Live data from Hacker News

Credit cards are vulnerable to brute force kind attacks

metin.nextc.org

131–140 of 201 posts

Re: Credit cards are vulnerable to brute force kind attacks

#131

>As a consumer, I thought I was safe; when saving my credit card to a billion dollar valued european merchant, or when i purchase something from supermarket and ignore the receipt, but the reality is slightly different from that. >I got the money back via chargeback in short time. So as evidenced, you are protected by the fraud infrastructure. The bank ate the loss for the fraud and you were made whole. In the end, t…

> The bank ate the loss for the fraud

Quite often, the merchant is unfortunately the one eating the fraud, which is creating a bit of a principal-agent problem (in that the issuing bank earns interchange on every transaction, so if they aren't liable for fraud, their default incentive would be to just approve as much as feasible and figure everything out later via chargebacks).

3DS changes that calculus quite a bit, though, and in-person payments are usually the issuing bank's liability as well.

Re: Credit cards are vulnerable to brute force kind attacks

#132

If 3D secure was mandatory everywhere that would help a lot, but if I understand correctly, it’s not really used in the US and with them being so big, card issuers are largely forced to allow non 3D secure requests or their clients will be unable to use their cards for too many things. So an enormously good anti-fraud mechanism is severely handicapped. It’s really frustrating for most of the rest of the world. I don’…

> I don’t get it, do US citizens prefer being defrauded over what is perceived as a slight inconvenience?

The general idea is that if the conversion rate drop of a given security mechanism is higher than the average fraud rate, it doesn't make financial sense to deploy it.

However, at the industry-wide level, this is a pretty classical coordination problem, in that conversion rate only drops because there still is a simpler alternative around unless all merchants and banks were to enforce 3DS at the same time. If there's nothing more convenient left to move to, users will for better or worse have to learn the new, more secure thing, and conversion rates will go up again.

This is what the EU has done with mandating 3DS for many payments, but even there regulators have recognized that a 100% coverage is counterproductive, and there's a sweet spot somewhere in the middle.

As more evidence for the same general idea: US credit cards don't have PINs, because any individual bank introducing them would see a huge drop in usage rates since customers would just use their competitor's card without a PIN instead. In other markets, all cards have PINs (whether due to regulatory invention or card network incentive), and people have just gotten used to them.

Re: Credit cards are vulnerable to brute force kind attacks

#133
post #119

Related story and wondering if the OP may have been chasing red herrings. I recently noticed an unauthorized charge for a small amount on my credit card (something about FB/Meta). Likely someone probing the card to see if anyone would notice. I called the CC company, had them removed the charge, canceled the card and had them send me a new card (5-7 business days). With the brand new unused card (new CC number, new e…

Check out privacy.com, you can make your own cards. One per service if you want.

Been doing this for a while now for ebay and other stuff. I'm always shocked at how many people have no idea this exists.

Re: Credit cards are vulnerable to brute force kind attacks

#134

If 3D secure was mandatory everywhere that would help a lot, but if I understand correctly, it’s not really used in the US and with them being so big, card issuers are largely forced to allow non 3D secure requests or their clients will be unable to use their cards for too many things. So an enormously good anti-fraud mechanism is severely handicapped. It’s really frustrating for most of the rest of the world. I don’…

No, the laws are different- and more consumer friendly in the US- so the US consumer behavior is different. Back when credit cards were first starting out (which happened in the US) the US Congress passed a law- the Fair Credit Billing Act of 1974- that consumers were only liable for $50 of losses as long as they reported the missing credit card within 60 days of the end of the fraudulent billing cycle . This was bac…

This theory explains why cardholders in the US are still using cards despite these being relatively less secure than in other countries, but fails to explain why issuing banks wouldn't take steps to protect their own fraud losses, such as introducing 3DS or PINs.

The actual explanation lies in the game theory of fraud prevention; see my sibling comment for details.

Re: Credit cards are vulnerable to brute force kind attacks

#135

Related story and wondering if the OP may have been chasing red herrings. I recently noticed an unauthorized charge for a small amount on my credit card (something about FB/Meta). Likely someone probing the card to see if anyone would notice. I called the CC company, had them removed the charge, canceled the card and had them send me a new card (5-7 business days). With the brand new unused card (new CC number, new e…

Same here, had a 200 EUR charge from Meta / FB - still waiting for my new card.

Re: Credit cards are vulnerable to brute force kind attacks

#136
post #110

If 3D secure was mandatory everywhere that would help a lot, but if I understand correctly, it’s not really used in the US and with them being so big, card issuers are largely forced to allow non 3D secure requests or their clients will be unable to use their cards for too many things. So an enormously good anti-fraud mechanism is severely handicapped. It’s really frustrating for most of the rest of the world. I don’…

FWIW, HSBC USA Mastercard uses 3D secure if it's something you want and you're in the states.

Capital One also offers it for their credit cards, which makes them the only ones usable in countries where requiring 3DS is common. (No idea why this is a thing actually – merchants get the fraud chargeback liability shift as soon as they request 3DS, whether the issuer actually supports it or not.)

The real problem is that in the US, almost no merchants request it in my experience, despite the fact that they'd get an almost free (in terms of conversion rate dropoff) liability shift. I suppose the few US issuers that do support it have a bad enough implementation that the conversion drop is still significant.

Re: Credit cards are vulnerable to brute force kind attacks

#137
post #2

People should have a separate card for online payments and have just enough money on it for a payment. I know that I am naïve :) Back to the article: Weak point was a password that lead to another merchant not using 3D secure. It seems from the article that bad actors have fully automated system, so (big) merchants should have handle automatic login attempts from the same ip address with different accounts. I see it…

Why should they, if they're not liable for any resulting fraud of the status quo?

Re: Credit cards are vulnerable to brute force kind attacks

#138

Earlier quoted context omitted.

You can reverse the charges on debit cards, but the money is withdrawn at the time the charge is made. This is not the case for credit cards.

> You can reverse the charges on debit cards, but the money is withdrawn at the time the charge is made. This is not the case for credit cards. In a sense it is though, because it lowers your available credit by the amount of the charge. And the fraudsters are going to try to run you right up to your credit limit, so you end up at the same problem: You now have legitimate charges being declined because the fraudsters…

Having multiple credit cards in the US is quite common, since there's no practical downside (unlike having multiple checking accounts, which locks up liquidity at usually no interest payment) and it can even be beneficial for your credit score.

Re: Credit cards are vulnerable to brute force kind attacks

#139
post #19

Earlier quoted context omitted.

You can reverse the charges on debit cards, but the money is withdrawn at the time the charge is made. This is not the case for credit cards.

Most US banks will credit your account for the amount of the dispute immediately upon starting the investigation, so it is functionally equivalent from a consumer perspective.

In fact, all US banks should be doing this, or they'd be in violation of Regulation E.

Re: Credit cards are vulnerable to brute force kind attacks

#140
post #29
post #10

Earlier quoted context omitted.

Why do you think they’re pointless?

For most of my adult life I haven't been able to get a credit card --- even after we sold Matasano Security, with the proceeds of that acquisition sitting in a money market checking account at the giant bank I use, that bank would still only issue me a secured card. I pay my bills and all, but at some point when I was like 19 I bought a shirt at Nordstroms and they signed me up for a card and I didn't pay enough atte…

> No part of my life has been harder for not having revolving credit.

Maybe not harder, but one undeniable downside is that you've been paying roughly 2% more for roughly every purchase you've ever made (other than rent or mortgage payments and a few other exceptions) than you would have if you had good credit and used a credit card, due to how the US payments market is structured.

To be clear, I'm not saying that this is a reasonable state of affairs, but it's the reality.

Another issue that comes to mind are rental cars – while there's no real difference in risk protection to merchants (it's not like a credit card on file can magically make a wrecked or never-returned car reappear), many rental car agencies require them; I suspect because they use them as something of a proxy indicator of "generally responsible-enough behavior to have been issued one by an institution also exposed to risk".

Post reply on HN