Live data from Hacker News

Credit cards are vulnerable to brute force kind attacks

metin.nextc.org

161–170 of 201 posts

Re: Credit cards are vulnerable to brute force kind attacks

#161
post #140
post #29

Earlier quoted context omitted.

For most of my adult life I haven't been able to get a credit card --- even after we sold Matasano Security, with the proceeds of that acquisition sitting in a money market checking account at the giant bank I use, that bank would still only issue me a secured card. I pay my bills and all, but at some point when I was like 19 I bought a shirt at Nordstroms and they signed me up for a card and I didn't pay enough atte…

> No part of my life has been harder for not having revolving credit. Maybe not harder, but one undeniable downside is that you've been paying roughly 2% more for roughly every purchase you've ever made (other than rent or mortgage payments and a few other exceptions) than you would have if you had good credit and used a credit card, due to how the US payments market is structured. To be clear, I'm not saying that th…

I am much, much less afraid of paying a little more on transactions, or of card theft resolution, than I am of racking up credit card debt. Everybody I know that got into a hole on credit card debt was smarter and better organized than I am. I see it as an inherently predatory product.

Re: Credit cards are vulnerable to brute force kind attacks

#162

Earlier quoted context omitted.

You don't know anybody in 5-figure+ credit card debt? I know several. I don't know anybody in debit card debt.

No, I don’t know of anybody who has a big credit card debt. I don’t think I’ve ever carried a credit card balance past my payment date. I did have a six-figure debt to a bank and if didn’t make my payments they would take the house from my family! Much higher stakes than any credit card debt I’ve ever had. I do have a debit card though and it’s actually not that different from a credit card. If I spend money not in m…

I think that's weird, because I can count off 6 or 7 just off the top of my head, people I know reasonably well, all of them well-educated, and smarter & better organized than I am. I don't really understand the argument we'd be having here: obviously, empirically, credit card debt is an enormous problem in the United States.

Re: Credit cards are vulnerable to brute force kind attacks

#163
post #123

Why credit card numbers are full persistent baffles me. They were never meant to be memorable, and the whole process is electronic: surely this can be replaced by cryptography at this point? I've deliberately demagnetized me and my wife's cards and we have black electrical tape over the numbers in public now. Online purchases are the last remaining problem which would be completely solved if payments were to random k…

PANs are indeed going away and every transaction could already be tokenized, today. But then the US were 20 years behind on EMV, and SCA is still not a thing.

Re: Credit cards are vulnerable to brute force kind attacks

#164

Earlier quoted context omitted.

No, I don’t know of anybody who has a big credit card debt. I don’t think I’ve ever carried a credit card balance past my payment date. I did have a six-figure debt to a bank and if didn’t make my payments they would take the house from my family! Much higher stakes than any credit card debt I’ve ever had. I do have a debit card though and it’s actually not that different from a credit card. If I spend money not in m…

I think that's weird, because I can count off 6 or 7 just off the top of my head, people I know reasonably well, all of them well-educated, and smarter & better organized than I am. I don't really understand the argument we'd be having here: obviously, empirically, credit card debt is an enormous problem in the United States.

I haven’t really talked about that kind of stuff with people I know. I could be surrounded by people who have big debt and just don’t know.

A quick googling says that about half of all credit card holders carry some kind of balance each month, so clearly there must be some people in my orbit not paying it off.

Re: Credit cards are vulnerable to brute force kind attacks

#165

Earlier quoted context omitted.

I am a bit confused about your situation. Did you have a stolen card used to make a purchase at ebay that was not under your account? Or did you make a purchase at ebay and have an issue with the product you received?

Scammer created two e-bay accounts. One with my name but e-mail address "pirate" something. A second one, a scammer merchant account to wash the money. They stole my credit card and used the bogus "me" ebay account to generate invoices (to my real address) and payments for goods from the second scammer merchant account. Then they found tracking numbers to my zip code. They bought the (fake) items from their scammer m…

You didn't provide any evidence that the charge was fraudulent. If they have a tracking number you gotta provide something, at least a police report.

Also you likely filed "merchandise/services not received" when you should have filed "unauthorized transaction". Even if you really did get the item, you don't have to pay for it if it was ordered by someone else using your card.

Re: Credit cards are vulnerable to brute force kind attacks

#166

Earlier quoted context omitted.

I think that's weird, because I can count off 6 or 7 just off the top of my head, people I know reasonably well, all of them well-educated, and smarter & better organized than I am. I don't really understand the argument we'd be having here: obviously, empirically, credit card debt is an enormous problem in the United States.

I haven’t really talked about that kind of stuff with people I know. I could be surrounded by people who have big debt and just don’t know. A quick googling says that about half of all credit card holders carry some kind of balance each month, so clearly there must be some people in my orbit not paying it off.

I'd be one of them, but I can't be, because I don't use credit cards.

Re: Credit cards are vulnerable to brute force kind attacks

#167
post #119

Earlier quoted context omitted.

Check out privacy.com, you can make your own cards. One per service if you want.

Been doing this for a while now for ebay and other stuff. I'm always shocked at how many people have no idea this exists.

Because people use credit cards for the rewards (cash, mileage, whatever) or because they don’t actually have the money now. They don’t want to pay for a unique number for every transaction (which doesn’t actually preserve privacy since most of the stuff you’re buying online needs a shipping address) nor do they want the money immediately pulled from their bank account.

Re: Credit cards are vulnerable to brute force kind attacks

#168
post #61

Earlier quoted context omitted.

I had no idea amex offers virtual cards... but I looked everywhere in the app and cannot find any such option?

https://www.americanexpress.com/en-gb/services/ways-to-pay/d...

>We have invited a small pilot group to the Digital Card feature now. The feature will become available to more Cardmembers soon.

Re: Credit cards are vulnerable to brute force kind attacks

#169
post #136
post #110

Earlier quoted context omitted.

FWIW, HSBC USA Mastercard uses 3D secure if it's something you want and you're in the states.

Capital One also offers it for their credit cards, which makes them the only ones usable in countries where requiring 3DS is common. (No idea why this is a thing actually – merchants get the fraud chargeback liability shift as soon as they request 3DS, whether the issuer actually supports it or not.) The real problem is that in the US, almost no merchants request it in my experience, despite the fact that they'd get…

> No idea why this is a thing actually

a) It still affects their bottom-line: the issuer might still try to dispute this using a different code despite payment scheme (formal term for Visa et al.) rules, and the merchant targeted is prone for fraud (for example, airlines have been hit with this by exploiting tourists looking for cheaper tickets by offering them suspiciously cheap tickets on seemingly-trustworthy websites by fraudsters and funding them by insecure cards)

b) Misinterpretation of mandatory rules: PDS2 is applicable only for EEA customer - EEA merchant, but some extended it for whole world despite the rules literally dictating the limits

c) Soft friction for encouraging domestic card usage: because of accept-all rules by payment schemes (and no local rules that allowed merchants in a region to reject international payments), this is a way to block US cards by guise of fraud prevention (because international cards are expensive for merchants to process)

Re: Credit cards are vulnerable to brute force kind attacks

#170
post #109

Earlier quoted context omitted.

Ah, the natural call of the wild European: blaming individual Americans for a century of policy failures with truly majestic smugness.

Who should be blamed then? Do you not vote your lawmakers? Do you not vote with your wallet by buying from non-3d-secure merchants?

Yes, I vote for leaders. So does everyone else, unfortunately.
Post reply on HN