8 ms·
What annoys me is the expiry date and CVV. It seems like their solution to "more secure" is just to add more numbers. How about put the last 3 digits on the bac
by digler999 10y ago
What annoys me is the expiry date and CVV. It seems like their solution to "more secure" is just to add more numbers. How about put the last 3 digits on the back, and call it the cvv ? How about use alphanumeric card numbers so we dont have to use as many digits ? Get rid of the expiry date used as validation. It's just more entropy, if you need more entropy then add another digit. It's just annoying having to type that crap in all the time.
- azm1 10y agonever thought of this.Simpyfying the number system would be beneficial for the consumer but also for the companies who make money out of this CC system
- Y_Y 10y agoTo play devil's advocate, it may be useful to know when the card expires for a merchant who mightn't charge immediately. And maybe it's significant that the cvv is on the back so you couldn't just use a photo. And mixing letters and numbers is scary. But I agree. Maybe the solution is just having lots of entropy and reading it electronically, who really needs to read out card numbers over the phone?
- digler999 10y agoI agree, keep the exp date, just dont use it to validate the transaction so I dont have to fumble with the keyboard and mouse to select stupid dropdown boxes. Let the server handle the case where the card expires tomorrow. I agree the CVV should be on the back, so just take the 3 numbers off the front and put them on the back.
- leejo 10y ago> if you need more entropy then add another digit. That would break so much as most of the message formats and batch files use fixed width fields. It's probably the same for the databases underneath. Changing to alphanumerics sounds nice but the check digit algorithm would have to change from Luhn to Luhn mod n. More breaking changes. Banking systems are one of the ultimate forms of legacy, which is why most of the security additions have been bolted on. Just look at 3D secure - they added an entire subsection to the message format and it was still just another single factor auth method that nobody wanted and everybody hated.
- digler999 10y ago> but the check digit algorithm would have to change or just get rid of it. It was a relic from 20+ years ago when networks and computers were 1/100th the speed they are today. Let them enter invalid numbers. Let the server return an error (as it already does)
- rlucas 10y agoSimilarly, once we did away with legacy electromechanical phone switches, the (phone area code) NANPA started allowing area codes with non-[0,1] middle digits. The big form of 10-digit numbers was retained and extended by relaxing a legacy constraint.
- avar 10y agoThe check digit gets used today by e.g. JavaScript in input forms to indicate a typo in the card number.
- IanCal 10y agoExpiry date: It checks that you're not using an old card that someone has just thrown away, often card numbers remain the same if you get a new one. This is effectively just specifying the version of the card, and is something that needs to be on cards anyway (so the user knows when they're no longer valid). Additional benefit is that it means your customer has just checked that their card is still valid. CVV: Not sure why it's on the back, but the point of this is that it's a number that's not raised, so it's not recorded when using a credit card imprinter (less common than is used now).
- mseebach 10y agoThat doesn't seem convincing, for the expiry. The issuer needs to keep track of cancelled cards anyway, and they should be cancelling expired cards anyway - it seems like a huge security hole to keep expired cards in an active state and rely on an expiry date check to reject transactions. I assumed that it's a leftover from early days, before online card checks, so the merchant can check that the card is still valid (besides checking signature and ID or whatever). When introducing online checks of the magnetic swipe, expiry date was part of the data transmitted, and early phone/Internet payment systems relied on reconstructing the data present on the magnetic strip, to "fake" a swipe. Then it just stuck from there.
- IanCal 10y agoExpired cards and active cards generally have the same card number. I've certainly had multiple cards with the same long number across them. If you have to write the expiry date on anyway then why not use it?
- rconti 10y agoWait, I thought the expiration date was just theoretical. Nobody keeps the same card number that long without having the card compromised, do they? :)
- theandrewbailey 10y ago
- nodesocket 10y agoI think we can all agree the correct model is a card that generates a globally unique card number for each and every transaction (e.g. coin failed, final). It should also have a 2nd factor authorization like CVV which is not embedded in the magnetic strip (can't be read by swipers).
- jdmichal 10y agoWhich is (roughly) exactly how EMV chips work. Crypographic challenges that result in unique tokens for every transaction.
- Nullabillity 10y agoOf course, EMV is still a broken piece of crap, because the signer can't actually verify the transaction being signed.
- lewiseason 10y agoPlus, you still have to support plaintext between the EMV chip and the reader. This opens an entirely new class of places to steal card details (like PINs)
- PeterisP 10y agoRecurring billing is a major feature of credit cards that some merchants find very important.
- nickpsecurity 10y agoThe first part is basically what Final claims to be doing: https://getfinal.com/ https://getfinal.com/
- discreditable 10y agoI have a Final card. You have three options: 1. Use your real card number. I never do this. 2. Use a merchant-locked card number. I use this commonly for online pizza and other online shops I don't trust much. Once a merchant uses it, only that merchant can use it. 3. Use a one-time card. The number is used once and disabled. Good for one-off orders or skeezy purchases. Overall I've been pretty pleased. I think the idea that card numbers should be disposable is awesome.
- pjc50 10y agoCVV is not just more entropy, it's handled differently: https://randomoracle.wordpress.com/2012/08/25/cvv1-cvv2-cvv3-demystifying-credit-card-data-12/ https://randomoracle.wordpress.com/2012/08/25/cvv1-cvv2-cvv3... The whole point is that you can't skim the CVV2 from the magnetic data and then use it to make purchase.
- _delirium 10y agoIn addition to not being on the magnetic stripe, merchants are also not allowed to save it, so if you steal a merchant's database of stored CCs, you don't get the CVVs.
- rlucas 10y agoThat probably works approximately as well as how merchants weren't allowed to store the cc number itself.
- theWatcher37 10y agoRequiring CVV's for online transactions invalidates this security feature.
- pjc50 10y agoNo, that's what the CVV is for. It's only for card-not-present online transactions. (Yes, there are probably a lot of retailers breaching their PCI-DSS compliance by storing the CVV, but the point is they're not supposed to. Until we can do chip-and-pin or similar for online purchases, e.g. Apple Pay, the problem remains)