Live data from Hacker News

Credit cards are vulnerable to brute force kind attacks

metin.nextc.org

91–100 of 201 posts

Re: Credit cards are vulnerable to brute force kind attacks

#91
post #29
post #10

Earlier quoted context omitted.

Why do you think they’re pointless?

For most of my adult life I haven't been able to get a credit card --- even after we sold Matasano Security, with the proceeds of that acquisition sitting in a money market checking account at the giant bank I use, that bank would still only issue me a secured card. I pay my bills and all, but at some point when I was like 19 I bought a shirt at Nordstroms and they signed me up for a card and I didn't pay enough atte…

> Under the law, credit card issuers actually have more time to deliberate before making you whole, not less.

Could be but in my personal experience, it has been the exact opposite. That said, I don't use banks. I work with credit unions exclusively. Maybe they have very different rules when it comes to handling debit card fraud.

The only time I have needed a debit card are when a place doesn't accept credit or charges a heavy markup for credit. Someone here mentioned Robinhood virtual credit card - I need to look into it, but I use a similar service and I keep my debit card locked only to unlock it for the exact window I am actually using it.

> rented cars, all that stuff. There's really been no point I can think of where I felt like having a revolving credit card would have made any of it more manageable.

I'm unaware when you last rented a car but when I rented a car last month, the company put a $500 hold on my credit card. That credit card hold went away after I returned the car in good condition a week later. I imagine, if I had used a debit card, that $500 hold would have made $500 disappear from my bank balance during that time. When my nephew rented a car, they put a $2000 hold on his credit card, I'm assuming because he's younger than 21. He certainly doesn't have $2000 to spare in his bank account.

The same credit card got me a free upgrade on the rental car, primary insurance protection during the rental period (I didn't have to buy the $40/day rental insurance) and got me 5% cashback on the full rental amount essentially undoing state taxes. The estimated cash value of these would have been ~$500 for the week. Using the debit card from my credit union would have got me exactly $0 (plus a reduced balance the whole time).

OTOH, a credit union shipped me a chipped debit card preactivated. The debit card shipped via regular USPS mail and was stolen along the way. I always keep $400 in my checking account, so the theif emptied my card at Target and 7/11. Within hours of receiving text about the charges, I called my credit union, informed them of the detail. They sent me a binder full of documents to sign. The whole time the money wasn't refunded. They took a month to review evidence and refunded me $50 (of the $400) and told me I would have to provide additional evidence that needed wet signatures, notarizied to receive the rest ($350). Every notarizied page in my jurisdiction costs $150.

> EFTA Reg E gives banks 10 days to make you whole

Interesting - any idea if this applies to credit unions too (because then you just got $350 back into my pocket!)

> I presumably still somehow owe them $40, and it wrecked my credit score.

> People say it will impact your ability to get a mortgage or a lease, but: not my experience!

Are these mortgages or a leases after you became wealthy or around the time when your credit score was wrecked? I imagine the effects of the Nordstroms credit card wore away 5-7 years (I don't recall exactly which) after the $40 was reported as late. So if more than 7 years passed between these two events, you might have a perfect FICO score now, even though you don't know it. I imagine you can just go to CreditKarma for free and use their free "dispute" charge option to permanently erase that Nordstrom black spot forever. I don't think anyone cares a multimillionaire had a forgotten $40 invoice when they were 19.

Also, for anyone above $1MM in liquid networth, most financial institutions treat the credit history as a signal and not the primary signal. I believe you have been above that by a healthy amount for a while now :)

PS: I am a HUGE fan of yours. I wrote all of the above expecting you absolutely wouldn't have a second to read a word but if you do, Thank You not only for reading (I hope atleast some of it helps you) but for your comments on HN from which I have learned a lot.

Re: Credit cards are vulnerable to brute force kind attacks

#92
post #60

Related story and wondering if the OP may have been chasing red herrings. I recently noticed an unauthorized charge for a small amount on my credit card (something about FB/Meta). Likely someone probing the card to see if anyone would notice. I called the CC company, had them removed the charge, canceled the card and had them send me a new card (5-7 business days). With the brand new unused card (new CC number, new e…

Digital wallets as in Apple/Google Pay? I had a similar thing happen and I am wondering what did you make of this double charge, what did the attackers do in your opinion?

no it's like a continuation of your credit card for recurring payments.

It's called Automatic Billing Updater (ABU)

the idea is that if you ask for a new credit card after being stolen, your say utility providers or other like netflix subscriptions can seamlessly switch over to the new credit card number.

it worked fine for a while, but of course the problem is that afterwards the stolen credit card credentials started to be refreshed as well.

(used ai to fetch the list below).

Visa: Visa Account Updater (VAU) Mastercard: Automatic Billing Updater (ABU) American Express: Cardrefresher General: Recurring Payment Tokenization

Re: Credit cards are vulnerable to brute force kind attacks

#93
post #54

Related story and wondering if the OP may have been chasing red herrings. I recently noticed an unauthorized charge for a small amount on my credit card (something about FB/Meta). Likely someone probing the card to see if anyone would notice. I called the CC company, had them removed the charge, canceled the card and had them send me a new card (5-7 business days). With the brand new unused card (new CC number, new e…

I’m not sure about “digital wallets”, but the concept of updating credit card details after a new card is issued does exist, and it’s a service offered by credit card companies. Blog post from Stripe: https://stripe.com/resources/more/what-is-a-card-account-upd...

Yep. I've been able to use the "wrong" (but still valid) expiration date on my AmEx for a long time. I've had other credit cards where the autopay info was never updated and it just kept working for at least 6 months.

Re: Credit cards are vulnerable to brute force kind attacks

#94
post #66
post #26

I once had a person that was hired by my company and then started bragging about finding a way to add stored value to gift cards. Then come to find out they were under investigation by the FBI. This was a government contractor mind you, so the biggest security guard I’ve ever seen showed up to escort them out.

What does “add stored value to gift cards” mean?

I think it means "take a gift card with $10 value stored and make it a gift card with $20 stored".

Re: Credit cards are vulnerable to brute force kind attacks

#95
post #54

Related story and wondering if the OP may have been chasing red herrings. I recently noticed an unauthorized charge for a small amount on my credit card (something about FB/Meta). Likely someone probing the card to see if anyone would notice. I called the CC company, had them removed the charge, canceled the card and had them send me a new card (5-7 business days). With the brand new unused card (new CC number, new e…

I’m not sure about “digital wallets”, but the concept of updating credit card details after a new card is issued does exist, and it’s a service offered by credit card companies. Blog post from Stripe: https://stripe.com/resources/more/what-is-a-card-account-upd...

it's called automatic billing updaters.

like

Visa: Visa Account Updater (VAU) https://developer.visa.com/capabilities/vau Mastercard: Automatic Billing Updater (ABU)

it worked fine for sometime, but the problem is that now the stolen credentials are being refreshed now as well.

Re: Credit cards are vulnerable to brute force kind attacks

#96

Earlier quoted context omitted.

USA. In USA your chargeback initially is usually taken on face. They'll usually reverse the charge within a week or so. But after that they let the merchant appeal it. Most merchants won't. But if they do, your bank isn't going to bat for you. If it looks like it's going to take them much time or effort to deal with it they're liable to just throw up their hands and let you duke it out in small claims court. In my ca…

I am a bit confused about your situation. Did you have a stolen card used to make a purchase at ebay that was not under your account? Or did you make a purchase at ebay and have an issue with the product you received?

Scammer created two e-bay accounts. One with my name but e-mail address "pirate" something. A second one, a scammer merchant account to wash the money.

They stole my credit card and used the bogus "me" ebay account to generate invoices (to my real address) and payments for goods from the second scammer merchant account. Then they found tracking numbers to my zip code. They bought the (fake) items from their scammer merchant account using their scammer "me" account. They used those tracking numbers to show the items were shipped and received to someone in my zip code (which is the only publicly available data from the tracking number). Of course, at no point were any of the goods "purchased" by "me" even real, but rather just ways to wash the credit card returns.

When I discovered what happened, I requested ebay refund it. Ebay claimed that since the accounts weren't actually mine (only in my name) I had no right to request a refund. So I could claim they were mine and then be ineligible for a refund because the underlying reason would be vaporized, or not claim them as mine and then be unable to ask for a refund because it's not actually my account -- a catch 22. The tracking numbers, again, since they weren't actually to me, the shipping companies refused to reveal the underlying data to me and I couldn't get any of the evidence showing it wasn't me.

At that point, I had my bank do a chargeback. Which they initially granted. I thought it was a done deal at that point.

Ebay sent all these invoices matching my name, with tracking numbers to my zip code, with my credit card being billed, etc to my bank along with a bunch of pages of banking mumbo jumbo about how the chargeback was wrong. At that point my bank turned face, called me a liar, and reinstated the charges. Not long after this, I noticed e-bay shut down the scammer account but they never refunded me the money. I assume the scammer had sucked out the money faster than e-bay could act to claw it back and when e-bay realized they'd be holding the bag they decided to dump it on the fraud victims.

Re: Credit cards are vulnerable to brute force kind attacks

#97
post #54

Earlier quoted context omitted.

I’m not sure about “digital wallets”, but the concept of updating credit card details after a new card is issued does exist, and it’s a service offered by credit card companies. Blog post from Stripe: https://stripe.com/resources/more/what-is-a-card-account-upd...

There are also "network tokens" that allow you to skip this step and instead remain linked to the new credit card when it changes.

Interesting. I recently cancelled and reordered a card and I have still been able to make purchases via Amazon without ever making an update. In this case I am happy about it because I am lazy but had no idea how it was working. Presume this is what is going on.

Re: Credit cards are vulnerable to brute force kind attacks

#98

If 3D secure was mandatory everywhere that would help a lot, but if I understand correctly, it’s not really used in the US and with them being so big, card issuers are largely forced to allow non 3D secure requests or their clients will be unable to use their cards for too many things. So an enormously good anti-fraud mechanism is severely handicapped. It’s really frustrating for most of the rest of the world. I don’…

No, the laws are different- and more consumer friendly in the US- so the US consumer behavior is different. Back when credit cards were first starting out (which happened in the US) the US Congress passed a law- the Fair Credit Billing Act of 1974- that consumers were only liable for $50 of losses as long as they reported the missing credit card within 60 days of the end of the fraudulent billing cycle . This was bac…

Why would the law being different mean they wouldn't use 3DS though? Surely it'd cut out a good amount of fraud along with the realtime monitoring? I understand that US consumers don't have a stake in this, but can't all the banks just agree to enforce 3DS? I can't imagine Americans are going to stop using their cards because of a small amount of friction added

Re: Credit cards are vulnerable to brute force kind attacks

#99
post #66
post #26

I once had a person that was hired by my company and then started bragging about finding a way to add stored value to gift cards. Then come to find out they were under investigation by the FBI. This was a government contractor mind you, so the biggest security guard I’ve ever seen showed up to escort them out.

What does “add stored value to gift cards” mean?

I'm guessing it means they can fraudulently add money to a store gift card without it costing anything.

Re: Credit cards are vulnerable to brute force kind attacks

#100
post #29

Earlier quoted context omitted.

For most of my adult life I haven't been able to get a credit card --- even after we sold Matasano Security, with the proceeds of that acquisition sitting in a money market checking account at the giant bank I use, that bank would still only issue me a secured card. I pay my bills and all, but at some point when I was like 19 I bought a shirt at Nordstroms and they signed me up for a card and I didn't pay enough atte…

> Under the law, credit card issuers actually have more time to deliberate before making you whole, not less. Could be but in my personal experience, it has been the exact opposite. That said, I don't use banks. I work with credit unions exclusively. Maybe they have very different rules when it comes to handling debit card fraud. The only time I have needed a debit card are when a place doesn't accept credit or charg…

I bought my first property in 2000, when I was in my very early 20s, and definitely wasn't wealthy. I bought a house in Ann Arbor in 2004, when I had no savings and was living on an ordinary developers salary; another in Chicago in 2005 (don't do what I did) when were starting Matasano. We sold Matasano in 2012 and my credit score was bad enough then that I was still required to get a secured card despite a relatively enormous sum of money parked in my account.

I think EFTA covers the mechanism of how debit cards work, not the institutions that issue them, but I'm not an expert. I would lean towards keeping an account for the card I use in normal transactions at one of the Big Four banks.

Post reply on HN