Takeaways from the $566M BriansClub Breach
11–20 of 29 posts
Re: Takeaways from the $566M BriansClub Breach
#12Re: Takeaways from the $566M BriansClub Breach
#13I find this kind of black hat cybercrime stuff fascinating. If I wanted to learn more about it (just for learning sake) what would be some good resources?
A good podcast I would recommend is called dark net diaries. They have lots of episodes on cryber crime. Episode 32 specifically talks about carding and how the secret service took down a guy who acquires the credit card numbers. Most of it involves putting malware on point of sale machines or hacking companies.
Re: Takeaways from the $566M BriansClub Breach
#14Are these idiots really still using bitcoin for doing shady stuff lol? Bitcoin can totally be traced. Most people using it are so weak in terms of their security.
Re: Takeaways from the $566M BriansClub Breach
#15I find this kind of black hat cybercrime stuff fascinating. If I wanted to learn more about it (just for learning sake) what would be some good resources?
Re: Takeaways from the $566M BriansClub Breach
#16Open question; What's the long game on securing the way credit cards work? Who's working on something interesting that could thwart the whole 'name+number+ccv' leak thing that's been perpetuating in this industry for decades? I'm just reaching out for anyone who knows about any grand plans, initiatives or rehabs of how credit cards currently work. Keen to read more.
This is a solved problem, really, some banks are less keen on implementing it: generate single use / single purpose credit card numbers in your ebank / mobile app. Leaks are total useless. Also, more than a decade ago already many European banks were sending a text SMS above a treshold and only approved on a positive reply. Today you'd likely offer sending a push notification. You have 16 digits on a Visa/MasterCard,…
Active confirmation of purchases would be great if it were available, but I. Not aware of any US card issuers that allow you to opt-in to such a service.
Re: Takeaways from the $566M BriansClub Breach
#17Are these idiots really still using bitcoin for doing shady stuff lol? Bitcoin can totally be traced. Most people using it are so weak in terms of their security.
If you don’t know something as basic as how to make bitcoin untraceable, then you’re the idiot.
Re: Takeaways from the $566M BriansClub Breach
#18Krebs should publish those card numbers to light a fire under the feet of the bankers to re-issue the cards and get them to demand better security on merchant terminals or servers or wherever the info came from. Of course he should publish only the numbers, without the associated names, CVVs, expiry dates, PINs, or other security info.
I don't think there is a risk in publishing just numbers, is there? The search space for valid card numbers is so tiny that I find it hard to believe that anyone could generate a false transaction with just the number and no other associated info.
Krebs could go a step further and provide a verification site à la haveibeenpwned.com where your enter your card number, or the last ten digits or something, and it tells you whether you've been pwned.
Re: Takeaways from the $566M BriansClub Breach
#19Open question; What's the long game on securing the way credit cards work? Who's working on something interesting that could thwart the whole 'name+number+ccv' leak thing that's been perpetuating in this industry for decades? I'm just reaching out for anyone who knows about any grand plans, initiatives or rehabs of how credit cards currently work. Keen to read more.
This is a solved problem, really, some banks are less keen on implementing it: generate single use / single purpose credit card numbers in your ebank / mobile app. Leaks are total useless. Also, more than a decade ago already many European banks were sending a text SMS above a treshold and only approved on a positive reply. Today you'd likely offer sending a push notification. You have 16 digits on a Visa/MasterCard,…
Funnily enough PayPal and Stripe were lobbying against this "harming of consumer experience."
Re: Takeaways from the $566M BriansClub Breach
#20Why don't credit/debit cards use elliptic curve cryptography?