Live data from Hacker News

Credit cards are vulnerable to brute force kind attacks

metin.nextc.org

181–190 of 201 posts

Re: Credit cards are vulnerable to brute force kind attacks

#181

Earlier quoted context omitted.

yes, obviously all of the bank's money comes from consumers. what other scenario do you see where a bank(etc) "eats the loss" but the money somehow comes from somewhere else

While it may be obvious to you that your fees include covering all the banks losses to fraud, I think that most people assume the bank makes less profit or something due to such incidents, when the truth is they just raise their prices to maintain profits.

I don't see the difference between the two TBH.

Re: Credit cards are vulnerable to brute force kind attacks

#182

If 3D secure was mandatory everywhere that would help a lot, but if I understand correctly, it’s not really used in the US and with them being so big, card issuers are largely forced to allow non 3D secure requests or their clients will be unable to use their cards for too many things. So an enormously good anti-fraud mechanism is severely handicapped. It’s really frustrating for most of the rest of the world. I don’…

No, the laws are different- and more consumer friendly in the US- so the US consumer behavior is different. Back when credit cards were first starting out (which happened in the US) the US Congress passed a law- the Fair Credit Billing Act of 1974- that consumers were only liable for $50 of losses as long as they reported the missing credit card within 60 days of the end of the fraudulent billing cycle . This was bac…

> Thanks to the internet, suddenly cards got a lot easier to steal and a lot easier to exploit- but banks are still on the hook for all losses reported within 60 days of the end of the cycle.

For card-not-present transactions (i.e. online ones) the liability is on the merchant. They however also have an incentive NOT to use 3DS because it adds real friction to purchases. I'm also not sure if all USA banks even support 3DS.

Re: Credit cards are vulnerable to brute force kind attacks

#183
post #178

Earlier quoted context omitted.

It never ceases to amaze me how many people don't even look at their bank/credit card statements and just let their credit cards auto-pay. Back when I was poor, I was logging into my bank and credit card accounts at least twice/week. I always knew within $20 how much money I had. As a well-paid tech worker, I'm still checking at each paycheck (2x/month) and paying the credit card card off every time, but I'm still sc…

$20 for food cart chicken strips is the real scam.

The foot cart scene in the Portland metro area is really good. Those chicken strips were amazing and the sauce was superb. And despite hating both kale and cole slaw, their kale cole slaw was delicious.

Re: Credit cards are vulnerable to brute force kind attacks

#184

Earlier quoted context omitted.

You can reverse the charges on debit cards, but the money is withdrawn at the time the charge is made. This is not the case for credit cards.

> You can reverse the charges on debit cards, but the money is withdrawn at the time the charge is made. This is not the case for credit cards. In a sense it is though, because it lowers your available credit by the amount of the charge. And the fraudsters are going to try to run you right up to your credit limit, so you end up at the same problem: You now have legitimate charges being declined because the fraudsters…

You have a debit card backup though in that scenario. Arguably, you can just do the reverse and have a credit card backup, but some things don't accept credit card as payment.

Re: Credit cards are vulnerable to brute force kind attacks

#185
post #136

Earlier quoted context omitted.

Capital One also offers it for their credit cards, which makes them the only ones usable in countries where requiring 3DS is common. (No idea why this is a thing actually – merchants get the fraud chargeback liability shift as soon as they request 3DS, whether the issuer actually supports it or not.) The real problem is that in the US, almost no merchants request it in my experience, despite the fact that they'd get…

> No idea why this is a thing actually a) It still affects their bottom-line: the issuer might still try to dispute this using a different code despite payment scheme (formal term for Visa et al.) rules, and the merchant targeted is prone for fraud (for example, airlines have been hit with this by exploiting tourists looking for cheaper tickets by offering them suspiciously cheap tickets on seemingly-trustworthy webs…

Wow, c) never occured to me but makes total sense.

b) can probably explain this happening for EU merchants, but I've also seen this in Japan and Central America, and I think even before PSD2 in the EU.

That's what I love about the payments space: While you're absorbed in your own game of checkers, you never know if your opponent is actually playing 1d or 10d chess :)

Re: Credit cards are vulnerable to brute force kind attacks

#186
post #138

Earlier quoted context omitted.

Having multiple credit cards in the US is quite common, since there's no practical downside (unlike having multiple checking accounts, which locks up liquidity at usually no interest payment) and it can even be beneficial for your credit score.

That's not the problem. After all, if it happened to your debit card you could likewise make purchases on a different card, regardless of whether the other card is a debit or credit card. It's also not that hard to get two debit cards. There are credit unions with no minimum balance requirement. The actual problem is that if it happens to any card, all the stuff configured to use that card is now failing. You have a…

> It's also not that hard to get two debit cards.

But then you need to have money in the other checking account too.

Still, completely agree with your larger point. It's a big hassle having to switch cards, and the status quo (i.e., the industry being in a multi-decade transition period towards acceptable security) is sometimes the worst of both worlds:

Half of all merchants don't support automatic card updates and need to be manually fixed, while the other half do and have a chance of keeping your card alive in a fraudster's account where it's on file if your issuer is not careful.

Re: Credit cards are vulnerable to brute force kind attacks

#187
post #119

Related story and wondering if the OP may have been chasing red herrings. I recently noticed an unauthorized charge for a small amount on my credit card (something about FB/Meta). Likely someone probing the card to see if anyone would notice. I called the CC company, had them removed the charge, canceled the card and had them send me a new card (5-7 business days). With the brand new unused card (new CC number, new e…

Check out privacy.com, you can make your own cards. One per service if you want.

Visited the site and the first thing it wanted me to do was accept optional cookies. Privacy.com wants to track me because of course it does.

Re: Credit cards are vulnerable to brute force kind attacks

#188

Related story and wondering if the OP may have been chasing red herrings. I recently noticed an unauthorized charge for a small amount on my credit card (something about FB/Meta). Likely someone probing the card to see if anyone would notice. I called the CC company, had them removed the charge, canceled the card and had them send me a new card (5-7 business days). With the brand new unused card (new CC number, new e…

It's a shame that a disputed charge doesn't result in the credit card company reviewing how the charge was processed, invalidating only the single saved token with a single merchant. That would save everyone a lot of time and money.

Re: Credit cards are vulnerable to brute force kind attacks

#189
post #113

Oh okay, so this is why Amex launched the online card in the app that changes the Cvv2 every few minutes.

3-digits? What is this, an OTP for ants?

Amex uses 4 but sure it ain’t a lot. Enough to stop this attach though.
Post reply on HN