Takeaways from the $566M BriansClub Breach
krebsonsecurity.com
Takeaways from the $566M BriansClub Breach
1–10 of 29 posts
Re: Takeaways from the $566M BriansClub Breach
#2They give me a new card with a new number for free, much less likely to have made it onto any carders list.
Re: Takeaways from the $566M BriansClub Breach
#3Re: Takeaways from the $566M BriansClub Breach
#4Why don't credit/debit cards use elliptic curve cryptography?
Re: Takeaways from the $566M BriansClub Breach
#5I'm just reaching out for anyone who knows about any grand plans, initiatives or rehabs of how credit cards currently work. Keen to read more.
Re: Takeaways from the $566M BriansClub Breach
#6Open question; What's the long game on securing the way credit cards work? Who's working on something interesting that could thwart the whole 'name+number+ccv' leak thing that's been perpetuating in this industry for decades? I'm just reaching out for anyone who knows about any grand plans, initiatives or rehabs of how credit cards currently work. Keen to read more.
You have 16 digits on a Visa/MasterCard, the first six is the bank identifier and the last is a checksum digit thus you have 9 digits to "waste" -- and you can recycle them.
Re: Takeaways from the $566M BriansClub Breach
#7Open question; What's the long game on securing the way credit cards work? Who's working on something interesting that could thwart the whole 'name+number+ccv' leak thing that's been perpetuating in this industry for decades? I'm just reaching out for anyone who knows about any grand plans, initiatives or rehabs of how credit cards currently work. Keen to read more.
This is a solved problem, really, some banks are less keen on implementing it: generate single use / single purpose credit card numbers in your ebank / mobile app. Leaks are total useless. Also, more than a decade ago already many European banks were sending a text SMS above a treshold and only approved on a positive reply. Today you'd likely offer sending a push notification. You have 16 digits on a Visa/MasterCard,…
The impression I've gotten is that since most of the costs of fraud are on the bank, rather than the cardholder, there's not much incentive for the cardholder to go through the trouble of using single-use cards. And so it's a better investment for the bank to develop good fraud detection algorithms.
In my anecdotal experience, the fraud detection has gotten really good. Every time in the past decade that someone's gotten hold of my credit card number, the bank's caught it nearly immediately.
Re: Takeaways from the $566M BriansClub Breach
#8Open question; What's the long game on securing the way credit cards work? Who's working on something interesting that could thwart the whole 'name+number+ccv' leak thing that's been perpetuating in this industry for decades? I'm just reaching out for anyone who knows about any grand plans, initiatives or rehabs of how credit cards currently work. Keen to read more.
This is a solved problem, really, some banks are less keen on implementing it: generate single use / single purpose credit card numbers in your ebank / mobile app. Leaks are total useless. Also, more than a decade ago already many European banks were sending a text SMS above a treshold and only approved on a positive reply. Today you'd likely offer sending a push notification. You have 16 digits on a Visa/MasterCard,…
Re: Takeaways from the $566M BriansClub Breach
#9Earlier quoted context omitted.
This is a solved problem, really, some banks are less keen on implementing it: generate single use / single purpose credit card numbers in your ebank / mobile app. Leaks are total useless. Also, more than a decade ago already many European banks were sending a text SMS above a treshold and only approved on a positive reply. Today you'd likely offer sending a push notification. You have 16 digits on a Visa/MasterCard,…
Can they handle monthly subscriptions?
Re: Takeaways from the $566M BriansClub Breach
#10Open question; What's the long game on securing the way credit cards work? Who's working on something interesting that could thwart the whole 'name+number+ccv' leak thing that's been perpetuating in this industry for decades? I'm just reaching out for anyone who knows about any grand plans, initiatives or rehabs of how credit cards currently work. Keen to read more.