Live data from Hacker News

Takeaways from the $566M BriansClub Breach

krebsonsecurity.com

1–10 of 29 posts

Re: Takeaways from the $566M BriansClub Breach

#5
Open question; What's the long game on securing the way credit cards work? Who's working on something interesting that could thwart the whole 'name+number+ccv' leak thing that's been perpetuating in this industry for decades?

I'm just reaching out for anyone who knows about any grand plans, initiatives or rehabs of how credit cards currently work. Keen to read more.

Re: Takeaways from the $566M BriansClub Breach

#6
post #5

Open question; What's the long game on securing the way credit cards work? Who's working on something interesting that could thwart the whole 'name+number+ccv' leak thing that's been perpetuating in this industry for decades? I'm just reaching out for anyone who knows about any grand plans, initiatives or rehabs of how credit cards currently work. Keen to read more.

This is a solved problem, really, some banks are less keen on implementing it: generate single use / single purpose credit card numbers in your ebank / mobile app. Leaks are total useless. Also, more than a decade ago already many European banks were sending a text SMS above a treshold and only approved on a positive reply. Today you'd likely offer sending a push notification.

You have 16 digits on a Visa/MasterCard, the first six is the bank identifier and the last is a checksum digit thus you have 9 digits to "waste" -- and you can recycle them.

Re: Takeaways from the $566M BriansClub Breach

#7
post #6
post #5

Open question; What's the long game on securing the way credit cards work? Who's working on something interesting that could thwart the whole 'name+number+ccv' leak thing that's been perpetuating in this industry for decades? I'm just reaching out for anyone who knows about any grand plans, initiatives or rehabs of how credit cards currently work. Keen to read more.

This is a solved problem, really, some banks are less keen on implementing it: generate single use / single purpose credit card numbers in your ebank / mobile app. Leaks are total useless. Also, more than a decade ago already many European banks were sending a text SMS above a treshold and only approved on a positive reply. Today you'd likely offer sending a push notification. You have 16 digits on a Visa/MasterCard,…

Bank of America has discontinued their ShopSafe system for single-use credit cards. Citibank seems to still have their virtual credit card system, but it requires Flash. Are any banks currently embracing it?

The impression I've gotten is that since most of the costs of fraud are on the bank, rather than the cardholder, there's not much incentive for the cardholder to go through the trouble of using single-use cards. And so it's a better investment for the bank to develop good fraud detection algorithms.

In my anecdotal experience, the fraud detection has gotten really good. Every time in the past decade that someone's gotten hold of my credit card number, the bank's caught it nearly immediately.

Re: Takeaways from the $566M BriansClub Breach

#8
post #6
post #5

Open question; What's the long game on securing the way credit cards work? Who's working on something interesting that could thwart the whole 'name+number+ccv' leak thing that's been perpetuating in this industry for decades? I'm just reaching out for anyone who knows about any grand plans, initiatives or rehabs of how credit cards currently work. Keen to read more.

This is a solved problem, really, some banks are less keen on implementing it: generate single use / single purpose credit card numbers in your ebank / mobile app. Leaks are total useless. Also, more than a decade ago already many European banks were sending a text SMS above a treshold and only approved on a positive reply. Today you'd likely offer sending a push notification. You have 16 digits on a Visa/MasterCard,…

Can they handle monthly subscriptions?

Re: Takeaways from the $566M BriansClub Breach

#9
post #8
post #6

Earlier quoted context omitted.

This is a solved problem, really, some banks are less keen on implementing it: generate single use / single purpose credit card numbers in your ebank / mobile app. Leaks are total useless. Also, more than a decade ago already many European banks were sending a text SMS above a treshold and only approved on a positive reply. Today you'd likely offer sending a push notification. You have 16 digits on a Visa/MasterCard,…

Can they handle monthly subscriptions?

I learned about privacy.com here on HN and it has been very helpful for me. You can create virtual cards for single-use or recurring payments. Each card can only be used by one vendor. You also set a max amount.

Re: Takeaways from the $566M BriansClub Breach

#10
post #5

Open question; What's the long game on securing the way credit cards work? Who's working on something interesting that could thwart the whole 'name+number+ccv' leak thing that's been perpetuating in this industry for decades? I'm just reaching out for anyone who knows about any grand plans, initiatives or rehabs of how credit cards currently work. Keen to read more.

Apple Pay generates a token that can only be used by the merchant for the authorized amount. More details: https://squareup.com/us/en/townsquare/what-does-tokenization...
Post reply on HN