Live data from Hacker News

Credit cards are vulnerable to brute force kind attacks

metin.nextc.org

151–160 of 201 posts

Re: Credit cards are vulnerable to brute force kind attacks

#151
post #93
post #54

Earlier quoted context omitted.

I’m not sure about “digital wallets”, but the concept of updating credit card details after a new card is issued does exist, and it’s a service offered by credit card companies. Blog post from Stripe: https://stripe.com/resources/more/what-is-a-card-account-upd...

Yep. I've been able to use the "wrong" (but still valid) expiration date on my AmEx for a long time. I've had other credit cards where the autopay info was never updated and it just kept working for at least 6 months.

Funny, the Amex on my Pixel Watch stopped working only a couple weeks after the physical card expiry.

It was quite confusing, because a) I received a replacement physical card several months before the card expiry, so by the time my watch stopped working I'd entirely forgotten about it, b) there's no indication anywhere in the Android/Wear OS of what the expiry date is or that it might be expired and c) there's no indication at the point of sale that the virtual card is expired, simply a generic "Declined" message.

Re: Credit cards are vulnerable to brute force kind attacks

#152
post #120
post #54

Earlier quoted context omitted.

I’m not sure about “digital wallets”, but the concept of updating credit card details after a new card is issued does exist, and it’s a service offered by credit card companies. Blog post from Stripe: https://stripe.com/resources/more/what-is-a-card-account-upd...

I also noticed that my Google Wallet cards no longer have expiration dates- when a card expires and they issue a new one, the Wallet card works without any intervention on my part

That's very much contrary to my experience just a couple months ago that I detailed in another post: https://news.ycombinator.com/item?id=47981956

Re: Credit cards are vulnerable to brute force kind attacks

#153

Related story and wondering if the OP may have been chasing red herrings. I recently noticed an unauthorized charge for a small amount on my credit card (something about FB/Meta). Likely someone probing the card to see if anyone would notice. I called the CC company, had them removed the charge, canceled the card and had them send me a new card (5-7 business days). With the brand new unused card (new CC number, new e…

> I again called the credit card company and this time, told them to cancel all the digital wallets (there were 99 of them!). There is no way to do this online. This is highly dependent on your bank. For example, Bank of America lets you view and delete any cards that have been added to a digital wallet right on their website.

Half of my cards can't even be added to non-iPhone devices without a verification phone call to some poor support agent who's never heard of a "Pixel Watch", has no idea what the workflow is on his end to manually verify cards being added, and just wants me to "use the iPhone app to verify".

Heaven forbid if I try to add a card to an Apple Wallet on a Mac where no iOS or Android app exists.

Re: Credit cards are vulnerable to brute force kind attacks

#154

Earlier quoted context omitted.

> The bank ate the loss for the fraud and you were made whole _If_ you notice the fraudulent charge.

It never ceases to amaze me how many people don't even look at their bank/credit card statements and just let their credit cards auto-pay. Back when I was poor, I was logging into my bank and credit card accounts at least twice/week. I always knew within $20 how much money I had. As a well-paid tech worker, I'm still checking at each paycheck (2x/month) and paying the credit card card off every time, but I'm still sc…

FWIW, I find looking at my statement and trying to remember if I actually made a random purchase of $8.63 to some unrecognizable name three weeks ago to be a much more difficult workflow than just enabling email notifications for every transaction so I can triage them quickly / at my convenience.

Re: Credit cards are vulnerable to brute force kind attacks

#155

Related story and wondering if the OP may have been chasing red herrings. I recently noticed an unauthorized charge for a small amount on my credit card (something about FB/Meta). Likely someone probing the card to see if anyone would notice. I called the CC company, had them removed the charge, canceled the card and had them send me a new card (5-7 business days). With the brand new unused card (new CC number, new e…

if it was a 0 or 1 dollar auth, its likely a fraud check done by said company to make sure you still exist.

one or more of those digital wallets are some subscription supporting thing, and if that auth failed or had an address mismatch or wrong kind of card, they will disable your account until you update your card.

Re: Credit cards are vulnerable to brute force kind attacks

#157
Unlike US, in some regions such as JP,TW,HK, almost every online card transaction requires 3D Secure. But many real-world cases show that banks then refuse to take responsibility for fraudulent transactions once 3DS was completed, even when the OTP leak was caused by failures in the banking and telecom systems rather than by the cardholder.

Re: Credit cards are vulnerable to brute force kind attacks

#158

Earlier quoted context omitted.

The downsides aren’t really self-evident to me. I’ve been using credit cards for everything I can for 35 years and I can’t think of any downsides. Even the cards I’ve had that had annual fees I chose to pay that fee because the benefits were worth more than the fee to me. I can think of plenty of times where the upsides of having a credit card were realized though.

You don't know anybody in 5-figure+ credit card debt? I know several. I don't know anybody in debit card debt.

No, I don’t know of anybody who has a big credit card debt. I don’t think I’ve ever carried a credit card balance past my payment date.

I did have a six-figure debt to a bank and if didn’t make my payments they would take the house from my family! Much higher stakes than any credit card debt I’ve ever had.

I do have a debit card though and it’s actually not that different from a credit card. If I spend money not in my account I would get charged a $25 overdraft fee plus interest.

Re: Credit cards are vulnerable to brute force kind attacks

#159

Unlike US, in some regions such as JP,TW,HK, almost every online card transaction requires 3D Secure. But many real-world cases show that banks then refuse to take responsibility for fraudulent transactions once 3DS was completed, even when the OTP leak was caused by failures in the banking and telecom systems rather than by the cardholder.

The EU has banned plain SMS tokens for SCA. You need an OTP + PIN or password, or more likely authorize the transaction from a mobile app with biometrics.
Post reply on HN