Live data from Hacker News

Credit cards are vulnerable to brute force kind attacks

metin.nextc.org

81–90 of 201 posts

Re: Credit cards are vulnerable to brute force kind attacks

#81
post #57

If 3D secure was mandatory everywhere that would help a lot, but if I understand correctly, it’s not really used in the US and with them being so big, card issuers are largely forced to allow non 3D secure requests or their clients will be unable to use their cards for too many things. So an enormously good anti-fraud mechanism is severely handicapped. It’s really frustrating for most of the rest of the world. I don’…

> I don’t get it, do US citizens prefer being defrauded over what is perceived as a slight inconvenience? Do you think we are requesting to have less secure payment methods or something? No, we don't "prefer to get defrauded", but things like this are a matter of negotiation between the card issuers and the merchants.

Legislate that the banks are liable for refunding this class of fraud and you'll find they suddenly take this stuff a lot more seriously and "discover" the technology.

Re: Credit cards are vulnerable to brute force kind attacks

#82
post #68

One other thing to add to the story is that the merchants can’t select what level of security they want from the credit card processor. For example, with authorize.net, you can accept the payment with the address doesn’t matter it doesn’t match. I guess the real question here is how are they able to steal from you? Were they purchasing gift cards from a merchant with lax security? It’s one thing to guess a number it’…

> merchants can’t select what level of security they want from the credit card processor

That really depends on the processor; many processors do allow merchants specify your acceptance rules in quite deep detail.

There's a bit of a dichotomy in the processor market: on one side you have those that aim to make it simple for their customers and unburden them, while on the other side you have those that expose all the complexities and give intricate controls. The first side won't allow you to specify security requirements, while the second side will give you a hundred options (of course there's also processors positioning them in between). The two sides generally target different customers.

Re: Credit cards are vulnerable to brute force kind attacks

#83

If 3D secure was mandatory everywhere that would help a lot, but if I understand correctly, it’s not really used in the US and with them being so big, card issuers are largely forced to allow non 3D secure requests or their clients will be unable to use their cards for too many things. So an enormously good anti-fraud mechanism is severely handicapped. It’s really frustrating for most of the rest of the world. I don’…

No, the laws are different- and more consumer friendly in the US- so the US consumer behavior is different.

Back when credit cards were first starting out (which happened in the US) the US Congress passed a law- the Fair Credit Billing Act of 1974- that consumers were only liable for $50 of losses as long as they reported the missing credit card within 60 days of the end of the fraudulent billing cycle. This was back when credit cards purchases were all made on paper with the machine that went "kachunk" and transferred a carbon copy of your card- everything was done completely offline. That law has not been changed, in fact, most banks completely waive the $50 and don't hold card-holders liable for anything reported (basically, annoying a customer over $50 isn't worth it to the bank). Thanks to the internet, suddenly cards got a lot easier to steal and a lot easier to exploit- but banks are still on the hook for all losses reported within 60 days of the end of the cycle. The result is that American banks have invested an enormous amount in real-time monitoring of credit card transactions, and are doing lots of stuff to monitor this- they care deeply since ultimately they are on the hook- but the consumer doesn't care. This is why US card's from the consumer perspective are so much laxer, because our banks have invested far more on the back-end because the consumer is held harmless in a way they aren't with European cards.

As a totally separate issue, the EU has regulated the amount of interchange fees that card-companies can charge, but the US has not capped them. The result is that US card-holders can get significant kickbacks for using cards (especially true for the top decile of wealth), in a way that is functionally impossible with EU issued cards that have capped interchange fees. There is a big lawsuit happening now to try and allow merchants to only accept low-fee cards (the standard VISA/MC/AMEX deal requires treating all cards equally, which gives them an incentive to push people to higher interchange cards). We will see what happens with that suit, but until then, American high-spenders can have much higher rewards on their cards, which also encourages greater use of the cards- and making them have less friction than the EU versions.

Re: Credit cards are vulnerable to brute force kind attacks

#84

Earlier quoted context omitted.

Banks don’t really eat the loss, instead they ensure all their services have enough of a markup to cover the cost of fraud. All consumers collectively pay for all the fraud, it’s just that we don’t tend to realize it as it’s not a specific line item on any of our bills, instead we all pay just a little more than we should for everything we buy.

yes, obviously all of the bank's money comes from consumers. what other scenario do you see where a bank(etc) "eats the loss" but the money somehow comes from somewhere else

While it may be obvious to you that your fees include covering all the banks losses to fraud, I think that most people assume the bank makes less profit or something due to such incidents, when the truth is they just raise their prices to maintain profits.

Re: Credit cards are vulnerable to brute force kind attacks

#85
post #74

Earlier quoted context omitted.

in what country?

USA. In USA your chargeback initially is usually taken on face. They'll usually reverse the charge within a week or so. But after that they let the merchant appeal it. Most merchants won't. But if they do, your bank isn't going to bat for you. If it looks like it's going to take them much time or effort to deal with it they're liable to just throw up their hands and let you duke it out in small claims court. In my ca…

I am a bit confused about your situation. Did you have a stolen card used to make a purchase at ebay that was not under your account? Or did you make a purchase at ebay and have an issue with the product you received?

Re: Credit cards are vulnerable to brute force kind attacks

#86
post #54

Earlier quoted context omitted.

I’m not sure about “digital wallets”, but the concept of updating credit card details after a new card is issued does exist, and it’s a service offered by credit card companies. Blog post from Stripe: https://stripe.com/resources/more/what-is-a-card-account-upd...

There are also "network tokens" that allow you to skip this step and instead remain linked to the new credit card when it changes.

Indeed, I suspect that's what went on here. I don't think there even exist 99 providers of what's customary called a digital wallet (e.g. Apple/Google Pay), and there's no definitely no single person that uses 99 of them.

It's bad service from GP's card company though, with network tokens they should be able to see which specific token was abused, and revoke just that one.

Re: Credit cards are vulnerable to brute force kind attacks

#88
post #71

Earlier quoted context omitted.

How much is lost to fraud that would be prevented by 3d secure, 0.1%?

In Europe, the max interchange fee is 0.3%. In the US, the average is 2%. So the relative impact of fraud is much higher.

There is also an additional (usually pretty high) fee for getting chargebacks.

Re: Credit cards are vulnerable to brute force kind attacks

#89

Earlier quoted context omitted.

> but things like this are a matter of negotiation between the card issuers and the merchants. Not necessarily, the EU has mandated strong customer authentication by law (PSD2), and as a result has practically universal 3DSecure support.

Exactly, if citizens could convince US lawmakers to make it mandatory, it would be a huge net benefit to society as a whole. I suspect that banks and merchants would lobby against it due the work involved. After all, they’ve already marked up their services and goods to cover the cost of fraud/insurance. So right now they don’t pay the cost of it, instead all their customers do through higher prices than they would o…

> Exactly, if citizens could convince US lawmakers to make it mandatory, it would be a huge net benefit to society as a whole.

That's not obviously true. Adding security would likely reduce fraud, but would also make transactions more difficult and time consuming, and may also make recovering from fraud more difficult and time consuming.

The costs may not justify the benefits.

Re: Credit cards are vulnerable to brute force kind attacks

#90
post #81
post #57

Earlier quoted context omitted.

> I don’t get it, do US citizens prefer being defrauded over what is perceived as a slight inconvenience? Do you think we are requesting to have less secure payment methods or something? No, we don't "prefer to get defrauded", but things like this are a matter of negotiation between the card issuers and the merchants.

Legislate that the banks are liable for refunding this class of fraud and you'll find they suddenly take this stuff a lot more seriously and "discover" the technology.

Quite hard to do when banks are major bribers of politicians.
Post reply on HN