Live data from Hacker News

Criminals can guess Visa number and security code in six seconds, experts find

independent.co.uk

71–80 of 166 posts

Re: Criminals can guess Visa number and security code in six seconds, experts find

#71
post #7

There are well-specified rules for coming up with valid credit card account numbers, and at most, say, 60 valid expiration dates (12 months × 5 years into the future). Once an attacker has a valid credit card number and expiration date, there are only 10⁴ = 10,000 four-digit security codes possible, which the attacker tries with parallel requests to hundreds of websites. Each website gives the attacker at least a few…

1) Pick a bank that gives expiration dates within 3 years. 60 => 36 combinations 2) Security codes are always 3 digits. I don't know why you think 4? 9999 => 999 combinations.

[deleted]

Re: Criminals can guess Visa number and security code in six seconds, experts find

#72
post #19
post #15

Earlier quoted context omitted.

Isn't that (almost) 1000? All numbers between 001 and 999?

For any valid card number yes. I'd bet that almost all don't have three numbers all the same and that there are probably more rules/conventions that would reduce the search space. http://m.wolframalpha.com/input/?i=count+of+permutations+of+...

> I'd bet that almost all don't have three numbers all the same and that there are probably more rules/conventions that would reduce the search space.

You're correct that almost all don't have three identical digits, but that's just because there's only 10 of them -

000, 111, 222, 333, 444, 555, 666, 777, 888, 999

10/1000 = 1%

I doubt they would make up rules for determining the cvv, as it would only improve security until bad actors could determine the rules - then it would hinder security as there would be less entropy in the selection space.

Re: Criminals can guess Visa number and security code in six seconds, experts find

#73
post #18
post #10

Earlier quoted context omitted.

The data you'd gain from this is practically useless to anyone looking to commit fraud... so laugh at the article I guess? Maybe you could abuse this to create a lot of netflix accounts, but you aren't really going to be able to buy anything with just the PAN/cvv/expiry.

You can potentially issue an old-style mag-stripe credit card knock-off, and pay with it in an offline store. IDK if it's worth the effort: the card should look reasonable physically, too.

No, there's an analogue of the CVV2, the CVV1, which is only present on the magnetic stripe. The information you'd get from an online transaction is not enough to print a working magstripe.

Re: Criminals can guess Visa number and security code in six seconds, experts find

#74

Shouldn't this be easy to detect, though? Every attempt to use a credit card number online involves a request to the bank providing that card to determine if it's valid, right? So the bank would see thousands of attempts across hundreds of websites for the same card number in a matter of seconds, which is clearly impossible for a human, and flag the card as "stolen". Or maybe I'm just way too optimistic about how thi…

That was one of the points in the article. Since the merchant implements the limit and not the bank itself, you work across N merchants and you get plenty of attempts. And if the merchant is trying to be "consumer friendly" and accepts a relatively high number of failures before blocking the transaction, the allowed number of attempts is probably staggering.

[deleted]

Re: Criminals can guess Visa number and security code in six seconds, experts find

#75

Shouldn't this be easy to detect, though? Every attempt to use a credit card number online involves a request to the bank providing that card to determine if it's valid, right? So the bank would see thousands of attempts across hundreds of websites for the same card number in a matter of seconds, which is clearly impossible for a human, and flag the card as "stolen". Or maybe I'm just way too optimistic about how thi…

They don't have to use the same number. 100 attempts at 100 numbers is just as likely to turn up a hit as 10000 attempts on one number.

Re: Criminals can guess Visa number and security code in six seconds, experts find

#76

Wouldn't asking for the name on the card as well stop this? You're not going to be able to randomly generate the correct name.

Unfortunately, at least in the US, cardholder name matching doesn't work for most transactions. Only AMEX supports it.

Edit: Offtopic rant, but as an online merchant this is the sort of thing that pisses me off about the CC situation. They don't support other obvious things either, like passing in the shipping address and ip address so they can be used for fraud detection. Yes, there are outboard services (MaxMind,etc) you can use, but they are working with a small subset of transactions, so their algorithms and blacklists are incomplete.

Re: Criminals can guess Visa number and security code in six seconds, experts find

#77
post #53

So criminals can guess a valid CC/CVC/Zip in 6 seconds, and merchants that get nothing but green lights across the board from their credit card processor will be left holding the bag when the card holder disputes the charge. Merchants doing everything they can need better protection from this crap.

The merchant is not just left holding the bag. The merchant has to buy the bag...and it is not a cheap paper or plastic bad. It is a fancy, expensive, designer bag. When a charge is disputed, the merchant pays a fee of typically $15-30, regardless of who wins the dispute. In other words, there are two possible outcomes to a dispute: 1. Merchant loses. Merchant refunds in full that amount of the charge plus $15-30 for…

> Worse, the merchant does not appear to be able to really know when payment from a credit card is actually final.

This is why I find it strange when people wring their hands over Bitcoin's 10 minute settlement window... Credit card transactions are regularly open for weeks if not months!

Re: Criminals can guess Visa number and security code in six seconds, experts find

#78
post #53

Earlier quoted context omitted.

The merchant is not just left holding the bag. The merchant has to buy the bag...and it is not a cheap paper or plastic bad. It is a fancy, expensive, designer bag. When a charge is disputed, the merchant pays a fee of typically $15-30, regardless of who wins the dispute. In other words, there are two possible outcomes to a dispute: 1. Merchant loses. Merchant refunds in full that amount of the charge plus $15-30 for…

> Worse, the merchant does not appear to be able to really know when payment from a credit card is actually final. This is why I find it strange when people wring their hands over Bitcoin's 10 minute settlement window... Credit card transactions are regularly open for weeks if not months!

From the consumer perspective CC transactions are effectively instant, at least for the strip transaction. Even introducing the short delay that the chips involve has been very unpopular. (Why they went with chip+sig is clearly some form of non-security motivation.)

The solution to bitcoin, ironically, would be bitcoin+signature. The signature is forming a contract, a promise to pay. This is different from waiting for /an/ actual payment to clear.

Re: Criminals can guess Visa number and security code in six seconds, experts find

#79
post #55
post #49

Earlier quoted context omitted.

ACH still has chargebacks. For up to six months after the debit, no less.

It does, but the only allowable reason is "not authorized". Of course, for this type of fraud, that's the reason that matters. Thought it worth mentioning though, because in the CC world, a lot of the fraud is return fraud. Like "Item Not Received" or "Not as Described" being used when they aren't true.

I wonder how much of "Item Not Received" is due to poor transport security, like delivering the item to someone's 'property' but just leaving it outside, unattended and unsecured.

Re: Criminals can guess Visa number and security code in six seconds, experts find

#80
post #25

A solution that some banks provide is to enable a credit card for only transactions using 3-D Secure [1], in which you are expected to enter a 2FA code sent to your phone by the bank during transaction to a webpage of the bank that gets opened. Unfortunately, some (most) websites don't support 3-D Secure. I remember that almost all Turkish e-commerce sites I shopped supported it but almost none of the American sites…

>almost none of the American sites supported it

There's just not much incentive to support it. You have to make it optional, otherwise your conversion rate drops like a rock. And, if you make it optional, only a very tiny amount of customers ever use it...and the ones that do are VERY unlikely to be fraudulent users. Thus, the shift in liability isn't really an incentive.

The only way it would work would be to make it 100% mandatory. The checkout path would be harder on customers, but they couldn't choose to go to a competitor's site that didn't require it.

Post reply on HN