Live data from Hacker News

Credit cards are vulnerable to brute force kind attacks

metin.nextc.org

101–110 of 201 posts

Re: Credit cards are vulnerable to brute force kind attacks

#101
post #9

Earlier quoted context omitted.

That has not been my experience with debit cards in the US at major banks, at all , over decades. (I'm pathologically avoidant of credit cards, which I think are mostly pointless.)

You can reverse the charges on debit cards, but the money is withdrawn at the time the charge is made. This is not the case for credit cards.

> You can reverse the charges on debit cards, but the money is withdrawn at the time the charge is made. This is not the case for credit cards.

In a sense it is though, because it lowers your available credit by the amount of the charge. And the fraudsters are going to try to run you right up to your credit limit, so you end up at the same problem: You now have legitimate charges being declined because the fraudsters locked up your payment card.

Re: Credit cards are vulnerable to brute force kind attacks

#102
post #93
post #54

Earlier quoted context omitted.

I’m not sure about “digital wallets”, but the concept of updating credit card details after a new card is issued does exist, and it’s a service offered by credit card companies. Blog post from Stripe: https://stripe.com/resources/more/what-is-a-card-account-upd...

Yep. I've been able to use the "wrong" (but still valid) expiration date on my AmEx for a long time. I've had other credit cards where the autopay info was never updated and it just kept working for at least 6 months.

Account Updater functionality isn't necessarily even involved there. In the end whether to accept a transaction is up to the issuer, and quite often they'll keep accepting recurring transactions on otherwise outdated card information.

Re: Credit cards are vulnerable to brute force kind attacks

#103

Earlier quoted context omitted.

Banks don’t really eat the loss, instead they ensure all their services have enough of a markup to cover the cost of fraud. All consumers collectively pay for all the fraud, it’s just that we don’t tend to realize it as it’s not a specific line item on any of our bills, instead we all pay just a little more than we should for everything we buy.

yes, obviously all of the bank's money comes from consumers. what other scenario do you see where a bank(etc) "eats the loss" but the money somehow comes from somewhere else

If the rate of fraud reduced bonus payments to executives.

Re: Credit cards are vulnerable to brute force kind attacks

#104
post #47
post #43

Earlier quoted context omitted.

In addition to nominal fraud prevention (and how is any debit card better) there’s nothing better to claw back transaction fees, so what the fuck am I supposed to do?

I'm not saying debit cards are better at fraud prevention and response; I'm saying they're roughly equivalent. The downsides of credit cards are self-evident.

The downsides aren’t really self-evident to me. I’ve been using credit cards for everything I can for 35 years and I can’t think of any downsides. Even the cards I’ve had that had annual fees I chose to pay that fee because the benefits were worth more than the fee to me.

I can think of plenty of times where the upsides of having a credit card were realized though.

Re: Credit cards are vulnerable to brute force kind attacks

#105
post #81
post #57

Earlier quoted context omitted.

> I don’t get it, do US citizens prefer being defrauded over what is perceived as a slight inconvenience? Do you think we are requesting to have less secure payment methods or something? No, we don't "prefer to get defrauded", but things like this are a matter of negotiation between the card issuers and the merchants.

Legislate that the banks are liable for refunding this class of fraud and you'll find they suddenly take this stuff a lot more seriously and "discover" the technology.

I don't understand your point. The banks and credit card companies are already responsible. If I have a fraudulent charge I call and tell them it's fraudulent and they say okay and take it off and either getit back from the issuer or eat the difference.

Re: Credit cards are vulnerable to brute force kind attacks

#106
post #62

Earlier quoted context omitted.

When my bank account got drained, I could not pay rent or any bills. I had enough cash for about a week of food. It took 4 weeks for the bank to decide I could be made whole. Ever since then I have never even put a debit card in my wallet. I know what the laws say. I have read endless "well banks usually[...]" type messages. and yet all the same I one day awoke to find myself transformed into a giant cockroach.

EFTA Reg E gives banks 10 days to make you whole (less an optional $50 deductible depending on when the fraud was reported). My experience going back decades is that they've simply reverted the charges instantly. What bank were you using? My experience is with the usual suspects --- Citi, Chase, and BofA. Under the law, credit card issuers actually have more time to deliberate before making you whole, not less.

That's not quite accurate. They have 10 days to issue you a temporary credit if the investigation is going to take more than 10 days. They are willing to issue the credit immediately precisely because it's temporary. If the investigation resolves in your favor the credit becomes permanent and you never know the difference. If it takes more than 30 days - well, I worked with BofA about 15 years ago and saw more than a few customers who ended up with a giant mess because that temporary credit expired after 30 days resulting in a snowball effect of failed payments and NSF charges.

Re: Credit cards are vulnerable to brute force kind attacks

#107
I'll get the usual hate for this, but in this instance using bitcoin is safer, since it forces you to verify the transaction on your phone (i.e. you use your phone to pay - either scanning QR code or now NFC). In the US the Square payment terminals can now accept bitcoin from any lightning enabled wallet app, CashApp does it natively, etc.

Re: Credit cards are vulnerable to brute force kind attacks

#108
post #47

Earlier quoted context omitted.

I'm not saying debit cards are better at fraud prevention and response; I'm saying they're roughly equivalent. The downsides of credit cards are self-evident.

The downsides aren’t really self-evident to me. I’ve been using credit cards for everything I can for 35 years and I can’t think of any downsides. Even the cards I’ve had that had annual fees I chose to pay that fee because the benefits were worth more than the fee to me. I can think of plenty of times where the upsides of having a credit card were realized though.

You don't know anybody in 5-figure+ credit card debt? I know several. I don't know anybody in debit card debt.

Re: Credit cards are vulnerable to brute force kind attacks

#109

Earlier quoted context omitted.

> but things like this are a matter of negotiation between the card issuers and the merchants. Not necessarily, the EU has mandated strong customer authentication by law (PSD2), and as a result has practically universal 3DSecure support.

Ah, the natural call of the wild European: blaming individual Americans for a century of policy failures with truly majestic smugness.

Who should be blamed then? Do you not vote your lawmakers? Do you not vote with your wallet by buying from non-3d-secure merchants?

Re: Credit cards are vulnerable to brute force kind attacks

#110

If 3D secure was mandatory everywhere that would help a lot, but if I understand correctly, it’s not really used in the US and with them being so big, card issuers are largely forced to allow non 3D secure requests or their clients will be unable to use their cards for too many things. So an enormously good anti-fraud mechanism is severely handicapped. It’s really frustrating for most of the rest of the world. I don’…

FWIW, HSBC USA Mastercard uses 3D secure if it's something you want and you're in the states.
Post reply on HN