Live data from Hacker News

A simple solution to credit card fraud, and why you won't see it any time soon

blog.rongarret.info

111–120 of 130 posts

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#111
Ron, before you get into the chip-n-pin/smart-card stuff commonly used in Europe and Asia, you should probably check out the modern "Man-In-The-Browser" attacks:

http://www.irongeek.com/i.php?page=videos/derbycon2/3-1-1-da...

As the above shows, crypto is useful, but it's far from perfect due to its reliance on insecure stuff (i.e. web browsers, operating systems, ...). When the foundation is flawed, it's turtles all the way up.

Also, don't let HN or the web in general get you down. Writing for those with a short attention span makes for short stories, not long ones. Being wedged could be an indication that you have a lot to say, too much to get it going properly. I've got a hunch you have a nice long story to tell, and it will be worth reading even if it comes out in a round about fashion. I ain't a crypto or security person, nor do I play one on TV, but if you want a proof reader contact me privately.

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#112

I think it is incorrect to say fraud is not costing credit card companies money, because they can transfer the cost to customers. If there was less fraud they could easily keep the transaction costs on same level and pocket the difference. Some finnish banks introduced a "verified by Visa" scheme where you need to verify online transactions with one time password (those are normally used to log into online bank accou…

I have a German Visa card and for me it works by creating a seperate password for online purchases (once). This prevents a lot of fraud because the verified by Visa password resides on the servers of Visa (or the bank, I don't know) and is not compromised when a shop get's hacked. Also I don't have to enter it every time I use my credit card but rather I'd guess about 10% of the time.

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#113
I'm not convinced of the premise that credit card companies have no incentive to reduce fraud.

"Fraud isn't costing them money, it is costing you money. [they] pass the cost on to you, the consumer."

That's true of any business really. Increased costs get passed onto the consumer. But that doesn't stop other businesses from trying to reduce costs.

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#114
post #58

Earlier quoted context omitted.

You've just described ARQC EMV card payments.

After having a cursory glance through the ARQC EMV wiki entry, it seems that EMV corresponds to what we currently have in Europe -> the same (consumer) PIN is still going to be re-entered in every transaction i.e. it's re-useable and can be easily captured(camera/eyeball) for later use at POS/ATM

Correct, it also describes your first flow; the only thing different is that the authentication is done through the merchant's PIN pad rather than a code sent through the cell network. In other words, providing the PIN unlocks the card, which serves as your authorization to dispense funds.

IIRC the card signs the merchant's request for funds once the PIN has been validated by the chip on the card, then sends it to the bank. I don't think there's anything in the standard that would preclude having one time PIN codes(the PIN validation is done by the chip, so you could just have a different app that does more than check a single PIN code), but the chip in the card itself doesn't have network access.

If you really wanted to have online authorization through the cell network, you could hold the processing of the AQRC message until it is verified through SMS (which can take several minutes for delivery and is best effort). However, that would hold the card reader unusable until the authorization is granted, as the card needs to stay in the terminal until the transaction is complete.

This obviously disregards offline processing (ie. card terminals that are not always connected to the network) and CNP transactions. For those, verification through another channel would be much more realistic.

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#115
post #48

Overreacting, shallow, misleading and bait-link article. Overreacting: - the most up-to-date technologies for anti-credit card fraud, namely variants of smart card/EMV, are already available and widely used by all the large credit card providers and banks in the EU and Asia (excluding domestic transactions in China and Japan). There are even US providers who use it in some situations. - in addition, most merchants in…

> the credit card industry HAS and IS deploying the most up-to-date technology. In some regions, e.g. US, there are legal or infrastructure barriers that take time to overcome.

And why is that, you think? People are somewhat surprised that a magstripe is still even considered valid here and have been for years. I've seen zero chip readers in the US. It's been more than five years since I've heard of a merchant using magstrips in the EU.

The industry in the US isn't toothless. Nor is the government. They seemed perfectly capable of banning betting and sales of illegal goods or donations to causes they disapprove of. Yes, they are now starting to roll out stuff. I have no idea how they're going to do it seeing as they're apparently still living in the remote past. Can they roll out all this by 2017? Perhaps. Meanwhile, in the EU Square Up is distributing free chip readers for android or iphone, same as the US side does for magstripes. Which they can then transmit over the nice 100 Mbit fiber. Apparently, it wasn't that damn hard, except in the US.

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#116
post #108
post #81

Earlier quoted context omitted.

That's if the cardholder discovers the charge and if it hasn't already caused any problems (such as leading to bounced checks or inability to make an important payment). Your language is much to strong, especially since is wrong.

How can credit card fraud lead to bounced checks?

When the credit card is a check card (directly debits a checking account), and the fraudulent purchases leave insufficient funds to clear your outstanding checks.

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#117
post #68
post #57

Earlier quoted context omitted.

EMV only seems to secure offline transactions at merchants and ATMs. How does it protect information for online and phone payments?

As part of EMV, the liability is typically shifted to the merchant for non-EMV authenticated transactions. This provides strong motivation for merchants to do a better job of filtering out fishy transactions. The only solutions I've seen to using EMV itself for online/phone transactions involve having a more advanced card (i.e. with LCD token readout) or a standalone card reader to interact with the chip. E.g.: ftp:/…

Merchants already have to pay back the transaction, plus a charge, plus we're out the merchandise. We already have plenty of incentive to spot fraudulent transactions.

What is needed is a better system.

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#118
post #83
post #23

Earlier quoted context omitted.

I think the other thing is that most online credit fraud doesn't come intercepting credentials over wires but by dupe sites that imitate real realtors. I think two factor authentication might help with that, if it has to verify both sender and recipient on some mutual third party server of the credit card provider, but that costs them money, which gets back to the root problem, it doesn't cost the companies that woul…

I think there is zero chance Bitcoin takes off.

I recall this being said when Bitcoin was at around a dollar and ever since.

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#119
post #34

In a rational world where declaring that government should be responsible for the foundational services that enable civil society the universal payment transaction service would be operated by the government as a public utility. In this hypothetical rational world, you would go to the government office when you needed to open a new payment account to make or receive payments. You would show proof of identity, and rec…

> In a rational world where declaring that government should be responsible for the foundational services that enable civil society the universal payment transaction service would be operated by the government as a public utility. Already exists. It's called cash.

That's one of the points I was alluding to. the .gov already does this in the physical world; why have they allowed a layer of private interests to insert themselves into the process when it is performed electronically?

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#120
post #107

Earlier quoted context omitted.

Because we buy books with only one chapter, these days?

This isn't a book, and you aren't paying for it. Also, books are also assumed to be a finished product if they're being published, unlike a blog post that explicitly states it's the first of several. Not really an applicable analogy.

So is he planning on modifying the blog post to be of higher quality, or is it okay to be sloppy because he'll totally explain everything in the next chapter?
Post reply on HN