Live data from Hacker News

The underground world of credit card network exploitation

chargebackstop.com

271–280 of 280 posts

Re: The underground world of credit card network exploitation

#271
post #256

Earlier quoted context omitted.

Have you ever considered that what’s keeping most companies proactively honest and consumer-friendly are consumer protection laws and regulations?

Have you ever considered that those don't require credit card chargebacks?

Of course not, but you made a different point in the comment I was replying to:

> I don't think customer protection is necessary [...]

Chargebacks are only one possible consumer recourse mechanism specific to payment cards. There's other means to keep merchants honest.

Re: The underground world of credit card network exploitation

#272
post #270
post #268

Earlier quoted context omitted.

> We’ve had both of these tools for over 20 years now. It’s just a question of how much the industry is choosing to cater to convenience and backwards compatibility, i.e. a security/availability trade off. Exactly: it’s not like this was a technological breakthrough but that companies were trying to avoid breaking backwards compatibility - not just things like the readers but backend payment systems using something l…

> that’s the peace of mind benefit I see: those businesses can slack on security without me getting stuck with a potentially massive bill. That's a false dichotomy, though: Regulators can mandate merchants and issuers to make fraud less likely without allowing the liability for any remaining fraud to be pushed onto cardholders.

That doesn’t make it a false dichotomy. We have an existing regulatory model which absolves consumers of most fraud risk, and many people like that.

Re: The underground world of credit card network exploitation

#273
post #272
post #270

Earlier quoted context omitted.

> that’s the peace of mind benefit I see: those businesses can slack on security without me getting stuck with a potentially massive bill. That's a false dichotomy, though: Regulators can mandate merchants and issuers to make fraud less likely without allowing the liability for any remaining fraud to be pushed onto cardholders.

That doesn’t make it a false dichotomy. We have an existing regulatory model which absolves consumers of most fraud risk, and many people like that.

Sure, and maybe I'm misunderstanding you, but your point is that changing that model might make things worse for consumers by pushing more liability onto them, right?

I'm just saying that this isn't necessarily a consequence of improving fraud rates, although it's definitely important to keep an eye on issuers – I've heard about attempts to use it as an opportunity to limit liability in the past.

Re: The underground world of credit card network exploitation

#274
post #250

Earlier quoted context omitted.

I think you misunderstood me. Peace of mind is in not having to worry about fraud being my responsibility to fight or dispute. I can call CC company or through mobile app, flag transaction, get my money back and never spend another minute on the issue.

Ok, but you have to worry about detecting fraud. Without a PIN/MFA attackers have it much easier time doing fraudulent transactions from the start => more time spent by everybody checking transactions. And even if you have peace of mind, I wonder who pays for the cost of the fraud. I would imagine the bank will just pass it over to the consumer in some fees. So a system that reduce fraud (even if can't eliminate it c…

No I don't.

Re: The underground world of credit card network exploitation

#275
post #166

Earlier quoted context omitted.

Definetly not a better experience for all consumers. Or waiter. I do know that some restaurant owners are removing these things. They do not want to look like Olive Garden :) But it really depends on a restaurant: is it high end, type of food / drinks, it is a date place, etc. Majority of restaurant is all about experience and event payment system should match that experience.

I've lived in Japan for so long now that paying at restaurants in other countries where it's done at the table seems so awkward. In Japan, you don't pay at the table, you get up when leaving and pay at the exit. If you're at a high-end establishment entertaining guests, this also leaves you the opportunity to "go to the restroom" late in the dinner and pay ahead of time so that the "mess" of payments is completely fo…

> In Japan, you don't pay at the table, you get up when leaving and pay at the exit.

Some (well, one maybe) restaurants near me are like this but it is uncommon. Ram's Horn comes to mind.

Re: The underground world of credit card network exploitation

#276

Earlier quoted context omitted.

> Majority of restaurant is all about experience and event payment system should match that experience. I'm in the UK. I go to many high-end restaurants, cocktail bars, etc. Portable card terminals are essentially universal in these places. The fact it's the same everywhere is a feature, not a bug. It's quick. Your card never leaves your sight. No pen is required. Payments up to £100 can be done using contactless on…

I’d be annoyed if I ended up in a restaurant that didn’t have a card machine. They’re almost universal at this point to the extent that not to have one would be unusual.

> almost universal at this point

Where you live maybe.

Re: The underground world of credit card network exploitation

#277
post #219

Earlier quoted context omitted.

UPI is a terrible thing. 0) makes every transaction a trivial SQL query away for the government. 1) everything needs an SMS code. Just as we are trying to get everyone off SMS 2FA 2) doesn’t work for non-Indian numbers or roaming devices 3) can’t get an Indian SIM without proof of address etc. No burners in India 4) regulation expressly forbids devic-local biometrics. This is why there is no Apple Pay in India. 5) Bi…

It may be a terrible thing but it has brought such a big change to the Indian economy. Imagine doing that in US which is a much smaller population and all you get is "choice" aka "freedom" to pay 3-5% credit card fee per transaction.

I'll take 3% over having a single payment processor I can't swap out.

The change to the Indian economy was going to come through private investment anyway but the government blocked that. So saying the change came because of UPI is disingenuous at best because it never had to compete with any other offerings. No other entity was even allowed to compete.

Re: The underground world of credit card network exploitation

#279

(Edwin from Stripe here.) Worth noting this is copypasta from an older post from a month ago ( https://piotrmierzejewski.com/p/card-networks-exploitation ). We've fixed most of these issues since then. This type of card testing has dwindled—Radar should now be catching these types of attacks. On the chargeback point—we hate chargebacks too and we want to limit them as much as possible (we're actually working on a few…

> Radar should now be catching these types of attacks. No, your base offering should catch these. Sincerely, a customer of yours.

Radar is included for free in the base offering.

Re: The underground world of credit card network exploitation

#280

Earlier quoted context omitted.

> Radar should now be catching these types of attacks. No, your base offering should catch these. Sincerely, a customer of yours.

Radar is included for free in the base offering.

My bad, I mixed that up with Radar for fraud teams.
Post reply on HN