Live data from Hacker News

Credit cards are vulnerable to brute force kind attacks

metin.nextc.org

191–200 of 201 posts

Re: Credit cards are vulnerable to brute force kind attacks

#191
post #129

Earlier quoted context omitted.

> I again called the credit card company and this time, told them to cancel all the digital wallets (there were 99 of them!). There is no way to do this online. This is highly dependent on your bank. For example, Bank of America lets you view and delete any cards that have been added to a digital wallet right on their website.

Only digital wallets, or also any merchant that saved the card using a token? The latter is getting more and more common, but usually happens transparently to the cardholder. Theoretically, it would allow a pretty neat feature of being able to manage all merchants that have a copy of the card in the banking app and revoke said copies – but since token use is not mandatory, that would be fairly confusing, so I haven't…

> Only digital wallets, or also any merchant that saved the card using a token?

Only digital wallets. Specifically, Apple Pay, Garmin Pay, and Google Pay.

Re: Credit cards are vulnerable to brute force kind attacks

#192
post #107

I'll get the usual hate for this, but in this instance using bitcoin is safer, since it forces you to verify the transaction on your phone (i.e. you use your phone to pay - either scanning QR code or now NFC). In the US the Square payment terminals can now accept bitcoin from any lightning enabled wallet app, CashApp does it natively, etc.

Bitcoin has no dispute/chargeback mechanism in case of error or fraud. That inherent unsafety trumps just about all other safety concerns for a practical payment network.

Re: Credit cards are vulnerable to brute force kind attacks

#196
post #167

Earlier quoted context omitted.

Been doing this for a while now for ebay and other stuff. I'm always shocked at how many people have no idea this exists.

Because people use credit cards for the rewards (cash, mileage, whatever) or because they don’t actually have the money now. They don’t want to pay for a unique number for every transaction (which doesn’t actually preserve privacy since most of the stuff you’re buying online needs a shipping address) nor do they want the money immediately pulled from their bank account.

Credit cards give rewards which can be significant, reduce or eliminate the need to keep liquid cash around and frees it up for investments which compounds on top of the rewards, and it dramatically simplifies the number of annoying bills from N to one.

Re: Credit cards are vulnerable to brute force kind attacks

#197
post #71

Earlier quoted context omitted.

How much is lost to fraud that would be prevented by 3d secure, 0.1%?

In Europe, the max interchange fee is 0.3%. In the US, the average is 2%. So the relative impact of fraud is much higher.

And then the next question, how does this affect consumer spending, what percent of purchases get the 3d secure message and change their mind instead of confirming the purchase?

Re: Credit cards are vulnerable to brute force kind attacks

#198
Please just enter into your Google search and review this platform” and educate yourself before joining. Read BBC, Guardian, and Reddit articles/posts. Selfie camera doesn’t work, and they refuse to offer an alternative login method, so I can’t access my money. Keep getting same automated response(do some work you twits). They heavily spam my email, though. No customer service so imagine being stuck abroad with these absentee idiots as your lifeline, best learn to beg or busk in the local language. Am happy jeffsilbert 39 g mail com was my savior in getting my refund possible.

Re: Credit cards are vulnerable to brute force kind attacks

#199

Earlier quoted context omitted.

> I again called the credit card company and this time, told them to cancel all the digital wallets (there were 99 of them!). There is no way to do this online. This is highly dependent on your bank. For example, Bank of America lets you view and delete any cards that have been added to a digital wallet right on their website.

Half of my cards can't even be added to non-iPhone devices without a verification phone call to some poor support agent who's never heard of a "Pixel Watch", has no idea what the workflow is on his end to manually verify cards being added, and just wants me to "use the iPhone app to verify". Heaven forbid if I try to add a card to an Apple Wallet on a Mac where no iOS or Android app exists.

[dead]

Re: Credit cards are vulnerable to brute force kind attacks

#200
post #147

Earlier quoted context omitted.

USA. In USA your chargeback initially is usually taken on face. They'll usually reverse the charge within a week or so. But after that they let the merchant appeal it. Most merchants won't. But if they do, your bank isn't going to bat for you. If it looks like it's going to take them much time or effort to deal with it they're liable to just throw up their hands and let you duke it out in small claims court. In my ca…

> If it looks like it's going to take them much time or effort to deal with it they're liable to just throw up their hands and let you duke it out in small claims court. In the US, couldn't you just make it their problem by not paying the disputed portion of your bill? (I haven't tried this myself and don't know how hard it is to dispute a negative credit report without going to small claims court in the end.)

In theory yes, Reg Z forces them to prove that it was you that borrowed the money. In practice this is a weird situation to be in since chargebacks almost always favor the buyer so I have no idea how this shakes out and if it's worth temporarily screwing up your credit score
Post reply on HN