Live data from Hacker News

Credit cards are vulnerable to brute force kind attacks

metin.nextc.org

71–80 of 201 posts

Re: Credit cards are vulnerable to brute force kind attacks

#71

If 3D secure was mandatory everywhere that would help a lot, but if I understand correctly, it’s not really used in the US and with them being so big, card issuers are largely forced to allow non 3D secure requests or their clients will be unable to use their cards for too many things. So an enormously good anti-fraud mechanism is severely handicapped. It’s really frustrating for most of the rest of the world. I don’…

How much is lost to fraud that would be prevented by 3d secure, 0.1%?

In Europe, the max interchange fee is 0.3%. In the US, the average is 2%. So the relative impact of fraud is much higher.

Re: Credit cards are vulnerable to brute force kind attacks

#72
post #54

Related story and wondering if the OP may have been chasing red herrings. I recently noticed an unauthorized charge for a small amount on my credit card (something about FB/Meta). Likely someone probing the card to see if anyone would notice. I called the CC company, had them removed the charge, canceled the card and had them send me a new card (5-7 business days). With the brand new unused card (new CC number, new e…

I’m not sure about “digital wallets”, but the concept of updating credit card details after a new card is issued does exist, and it’s a service offered by credit card companies. Blog post from Stripe: https://stripe.com/resources/more/what-is-a-card-account-upd...

There are also "network tokens" that allow you to skip this step and instead remain linked to the new credit card when it changes.

Re: Credit cards are vulnerable to brute force kind attacks

#73
post #57

Earlier quoted context omitted.

> I don’t get it, do US citizens prefer being defrauded over what is perceived as a slight inconvenience? Do you think we are requesting to have less secure payment methods or something? No, we don't "prefer to get defrauded", but things like this are a matter of negotiation between the card issuers and the merchants.

> but things like this are a matter of negotiation between the card issuers and the merchants. Not necessarily, the EU has mandated strong customer authentication by law (PSD2), and as a result has practically universal 3DSecure support.

Ah, the natural call of the wild European: blaming individual Americans for a century of policy failures with truly majestic smugness.

Re: Credit cards are vulnerable to brute force kind attacks

#74

>As a consumer, I thought I was safe; when saving my credit card to a billion dollar valued european merchant, or when i purchase something from supermarket and ignore the receipt, but the reality is slightly different from that. >I got the money back via chargeback in short time. So as evidenced, you are protected by the fraud infrastructure. The bank ate the loss for the fraud and you were made whole. In the end, t…

It's my experience that the bank will give up against a motivated chargeback counterparty. My experience with ebay (stolen credit card) in particular was that things were going well until e-bay sent their stack of paperwork to my bank. Then my chargeback was reversed and shortly after that even my bank account was closed. So you're not in the clear once you get your chargeback back. That is done initially while they…

in what country?

Re: Credit cards are vulnerable to brute force kind attacks

#75
post #57

Earlier quoted context omitted.

> I don’t get it, do US citizens prefer being defrauded over what is perceived as a slight inconvenience? Do you think we are requesting to have less secure payment methods or something? No, we don't "prefer to get defrauded", but things like this are a matter of negotiation between the card issuers and the merchants.

> but things like this are a matter of negotiation between the card issuers and the merchants. Not necessarily, the EU has mandated strong customer authentication by law (PSD2), and as a result has practically universal 3DSecure support.

Exactly, if citizens could convince US lawmakers to make it mandatory, it would be a huge net benefit to society as a whole.

I suspect that banks and merchants would lobby against it due the work involved. After all, they’ve already marked up their services and goods to cover the cost of fraud/insurance. So right now they don’t pay the cost of it, instead all their customers do through higher prices than they would otherwise have needed to pay.

Re: Credit cards are vulnerable to brute force kind attacks

#76

Virtual credit cards have been a thing for years. I remember bank of america or Citi providing them to me 15+ years ago. If I recall it was a java app or maybe even a standalone exe. Shocked they never took off more broadly. Robinhood absolutely nails this. Best virtual credit card system I have ever used. So seamless. Can auth a card for one time use, 24 hours, or indefinite until you cancel. Such a great UI / UX

MBNA (which got bought out by Chase) had a Flash-based virtual card app back in the early 2000's. I really enjoyed using it. I also can't understand why they haven't taken off, especially in the world of Everything Is A Subscription we're living in now. I adored being able to set expiration dates and spend limits to save ugly negotiations about ending subscriptions.

Re: Credit cards are vulnerable to brute force kind attacks

#77

Virtual credit cards have been a thing for years. I remember bank of america or Citi providing them to me 15+ years ago. If I recall it was a java app or maybe even a standalone exe. Shocked they never took off more broadly. Robinhood absolutely nails this. Best virtual credit card system I have ever used. So seamless. Can auth a card for one time use, 24 hours, or indefinite until you cancel. Such a great UI / UX

It didn’t take off because it was easier to eat the costs of fraud than to maintain the system. It didn’t catch on simply because it’s pro-consumer.

Re: Credit cards are vulnerable to brute force kind attacks

#78

Payment processors don't allow just brute forcing all card numbers a.k.a. card enumeration or card testing [1][2] and card schemes penalise merchants and payment processors heavily if they don't take measures against it [3]. 1) https://stripe.com/newsroom/news/card-testing-surge 2) https://stripe.com/blog/the-ml-flywheel-how-we-continually-i... 3) https://docs.stripe.com/disputes/monitoring-programs#enumera...

Until 6 years ago Stripe didn't obfuscate card numbers in API logs at all.

Re: Credit cards are vulnerable to brute force kind attacks

#79
Recently I got an sms from my bank about a suspicious transaction overseas from my wife’s card, it was literally listed as zero USD, at a time when she was not using her phone or computer.

I initially thought the sms itself was phishing, but after checking online, the sms format matched and the bank webpage ensured the feedback process will not ask for any information so we proceeded to confirm that we did not purchase anything.

The bank immediately cancelled the card and shipped a new one.

My initial thought is that the bank safety system could be overreacting, but it was likely that someone was doing exactly what is described in this article and the bank detected it earlier.

Re: Credit cards are vulnerable to brute force kind attacks

#80
post #74

Earlier quoted context omitted.

It's my experience that the bank will give up against a motivated chargeback counterparty. My experience with ebay (stolen credit card) in particular was that things were going well until e-bay sent their stack of paperwork to my bank. Then my chargeback was reversed and shortly after that even my bank account was closed. So you're not in the clear once you get your chargeback back. That is done initially while they…

in what country?

USA. In USA your chargeback initially is usually taken on face. They'll usually reverse the charge within a week or so. But after that they let the merchant appeal it.

Most merchants won't. But if they do, your bank isn't going to bat for you. If it looks like it's going to take them much time or effort to deal with it they're liable to just throw up their hands and let you duke it out in small claims court.

In my case they had a megacorp ready to fight it on one side, and little old me on the other. So some lady on the phone just insinuated I was a lying scammer and told me my case had been reversed. There was some sort of appeal process I tossed my hat into but it went straight to radio silence and I've not heard from them in years. I would have taken them to court but I moved cross country around the same time and it would cost me $2000 or so for airfare and hotel rooms to show up to the right courts to get $1000 in judgements.

Post reply on HN