Live data from Hacker News

Credit cards are vulnerable to brute force kind attacks

metin.nextc.org

111–120 of 201 posts

Re: Credit cards are vulnerable to brute force kind attacks

#111
post #81

Earlier quoted context omitted.

Legislate that the banks are liable for refunding this class of fraud and you'll find they suddenly take this stuff a lot more seriously and "discover" the technology.

I don't understand your point. The banks and credit card companies are already responsible. If I have a fraudulent charge I call and tell them it's fraudulent and they say okay and take it off and either getit back from the issuer or eat the difference.

They can also punish you for doing so, like banning you from the bank.

They also report account closures to ChexSystems, which can make it harder to open accounts at other banks for years. Credit card issuers can drop you and ding your credit. Definitively not your fault, but still your problem, and the consequences are for you.

Re: Credit cards are vulnerable to brute force kind attacks

#112

Earlier quoted context omitted.

No, the laws are different- and more consumer friendly in the US- so the US consumer behavior is different. Back when credit cards were first starting out (which happened in the US) the US Congress passed a law- the Fair Credit Billing Act of 1974- that consumers were only liable for $50 of losses as long as they reported the missing credit card within 60 days of the end of the fraudulent billing cycle . This was bac…

Why would the law being different mean they wouldn't use 3DS though? Surely it'd cut out a good amount of fraud along with the realtime monitoring? I understand that US consumers don't have a stake in this, but can't all the banks just agree to enforce 3DS? I can't imagine Americans are going to stop using their cards because of a small amount of friction added

> can't all the banks just agree to enforce 3DS

They could, but it's one of those things that really only work if everybody joins. Because 3DS is rarely used right now, a portion of merchants don't even support it, so if you start enforcing is as a single bank, your customers will start complaining their card doesn't work. The banking industry in the US is also more decentralized than in the EU, so getting everybody to join in simultaneously is hard.

The window of opportunity for 3DS has also more or less passed, the industry is moving on to the next generation of tech (wallets/tokenization), that should be both easier to use and more secure.

Re: Credit cards are vulnerable to brute force kind attacks

#114
This blog doesn't mention the most critical part

Settlement the part where the bank agrees to transfer money from your account (in this case increasing your debt on the card) to the merchant is completely separate from Authorization.

Authorization is the modern EMV ("Chip and pin") authentication, the CVV stuff for online, and any other mechanism by which the bank protects themselves from your fraud and, maybe, as an afterthought protects merchants.

The network is completely OK with Amazon saying here's a card number, we say they're paying us $400. That's just a settlement, goes on your bill. No sophisticated cryptography, nothing even as clever as a 4 digit PIN, or remembering your mother's maiden name, just OK, we trust you. Which means you, as a consumer, need to read your credit card bills and dispute anything you don't recognise or you'll pay.

There is very little incentive for the networks to care if you get ripped off. If you don't dispute it then everybody is happy, and if you do they just claw it back from the merchant and it's not their problem.

Re: Credit cards are vulnerable to brute force kind attacks

#115

Earlier quoted context omitted.

No, the laws are different- and more consumer friendly in the US- so the US consumer behavior is different. Back when credit cards were first starting out (which happened in the US) the US Congress passed a law- the Fair Credit Billing Act of 1974- that consumers were only liable for $50 of losses as long as they reported the missing credit card within 60 days of the end of the fraudulent billing cycle . This was bac…

Why would the law being different mean they wouldn't use 3DS though? Surely it'd cut out a good amount of fraud along with the realtime monitoring? I understand that US consumers don't have a stake in this, but can't all the banks just agree to enforce 3DS? I can't imagine Americans are going to stop using their cards because of a small amount of friction added

Because adding friction will deter many impulse purchases. Americans use credit cards constantly. The equilibrium would be perturbed in a way very much not advantageous for the credit card issuers if consumers became more cautious about using credit cards.

It’s the same reason credit card issuers are willing to pay Apple a few basis points to participate in Apple Pay: reducing friction has a non-linear impact on propensity to pay.

Re: Credit cards are vulnerable to brute force kind attacks

#116
post #29
post #10

Earlier quoted context omitted.

Why do you think they’re pointless?

For most of my adult life I haven't been able to get a credit card --- even after we sold Matasano Security, with the proceeds of that acquisition sitting in a money market checking account at the giant bank I use, that bank would still only issue me a secured card. I pay my bills and all, but at some point when I was like 19 I bought a shirt at Nordstroms and they signed me up for a card and I didn't pay enough atte…

I've never needed credit but chose to get credit cards to establish a credit history for the future, and use their cash back programs. I get 3-5% back on all my purchases, so they've paid well over the years, and I have a good credit score.

Re: Credit cards are vulnerable to brute force kind attacks

#117
post #71

Earlier quoted context omitted.

How much is lost to fraud that would be prevented by 3d secure, 0.1%?

In Europe, the max interchange fee is 0.3%. In the US, the average is 2%. So the relative impact of fraud is much higher.

Huh? Your conclusion does not follow. A large fraction of the interchange fee is kicked back to customers.

The size of the pie being so much bigger means the issuer’s tolerance for fraud is much larger, but it’s orthogonal to whether there’s actually more fraud. In practice credit cards fraud actually impacting customers is vanishingly rare at this point.

Re: Credit cards are vulnerable to brute force kind attacks

#119

Related story and wondering if the OP may have been chasing red herrings. I recently noticed an unauthorized charge for a small amount on my credit card (something about FB/Meta). Likely someone probing the card to see if anyone would notice. I called the CC company, had them removed the charge, canceled the card and had them send me a new card (5-7 business days). With the brand new unused card (new CC number, new e…

Check out privacy.com, you can make your own cards. One per service if you want.

Re: Credit cards are vulnerable to brute force kind attacks

#120
post #54

Related story and wondering if the OP may have been chasing red herrings. I recently noticed an unauthorized charge for a small amount on my credit card (something about FB/Meta). Likely someone probing the card to see if anyone would notice. I called the CC company, had them removed the charge, canceled the card and had them send me a new card (5-7 business days). With the brand new unused card (new CC number, new e…

I’m not sure about “digital wallets”, but the concept of updating credit card details after a new card is issued does exist, and it’s a service offered by credit card companies. Blog post from Stripe: https://stripe.com/resources/more/what-is-a-card-account-upd...

I also noticed that my Google Wallet cards no longer have expiration dates- when a card expires and they issue a new one, the Wallet card works without any intervention on my part
Post reply on HN