Live data from Hacker News

The underground world of credit card network exploitation

chargebackstop.com

181–190 of 280 posts

Re: The underground world of credit card network exploitation

#181
post #79

Earlier quoted context omitted.

The number of banks in the US seems perfectly normal. Germany has ~1500 for 80 million inhabitants, the US has ~4800 for 300 million.

The US is 50 related but different regulatory regimes, not 1.

Germany also has states, although they aren't as independent as US states. In an case the EU is much less unified than the US.

Re: The underground world of credit card network exploitation

#182
post #2

Isn't this solved with 3-D Secure ? Many websites (at least in the EU) implement it and if mandatory, it's impossible to buy something without 2FA (either by SMS, phone app, ...)

Enabling 3-D secure on all transactions leads to lower conversion rates, therefore typically a hybrid model is used where its enabled/disabled per transaction whether it is needed based on a risk score.

Re: The underground world of credit card network exploitation

#183
post #7

Earlier quoted context omitted.

Not sure I understand. Does everyone outside the US have a card reader attached to their PC and phone?

I have never ever seen an online payment processor that was capable of using a card reader to perform a transaction from a webpage (on a non-specialized device). I don't think there is even any established standard for using a smartcard from a website. WebUSB/WebNFC may work (although browsers have blacklists of vendor IDs to disallow access to e.g. Yubikeys, so at least some smartcards may not be accessible this way…

A card reader is a stand-alone device and has nothing to do with any web tech.

You put your ATM card in the device, enter your PIN code, and then the device has a tiny camera that scans the QR code on the web page. Next, you can see the transaction details on the device and confirm. It will then output a signing code which you enter on the web page.

It is what was commonly used in some EU countries before we switched to mobile banking apps. Most banks still supply them for when you do very large online transactions.

Re: The underground world of credit card network exploitation

#185

Why does the US still accept hand-typed cards? My friend had a USB smartcard reader in like 2001. He'd dip his AmEx to perform a transaction on his PC. It's twenty years later and the industry still hasn't caught up? What's different about Europe that they seem to have figured this out decades ago?

Fuck smartcard readers. Also: fuck 3d secure. The nice thing about old, "insecure" card payments was: I just needed to memorize my credit card number, expiry date and CCV and I could pay online for everything. No need to always carry a phone for SMS/app authentication.

Re: The underground world of credit card network exploitation

#186

Earlier quoted context omitted.

First, compared to the rest of the EU, Germany is a weird outlier with the number of banks they have (which, by the way, has been declining steadily for 15 years). Setting that aside, you missed the "deregulated" part. As I understand it (and I grant my understanding is pretty cursory) Germany has a much stronger central regulating body, and is subject to overall EU regulations as well. The US has multiple regional b…

> First, compared to the rest of the EU, Germany is a weird outlier with the number of banks they have (which, by the way, has been declining steadily for 15 years). Still, the absolute number itself seems to be not really the issue here. (I assume the number of US banks has similarly declined in the US, as fusions reduce cost.) > Setting that aside, you missed the "deregulated" part. Yeah, that part I don't object t…

[deleted]

Re: The underground world of credit card network exploitation

#187
post #5

Earlier quoted context omitted.

"banks (usually American ones) will happily accept transactions that have incorrect full name, invalid CVV / CVC, wrong expiration date, only partial billing address provided, with incorrect ZIP code. All of the above is still not enough to trigger a 3D secure authorisation" The solution indeed is to write manual rules to trigger 3D secure.

Even more funny is that in USA, the actual amount charged to the card is mutable. Take for example when you go to a restaurant and give your card, it's charged, and then you write out with a pen a tip amount, which at some future point gets added on to your charge.

But there are laws about that: you authorize tip with your signature, if they charge you more than you authorized, they can get in trouble. Don't see the issue here.

Re: The underground world of credit card network exploitation

#188

Earlier quoted context omitted.

... Which is hell if you're in a country where your sim card doesn't work and your bank requires sms 2fa.

Then it's a good thing that many banks in the EU now have 3DSecure validation through the phone app instead of SMS

What if you lose your phone? In my country banks only allow you to use one phone for mobile authorization, so you can't even have a backup phone. I really wish 3DSecure was optional so I can turn it of when going to foreign vacation.

Re: The underground world of credit card network exploitation

#189
post #83

Why does the US seem so far behind when it comes to banking? - Chip and PIN has been in the UK since 2004 and mandatory since 2006. It wasn't until a decade later that the US caught up. - Faster Payments allow for instant bank transfers (usually) between any bank account for free. Receiving transfers from clients in US (even with a US Wise bank account) was always a nightmare. - Since the EU introduced Strong Custome…

In my view, the U.S. is leading the way in this area. Europe seems to be shifting the burden of fraud prevention onto customers with methods like SMS notifications and pins. In contrast, in the U.S., banks and businesses are primarily responsible for dealing with fraud.

Oh, please. You're grossly misinformed. If anything, US is lagging lightyears behind Europe in terms of fighting fraud and fighting card schemes, which are stripping everyone equally in US, banks and customers alike.

PSD2 directive intruduced a lot of novelties, which no one at the time had (and very few do, not even US). For instance, specific to this situation - remote payments above 30 eur must be SCA (strong customer authentication, similar to 2FA, but more elaborate) verified (small value exception from PSD2 RTS). Also, banks must have both real time and post-time transaction monitoring in place, i.e. they must have systems to detect and prevent such fraudulent attemtps. There literally tens if not hundreds of fraud fighting measures in PSD2, which all banks (both acquirer and issuer) must come mply with. I could go on and on (not the place and format).

Frankly, it's utterly unbelievable that this kind of thing could happen without anyone (either acquirer or issuer) intervenining. Not what could (should) happen here in Europe.

Re: The underground world of credit card network exploitation

#190

Why does the US seem so far behind when it comes to banking? - Chip and PIN has been in the UK since 2004 and mandatory since 2006. It wasn't until a decade later that the US caught up. - Faster Payments allow for instant bank transfers (usually) between any bank account for free. Receiving transfers from clients in US (even with a US Wise bank account) was always a nightmare. - Since the EU introduced Strong Custome…

What's super interesting to me, lot of countries that you would expect to be behind the US on that topic actually have state-of-the-art banking techs. Even the EU is behind some of the stuff I've seen in LATAM.

Please, name an example. Particularly, EU being behind LATAM. As an expert, I'm honestly interested.
Post reply on HN