Live data from Hacker News

Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

krebsonsecurity.com

101–102 of 102 posts

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#101
post #99
post #98

Earlier quoted context omitted.

« There would be more dishonest merchants if the possibility of chargebacks ceased to exist » Yes there will probably be a minor uptick in merchants being dishonest. But I doubt it will be as bad as you make it to be. Many other factors push merchants to stay honest: legal repercussions, damaged reputation, etc. « And to say that virtually no merchant acceptance[1] is an “irrelevant argument” is laughable » Irrelevan…

> Yes there will probably be a minor uptick in merchants being dishonest. But I doubt it will be as bad... Simply wishful thinking. If that were the case consumer protections never would have been a very interesting feature. But they are. Especially for ecommerce. > Your argument is like saying in the early days of Blu-ray that "no one will buy Blu-ray discs... No and I clearly stated otherwise. Apple Pay is more lik…

«Simply wishful thinking»

People will pay in BTC only merchants that they already trust. Think high-reputation businesses like Amazon, Costco. Do you really think companies like that would start being dishonest if they accepted bitcoins?

«compared to one that requires brand new hardware»

No, accepting Bitcoin doesn't require new hardware. It's a software update to a website or to a point-of-sale.

«You also ignored -- probably because it is in your interest to ignore it -- that the reason merchants have no incentive to adopt is that nobody uses it»

You can continue writing they have "no incentive" but it doesn't make it true. This is the 3rd time you ignore it, and the 3rd time I point it out: their #1 incentive to accept BTC is to avoid chargeback fraud. Will I have to repeat it a 4th time?

As to "nobody uses it", I am not ignoring you, it is simply that you are wrong. Usage is growing: we got from 0 to 160,000 merchants in a few years, the transaction rate is doubling every 18 months (not due to speculation: https://news.ycombinator.com/item?id=15281860)

«Bitcoin as it stands is a major regression in consumer benefits»

It is a (small) regression, yes, no denying that, but it is far outweighed by the advantages: permissionless, near-instant international payments, no inflation, censorship-resistant, gives access to the underbanked/unbanked, etc.

As to Apple P2P, it is pointless to continue discussing it before it is rolled out and before we have a clear idea of its advantages and inconvenients. But I maintain my position that, if not delays, there will be transactions limits, and it also won't ever be used widely (for starters, only 2-3% of the world population has an iPhone.)

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#102
post #85
post #84

Earlier quoted context omitted.

I can’t tell if you are playing, but by storing the most unique part of the credit card with last name you are not reducing the desirability of the target much.

You don't store the name. You use the name to generate the salt and hash the results. You only store the hashes.

You are still doing a near lossless transformation of the unique part of the credit card and name as one of your goals is zero (minimized) hash collisions. The character set and length of the input plus reasonable assumptions about the salt and hash make it very likely "reversible" using rainbow tables or other brute force techniques.

Choose metadata that doesn't have such high financial value. Additionally, it's been years since I've been involved in e-commerce and the details are now foggy, but if I recall storing those addition credit card digits, even transformed, will prevent you from achieving the industrial certifications.

Post reply on HN