6 ms·
In case anyone is worried, most (all?) browsers do not autofill credit card information without the user explicitly clicking into the credit card field so there
by error54 10y ago
In case anyone is worried, most (all?) browsers do not autofill credit card information without the user explicitly clicking into the credit card field so there's no chance of a hidden field stealing your CC information.
- flanbiscuit 10y agoAnd even when clicking into the credit card field you still need to click a little popup that asks if you want to autofill.... at least that's how it works for me, I don't remember ever changing a setting on Chrome for this so I assume this is the default state. In fact it does something similar for my address information too. There must be some setting because I know my address autofill info is saved in Chrome but when I tried the demo I did not see my address info in the headers
- lightbyte 10y agoLast time I autofilled a CC with chrome it asked me to input the cvv number on the card before it filled in.
- gohrt 10y agoInteresting use of CVV, since vendors aren't permitted to store it. But Chrome does, for you... is that synced across browsers? That would require Google to store the CVV on its servers...
- bradjohnson 10y agoI don't know about this feature, but why couldn't it be stored as a hash?
- Scirra_Tom 10y agoI might be an order of magnitude off here, but I believe there's only around 1 billion unique numbers per card once you take away check sum digits and look at how they are issued. Assuming that's correct, it really wouldn't take up much memory or computing power to create a lookup table for every credit card number with hash x.
- hamhamed 10y agoChrome doesn't store the CVV, Google does. It syncs with your Google wallet account, and if the CVV is matched, then the credit card is auto filled
- minxomat 10y agoThis is what happens to me: 1) Google Chrome doesn't always explicitly ask for a CCV. If it does, the browser dialog opens. 2) It actually charges $1 per CCV check to verify the credit card. 3) If the CCV check is successful, it does the autofill on the form. However, you still have to enter the CCV in the form manually most of the time. 4) The $1 charge is immediately canceled and thus doesn't affect your account balance. For reference, here's a screenshot of how my bank receives such a charge: http://imgur.com/qwdM9Jx.png http://imgur.com/qwdM9Jx.png To be clear, this is not from any Google purchase. That's what happens if I use my CC in Chrome on any site. It also has to be noted that this implementation is pretty bad. On pre-paid CC (i.e. your CC payments are directly tied to your bank account - there is no CC bill), this will negatively impact your spending balance: Account balance: All your money. Spending balance: (account balance) - (pending charges) Some banks refuse to apply the charge cancellation sent by Google and keep the pending charge active for some fixed amount of time (e.g. 90 days).
- danielweber 10y agoChrome isn't a credit card vendor. I can save your credit card number for you too, if you want.
- adblair 10y agoMy understanding was that Google doesn't store your CVV anywhere, which is why you need to enter it every time. When you do so, it attempts to charge you zero units of your preferred currency (or perhaps it gives you zero, not sure) and if the transaction succeeds it accepts the CVV as valid.
- minxomat 10y agoThe CCV check Chrome does doesn't compare the entered CCV against anything stored at all. Instead, it charges a small amount to verify the credit card. See my comment below. Your mileage my vary, but I'd be very surprised if it does.
- stevarino 10y agoThis requires the browser to recognize it as a credit card field. Suppose a form uses a non-standard name for the field (say a localized name), and a user enters it at a legitimate site. Any attacker simply has to find these non-standard names for auto-complete to fill this in. I feel like I've seen a credit card autofill before outside of normal controls.
- jazoom 10y agoBut then the browser won't autofill it, so what's the problem?
- sharkoz 10y agoIt will if the attacker uses the same custom name for his field. The attacker could try to suck as much data as possible by creating thousands of hidden fields having a lot of possible combinations for the names of these non-standard CC fields, and wait to get lucky.
- tomcorrigan 10y agoWhy would I even care about credit card information being stolen. My bank will reimburse that no questions asked. I am much more concerned about my personal information being leaked. CC fraud costs other people money, identity fraud is much more damaging to me.
- error54 10y agoFor many people living paycheck to paycheck, someone cleaning out their bank account would be quite harmful. Yes, the banks will reimburse them but that could take up to a week if not more. In the meantime when your rent and utility checks bounce, you could be in an extremely uncomfortable position.
- tyingq 10y agoChrome does autofill CC info based on just a name if you want. It does give the user a visual cue as to what might happen http://i.imgur.com/2bY2Pes.png http://i.imgur.com/2bY2Pes.png You might catch some careless people with it though: https://jsfiddle.net/hvs4ox2q/4/ https://jsfiddle.net/hvs4ox2q/4/