once you get your chargeback back. That is done initially while they give the other party time to respond. I think it took 30 days or so for ebay to bury me in paperwork, get the chargeback unwound again, and their schpeel was so effective that my bank themselves then accused me of being the fraudster.

As for

> The bank ate the loss for the fraud

I'm not 100% that's true. The entire reason why the chargebackee wants to contest it is because either the chargebackee or the chargebacker is eating the loss. The bank isn't eating that loss. There is no way E-bay would have bothered contesting my chargeback and paying their white collar workers for professional time researching if the bank was just going to eat it.

Re: Credit cards are vulnerable to brute force kind attacks

#47
post #43
post #35

Earlier quoted context omitted.

Like what? That banks will make you instantly whole on card fraud to debit cards, and are legally required to do so? I like that too.

In addition to nominal fraud prevention (and how is any debit card better) there’s nothing better to claw back transaction fees, so what the fuck am I supposed to do?

I'm not saying debit cards are better at fraud prevention and response; I'm saying they're roughly equivalent. The downsides of credit cards are self-evident.

Re: Credit cards are vulnerable to brute force kind attacks

#48

Payment processors don't allow just brute forcing all card numbers a.k.a. card enumeration or card testing [1][2] and card schemes penalise merchants and payment processors heavily if they don't take measures against it [3]. 1) https://stripe.com/newsroom/news/card-testing-surge 2) https://stripe.com/blog/the-ml-flywheel-how-we-continually-i... 3) https://docs.stripe.com/disputes/monitoring-programs#enumera...

The rate they try becomes very non frequent when they use multiple card validation apis. I'm not sure how it can be related when it's different pan numbers, different source ips etc.

Enumerating CVC2 with a single PAN is a different story.

Re: Credit cards are vulnerable to brute force kind attacks

#49
post #2

People should have a separate card for online payments and have just enough money on it for a payment. I know that I am naïve :) Back to the article: Weak point was a password that lead to another merchant not using 3D secure. It seems from the article that bad actors have fully automated system, so (big) merchants should have handle automatic login attempts from the same ip address with different accounts. I see it…

My previous bank provided this virtual card service on demand. You create the card for a single purchase with a specific amount and that’s it. I moved to an other bank when getting an affordable mortgage loan became impossible in it for me.

Re: Credit cards are vulnerable to brute force kind attacks

#50
If 3D secure was mandatory everywhere that would help a lot, but if I understand correctly, it’s not really used in the US and with them being so big, card issuers are largely forced to allow non 3D secure requests or their clients will be unable to use their cards for too many things.

So an enormously good anti-fraud mechanism is severely handicapped.

It’s really frustrating for most of the rest of the world.

I don’t get it, do US citizens prefer being defrauded over what is perceived as a slight inconvenience?

Even for non-victims of fraud, they still pay for the fraud as all merchants up the prices of their goods to cover fraud costs/insurance.

Post reply on HN