Live data from Hacker News

Credit cards are vulnerable to brute force kind attacks

metin.nextc.org

1–10 of 201 posts

Re: Credit cards are vulnerable to brute force kind attacks

#2
People should have a separate card for online payments and have just enough money on it for a payment.

I know that I am naïve :)

Back to the article: Weak point was a password that lead to another merchant not using 3D secure.

It seems from the article that bad actors have fully automated system, so (big) merchants should have handle automatic login attempts from the same ip address with different accounts. I see it from our wordfence logs that ip rotation is not so quick so it could be handled with some permanent ip blocking.

Re: Credit cards are vulnerable to brute force kind attacks

#3
post #2

People should have a separate card for online payments and have just enough money on it for a payment. I know that I am naïve :) Back to the article: Weak point was a password that lead to another merchant not using 3D secure. It seems from the article that bad actors have fully automated system, so (big) merchants should have handle automatic login attempts from the same ip address with different accounts. I see it…

I agree with the seperate card. That was my seperate card and luckily the amount was not quite big because of that.

>Weak point was a password that lead to another merchant not using 3D secure

Well leaking a password shouldn't cause leaking a whole ass credit card data imo. The same data is printed on physical receipts the markets print, sometimes 4 digits, sometimes 10 digits. It's still possible to brute force from unattended physical receipts on the market.

Re: Credit cards are vulnerable to brute force kind attacks

#7
Some have speculated that the entire credit card system is compromised, end to end. I think the real question is why NSA didn't intervene in the early 1990s. Online commerce was just beginning, and the importance of electronic funds transfer was obvious, but the method wasn't set in stone. NSA knew about public key crypto well before the rest of us did. They could have helped set up very secure electronic payments, but chose not to for unknown reasons.

Re: Credit cards are vulnerable to brute force kind attacks

#8

Some have speculated that the entire credit card system is compromised, end to end. I think the real question is why NSA didn't intervene in the early 1990s. Online commerce was just beginning, and the importance of electronic funds transfer was obvious, but the method wasn't set in stone. NSA knew about public key crypto well before the rest of us did. They could have helped set up very secure electronic payments, b…

NSA prefers compromised security so that answers your question

Credit card system was already around for decades before though

Re: Credit cards are vulnerable to brute force kind attacks

#9

At least with a credit card you have some fraud protection. Report it and the charge should be reversed. And chargebacks are possible. With a debit card you’re playing with your own money.

That has not been my experience with debit cards in the US at major banks, at all, over decades.

(I'm pathologically avoidant of credit cards, which I think are mostly pointless.)

Re: Credit cards are vulnerable to brute force kind attacks

#10
post #9

At least with a credit card you have some fraud protection. Report it and the charge should be reversed. And chargebacks are possible. With a debit card you’re playing with your own money.

That has not been my experience with debit cards in the US at major banks, at all , over decades. (I'm pathologically avoidant of credit cards, which I think are mostly pointless.)

Why do you think they’re pointless?
Post reply on HN