4 ms·
Do you know how they detect virtual cards? I have seen some scripts which detect whether card number is valid CC or not. But never heard of validation of virtua
by codecutter 6y ago
Do you know how they detect virtual cards? I have seen some scripts which detect whether card number is valid CC or not. But never heard of validation of virtual cards.
- segmondy 6y agoThe first 4-6 digits of cards are called BIN (Bank Identification Numbers). Every bank has there own. So if you started your own company called codecutter virtual cards. You will have to get a BIN from Visa & Mastercard. Say your BIN is 5123-45 then all the cards you issue will begin with 5123-45. Anyone in the industry can obtain a list of all who owns' all BINs and the type of cards is it. Gift card, virtual card, credit card, debit card, etc.
- lukevp 6y agoCard numbers all come from BIN ranges, most likely these virtual cards are all issued within some specific BIN ranges (meaning you can tell them apart based on a certain # of prefix digits).
- judge2020 6y agoIt's not inherit to the card, rather it's pulled via info from the card network (visa/mc/amex/etc). Stripe, for example, returns `card.funding` which is either credit, debit, prepaid, or unknown - blocking anything other than credit or debit isn't bad for SaaS businesses who doesn't want prepaid cards anyways[0]. Outside of that, you can use the IIN/BIN (first 6 digits) to build a blocklist of virtual-card-issuing banks[1]. 0: https://stripe.com/docs/api/payment_methods/object#payment_method_object-card-funding https://stripe.com/docs/api/payment_methods/object#payment_m... 1: https://developers.braintreepayments.com/reference/response/credit-card/ruby#issuing_bank https://developers.braintreepayments.com/reference/response/...
- dvfjsdhgfv 6y ago> blocking anything other than credit or debit isn't bad for SaaS businesses who doesn't want prepaid cards anyways It's not clear to me what you mean here: do you suggest SaaS businesses should reject those customers who prefer paying with prepaid cards? Hello, this is me! When I see a prepayment option or even Paypal, I gladly pay, but when you want my credit card info, I wave you good bye!
- duskwuff 6y ago> do you suggest SaaS businesses should reject those customers who prefer paying with prepaid cards Not the parent, but: yes, absolutely. Prepaid cards are for making one-time payments. They are not suitable for setting up ongoing subscriptions, and it is entirely appropriate for a merchant to reject them in this context.
- dvfjsdhgfv 6y ago> Prepaid cards are for making one-time payments. They are not suitable for setting up ongoing subscriptions Why? Because from the point of the view of the customer, they are the best fit for that purpose.
- duskwuff 6y ago> Because from the point of the view of the customer From the point of view of a legitimate customer who intends to pay for a service, a prepaid card is a poor fit for an ongoing subscription, as it will stop working unpredictably when its funds are exhausted (causing it to start rejecting all charges). Optimizing for customers who intend to ditch a service without paying for it is not a goal.
- dvfjsdhgfv 6y agoI'm sorry, but this makes no sense at all. The only difference between these two scenarios is who is in a position of power. If I use a prepaid card, it's not because I intend to ditch a service, but to control the costs. A simple example of one of the services I use, Mailerlite. When the funds are depleted, I receive an email from them they were unable to charge me this month and they downgraded me to their free plan, and they will try again in two days. I then charge my card, they charge me and everything is fine. You don't want people like me - fine, you will have less customers. And I'm a very loyal customer, cases like failed payment happen maybe once 2-3 years.