Live data from Hacker News

Credit cards are vulnerable to brute force kind attacks

metin.nextc.org

61–70 of 201 posts

Re: Credit cards are vulnerable to brute force kind attacks

#61

Oh okay, so this is why Amex launched the online card in the app that changes the Cvv2 every few minutes.

I had no idea amex offers virtual cards... but I looked everywhere in the app and cannot find any such option?

https://www.americanexpress.com/en-gb/services/ways-to-pay/d...

Re: Credit cards are vulnerable to brute force kind attacks

#62
post #9

Earlier quoted context omitted.

That has not been my experience with debit cards in the US at major banks, at all , over decades. (I'm pathologically avoidant of credit cards, which I think are mostly pointless.)

When my bank account got drained, I could not pay rent or any bills. I had enough cash for about a week of food. It took 4 weeks for the bank to decide I could be made whole. Ever since then I have never even put a debit card in my wallet. I know what the laws say. I have read endless "well banks usually[...]" type messages. and yet all the same I one day awoke to find myself transformed into a giant cockroach.

EFTA Reg E gives banks 10 days to make you whole (less an optional $50 deductible depending on when the fraud was reported). My experience going back decades is that they've simply reverted the charges instantly. What bank were you using? My experience is with the usual suspects --- Citi, Chase, and BofA.

Under the law, credit card issuers actually have more time to deliberate before making you whole, not less.

Re: Credit cards are vulnerable to brute force kind attacks

#63
post #57

If 3D secure was mandatory everywhere that would help a lot, but if I understand correctly, it’s not really used in the US and with them being so big, card issuers are largely forced to allow non 3D secure requests or their clients will be unable to use their cards for too many things. So an enormously good anti-fraud mechanism is severely handicapped. It’s really frustrating for most of the rest of the world. I don’…

> I don’t get it, do US citizens prefer being defrauded over what is perceived as a slight inconvenience? Do you think we are requesting to have less secure payment methods or something? No, we don't "prefer to get defrauded", but things like this are a matter of negotiation between the card issuers and the merchants.

> but things like this are a matter of negotiation between the card issuers and the merchants.

Not necessarily, the EU has mandated strong customer authentication by law (PSD2), and as a result has practically universal 3DSecure support.

Re: Credit cards are vulnerable to brute force kind attacks

#64

>As a consumer, I thought I was safe; when saving my credit card to a billion dollar valued european merchant, or when i purchase something from supermarket and ignore the receipt, but the reality is slightly different from that. >I got the money back via chargeback in short time. So as evidenced, you are protected by the fraud infrastructure. The bank ate the loss for the fraud and you were made whole. In the end, t…

Banks don’t really eat the loss, instead they ensure all their services have enough of a markup to cover the cost of fraud.

All consumers collectively pay for all the fraud, it’s just that we don’t tend to realize it as it’s not a specific line item on any of our bills, instead we all pay just a little more than we should for everything we buy.

Re: Credit cards are vulnerable to brute force kind attacks

#65
post #8

Some have speculated that the entire credit card system is compromised, end to end. I think the real question is why NSA didn't intervene in the early 1990s. Online commerce was just beginning, and the importance of electronic funds transfer was obvious, but the method wasn't set in stone. NSA knew about public key crypto well before the rest of us did. They could have helped set up very secure electronic payments, b…

NSA prefers compromised security so that answers your question Credit card system was already around for decades before though

Reminds me of when I wrote a lightweight blockchain from scratch including the Lamport OTS (quantum resistant) signature scheme and then most of the leaders from my crypto community at the time turned against me for no reason.

The signature scheme I implemented was thoroughly tested. Implemented from reading the Lamport and Merkel academic papers and under 1000 lines of code in total so pretty easy to audit... Nobody found an issue with it in 5 years. But the suppression was suspicious. The narrative of "Don't roll your own crypto" is suspicious... Is it really better to use the same library as hundreds of thousands of other projects? Is that really lower risk? Didn't we learn from the Axios hack that popularity doesn't provide security.

Re: Credit cards are vulnerable to brute force kind attacks

#66
post #26

I once had a person that was hired by my company and then started bragging about finding a way to add stored value to gift cards. Then come to find out they were under investigation by the FBI. This was a government contractor mind you, so the biggest security guard I’ve ever seen showed up to escort them out.

What does “add stored value to gift cards” mean?

Re: Credit cards are vulnerable to brute force kind attacks

#67
post #57

Earlier quoted context omitted.

> I don’t get it, do US citizens prefer being defrauded over what is perceived as a slight inconvenience? Do you think we are requesting to have less secure payment methods or something? No, we don't "prefer to get defrauded", but things like this are a matter of negotiation between the card issuers and the merchants.

> but things like this are a matter of negotiation between the card issuers and the merchants. Not necessarily, the EU has mandated strong customer authentication by law (PSD2), and as a result has practically universal 3DSecure support.

Bold of you to assume that the public has more influence on legislation than lobbyists do in the US.

Re: Credit cards are vulnerable to brute force kind attacks

#68
One other thing to add to the story is that the merchants can’t select what level of security they want from the credit card processor. For example, with authorize.net, you can accept the payment with the address doesn’t matter it doesn’t match.

I guess the real question here is how are they able to steal from you? Were they purchasing gift cards from a merchant with lax security?

It’s one thing to guess a number it’s another thing to get the money out of the system

Re: Credit cards are vulnerable to brute force kind attacks

#69

>As a consumer, I thought I was safe; when saving my credit card to a billion dollar valued european merchant, or when i purchase something from supermarket and ignore the receipt, but the reality is slightly different from that. >I got the money back via chargeback in short time. So as evidenced, you are protected by the fraud infrastructure. The bank ate the loss for the fraud and you were made whole. In the end, t…

Banks don’t really eat the loss, instead they ensure all their services have enough of a markup to cover the cost of fraud. All consumers collectively pay for all the fraud, it’s just that we don’t tend to realize it as it’s not a specific line item on any of our bills, instead we all pay just a little more than we should for everything we buy.

yes, obviously all of the bank's money comes from consumers. what other scenario do you see where a bank(etc) "eats the loss" but the money somehow comes from somewhere else

Re: Credit cards are vulnerable to brute force kind attacks

#70
post #62

Earlier quoted context omitted.

When my bank account got drained, I could not pay rent or any bills. I had enough cash for about a week of food. It took 4 weeks for the bank to decide I could be made whole. Ever since then I have never even put a debit card in my wallet. I know what the laws say. I have read endless "well banks usually[...]" type messages. and yet all the same I one day awoke to find myself transformed into a giant cockroach.

EFTA Reg E gives banks 10 days to make you whole (less an optional $50 deductible depending on when the fraud was reported). My experience going back decades is that they've simply reverted the charges instantly. What bank were you using? My experience is with the usual suspects --- Citi, Chase, and BofA. Under the law, credit card issuers actually have more time to deliberate before making you whole, not less.

sorry, I ninja edited my comment to avoid having an identical discussion as the previous many times I brought up this topic.

It is nice that you know what the law is but that isn't the same as the law being followed. Also the bank was PNC, not the biggest guy ever but not a small player either.

Post reply on HN