21 ms·
The underground world of credit card network exploitation
- Faaak 3y agoIsn't this solved with 3-D Secure ? Many websites (at least in the EU) implement it and if mandatory, it's impossible to buy something without 2FA (either by SMS, phone app, ...)
- alsodumb 3y agoThat’s not the case in US. It’s kinda funny, but the only time Chase and Amex credit cards asked me for 2FA (I didn’t even know they had 2FA) was when I used them to purchase some things in Indian website through local payment provider (Razorpay).
- lotsofpulp 3y agoI have seen it multiple times at BestBuy.com and HomeDepot.com, and probably others.
- bonzini 3y ago"banks (usually American ones) will happily accept transactions that have incorrect full name, invalid CVV / CVC, wrong expiration date, only partial billing address provided, with incorrect ZIP code. All of the above is still not enough to trigger a 3D secure authorisation" The solution indeed is to write manual rules to trigger 3D secure.
- selimthegrim 3y agoI’ve seen verified by visa triggered a few times for online purchases
- __MatrixMan__ 3y ago... Which is hell if you're in a country where your sim card doesn't work and your bank requires sms 2fa.
- alexvoda 3y agoThen it's a good thing that many banks in the EU now have 3DSecure validation through the phone app instead of SMS
- Detrytus 3y agoWhat if you lose your phone? In my country banks only allow you to use one phone for mobile authorization, so you can't even have a backup phone. I really wish 3DSecure was optional so I can turn it of when going to foreign vacation.
- pas 3y agoOn a vacation I have my card (and can use PIN auth), the issue is usually online transactions ("card not present", ie. vPOS transactions).
- iggldiggl 3y ago… and it already brings us halfway to the point where you can't buy a new phone if you don't have a phone already.
- ec109685 3y agoI hardly use an iPad, but take it with me for this reason.
- orangepurple 3y agoMy US bank requires SMS 2FA and SMS works for free because I am connected to Wifi. I have VoWiFi enabled. My US phone plan is with a budget carrier I only pay $15 a month for voice, sms, and data.
- radicality 3y agoEven more funny is that in USA, the actual amount charged to the card is mutable. Take for example when you go to a restaurant and give your card, it's charged, and then you write out with a pen a tip amount, which at some future point gets added on to your charge.
- Detrytus 3y agoBut there are laws about that: you authorize tip with your signature, if they charge you more than you authorized, they can get in trouble. Don't see the issue here.
- zer0x4d 3y agoThe author is wrong about this. Banks don't choose to accept incorrect name, invalid CVC, invalid exp date or wrong billing address. It's up to the user (in this case him) to enable CVC Check and AVS in his payment processor to fail payments that don't pass this check. It's also up to him/Stripe to implement 3D secure and trigger it. https://stripe.com/docs/disputes/prevention/verification#cvc-check https://stripe.com/docs/disputes/prevention/verification#cvc...
- zaroth 3y agoFrom your link; “Radar includes a rule to block any payments that fail the CVC verification check, which you can enable or disable within the Dashboard (this doesn’t affect payments where the CVC check couldn’t be performed).” Also; “…Support for both types of AVS checks varies by country and card issuer (for example, certain countries don’t use a postal code or some card issuers don’t support street address verification)” So it appears there are cases where these checks can be enabled on your Dashboard, but skipped by Stripe or not actually performed by the issuer, I’m thinking like for prepaid cards?
- swarnie 3y agoWe're talking about an industry who proudly announced instant bank to bank payments last week like 2003 has just arrived in the colonises. Don't expect speed or creativity in the US banking sector.
- dahwolf 3y agoEnabling 3-D secure on all transactions leads to lower conversion rates, therefore typically a hybrid model is used where its enabled/disabled per transaction whether it is needed based on a risk score.
- myself248 3y agoWhy does the US still accept hand-typed cards? My friend had a USB smartcard reader in like 2001. He'd dip his AmEx to perform a transaction on his PC. It's twenty years later and the industry still hasn't caught up? What's different about Europe that they seem to have figured this out decades ago?
- mschuster91 3y ago> What's different about Europe that they seem to have figured this out decades ago? Our governments actually care about monopolies and security. The PSD2 directive was an utter pain to deal with, but at least it stopped a lot of common scams and thefts in its tracks, and it forced banks and other payment actors to open up their system.
- TacticalCoder 3y ago> The PSD2 directive was an utter pain to deal with, but at least it stopped a lot of common scams and thefts in its tracks Inded. More specifically SCA (Strong Customer Authentication) which is required by PSD2. VISA says the "SYH" (Something You Have) is either "a mobile phone, a card reader or other device evidenced by a one-time passcode". Note however that I cannot log nowadays to any of my bank in the EU without having a big banner saying something like (paraphrasing): "WARNING: scammers are trying to steal your funds. Neither the bank nor the police nor anyone else shall ask you your PIN or to confirm anything on your card reader." Basically: life is harder for scammers so they try to trick (mostly old) people into validating transactions over the phone.
- paxys 3y agoNot sure I understand. Does everyone outside the US have a card reader attached to their PC and phone?
- fireflash38 3y agoMost people have an NFC reader at least built into their phone.
- 3y ago
- thedangler 3y agoI worked at a company who's server was hacked and they stole the API keys and did carding on it from the server. Paypal tried to tell us we owned them $100,000.00 in fees. We were only running $4500.00 payments at most 5 times a day for course registrations. The hacker ran auths on random CC number for $1 every second. We didn't have to pay the fees for carding but they don't care. They do not care because they make money off fraud. We had settings stating we only have orders between $2500 and $6000. But they do not check auths lol Crazy. This was back around 2010 and stripe was not available in Canada at the time.
- chasebank 3y agoRe: Chargeback fees - Visa acquired a company called Verifi a few years back. Their new products are Rapid Dispute Resolution (RDR) and Order Insight. RDR effectively lets you automatically refund a transaction before it gets turned into a chargeback and Visa charges a $4 fee (Assuming your MCC code is not high risk). Order insight lets you provide certain data about a questioned charge immediately and if the customer has had 3 previous charges with you, a chargeback CANNOT be issued. It was a really easy decision for our business based on win rate, avg order size and chargeback fees. Plus now we don't have to constantly worry about Visa's or the merchant bank's 1% chargeback rule. This only applies to Visa charges but it represented about 50% of our total volume. One last note - Visa is basically taking away a massive revenue source for the processors. If your processor is TSYS, they are trying to charge a RDR fee of $10.
- pimpl 3y agoArticle author here. Really valuable stuff, thanks for sharing! Do you handle this for Mastercard in any way? I've heard of Ethoca (they are really good at SEO), it seems quite similar to Verifi.
- chasebank 3y agoYa, for Mastercard we use their Ethoca network. They are much more expensive, like $25 per resolved charge but now our chargeback rate is near 0% for Visa / MC and get incredible rates on the front end from such clean processing. Plus we never have to worry about chargebacks threatening our merchant account again.
- kareemc 3y ago[dead]
- spetteruti 3y agoWhat do you do for Amex/Discover?
- 3y ago
- paxys 3y agoIf you are a foreign company accepting payments from the USA, you should simply expect this as a cost of doing business. Credit card fraud here is socialized. The end consumer is never liable, and so we don't bother with chip and pin, 2FA, 3D secure or whatever else. If we notice a suspicious transaction we simply tap a button in the bank's app and the charge is reversed in minutes. Banks and payments processors are themselves incentivized to push through transactions as quickly and easily as possible so people spend more (yay consumerism!), and like the author said you mostly don't even need to input the right expiry date, billing address or zip code. The drawback of course is that all of the liability is pushed on to the business, and so they have to raise prices for everyone to make up for it.
- notyourwork 3y agoI'm not sure how much extra I pay but the hassle free peace of mind I have seems worth it.
- vladms 3y ago"Hassle free peace of mind" meaning you do not need to remember a 4 digit code (or clicking "yes" in a phone app), while you need to check your credit card transaction list regularly to reject fraudulent transactions? I find the effort of remembering the 4 digit code/having the phone much smaller than the alternative ...
- Invictus0 3y agoI think OP is talking about never being liable for fraud
- acdha 3y agoI’ve never had a card stolen where either of those would have helped - they’re stopgaps trying to avoid upgrading the banking system to use public-key encryption with reuse protection. A couple of times, merchants with my card on file were compromised. The thief could make charges because the merchant had to be able to as well. What would have stopped that would have been having a way to restrict a charge to a particular merchant so the attacker couldn’t have been able to get the money out. Once, my supermarket had skimmers. A code wouldn’t have been effective unless you were very good at spotting where the thieves planted cameras, too. An active MFA prompt would help against attacks at a substantially later time but it’d have to include the merchant name in an unspoofable form to prevent real-time attacks so I wouldn’t be asked to approve charges from SAFEWAY_, and that old-fashioned style of MFA is painful: it’d always make checkout slower and you’d have some fraction of people who don’t have phones with them or just ran out of battery. What completely solved this problem for me was the modern tap systems (ApplePay). It requires more smarts on the client but means that I have to approve each transaction and the value the card reader gets can’t be used anywhere else.
- appplication 3y agoWhat was most surprising about this is not the fact that there is a group of people exploiting Stripe’s payments, but that the author had ChatGPT write a script to automatically handle payments processing, specifically for chargebacks. And based on the context in the article, the author sounds like they lacked the technical skill to write or validate these scripts themselves. This author is jumping out of the frying pan and into the fire. ChatGPT is cool and all, but the fact that they’re trusting it to write critical code for handling their customers money speaks volumes. They’re incredulous at how they feel Stripe violated their trust in it to manage fraud, but then go ahead and blindly place it in another technology they don’t understand. The problem isn’t Stripe (though, yes, they should fix this), it’s the fact that they are just giving away trust and hoping for the best.
- pimpl 3y agoArticle author here. I carefully reviewed and tested the ChatGPT scripts before executing them. It helped me save a lot of time manually writing these scripts! I wouldn't say I lack technical expertise in this area, I'm just trying to use my time as efficiently as possible.
- BaseballPhysics 3y agoGenuinely curious: How much time would you say you saved prompting for and then carefully reviewing and testing those scripts for bugs, versus writing them yourself? And for context what's the average line count we're talking about here? Tens of lines? Hundreds?
- pimpl 3y agoI'd estimate it that it saved me a couple of hours tops. They were simple, self-contained scripts with at most 150 LOC.
- BaseballPhysics 3y agoInteresting! Thanks for the insight!
- _feus 3y agoUsually these transactions are automated with the checkers. Some are as simple as a PHP script replaying a request, some are more sophisticated that use residential proxies, some are parts of huge enterprises like try2check. If you have a list of IPs, you can scan them for 80/443 open and sometimes catch simple checkers in action.
- nickdothutton 3y agoI’ve always found it incredible that US banks often require only the card number to perform a transaction. All those “card generators” I used to see uploaded to BBS in the late 80s and early 90s make sense.
- deathanatos 3y agoThat part of the article was news to me. Like, why do I have to deal with CVVs, expiration dates, zip codes, (not to mention the resulting work from the fallout from the fraud) … if it doesn't even matter? How many person years of human life per year could pursue something … worthwhile … if we checked the CVV?
- cesarb 3y agoIt makes sense to me that zip codes don't matter (or might be a weak signal), since some countries might not have postal codes, or might have a different postal code format. But I agree with you that it doesn't make sense to not check the CVV and expiration date; both are printed directly in the card, and should match exactly (unlike the card owner name, which is also printed in the card, but the user might type it differently, for instance typing in full their middle name when it's abbreviated in the card).
- nitwit005 3y agoHaven't dealt with credit cards, but people often have the zip code wrong on their address. The mail gets delivered if the rest of the information is correct. I assume that makes it hard to be strict about zip code.
- zaroth 3y agoI don’t understand not checking CVV and Expiration Date at all… But for the other info, they could be carding for prepaid cards which have no name, address, or ZIP code to verify against?
- deathanatos 3y ago
- nerdawson 3y agoWhy does the US seem so far behind when it comes to banking? - Chip and PIN has been in the UK since 2004 and mandatory since 2006. It wasn't until a decade later that the US caught up. - Faster Payments allow for instant bank transfers (usually) between any bank account for free. Receiving transfers from clients in US (even with a US Wise bank account) was always a nightmare. - Since the EU introduced Strong Customer Authentication, most new payments have to be authorised in your mobile banking app or by some other means of 2FA. - Even before SCA, you'd have to get the Postcode (often digits that mattered) and CVV correct at the very least. These measures seem like a way of banks shifting the responsibility for fraud onto the customer. In either case though, it's the customer who loses out. In a culture that accepts widespread card fraud, costs increase to offset it.
- arjvik 3y agoWe have 3D Secure, but it's almost never implemented on sites!
- _puk 3y agoDefine "We". With a UK card pretty much any transaction I do online requires me to Auth it in app. I even found I had to do it recently for things like car hire, and those websites are generally just wrappers around local company searches (though higher sums overall).
- BaseballPhysics 3y agoA massively diverse and deregulated banking sector. The US has literally thousands of small regional banks across 50 fairly independent states. Rolling out major new technologies in that environment is far far harder.
- cubefox 3y agoThe number of banks in the US seems perfectly normal. Germany has ~1500 for 80 million inhabitants, the US has ~4800 for 300 million.
- thierryzoller 3y agoWhat strikes me is the comment on 3DS challenges that passed. By law in Europe, once 3DS challenge is completed the Bank owns the risk and cost of the chargeback NOT the Online Shop. Can someone tell me how this is implemented in common processors ? Any experience?
- kareemc 3y agoIn my experience, Stripe used to be a lot better at catching this stuff - but I've noticed it's seem to have been getting worse and worse. Has Stripe Radar improvements slowed down or have fraudsters gotten better?
- zitterbewegung 3y agoCandyjapan has a good write up on mitigating this https://www.candyjapan.com/behind-the-scenes/how-i-got-credit-card-fraud-somewhat-under-control https://www.candyjapan.com/behind-the-scenes/how-i-got-credi...
- pimpl 3y agoReally interesting, thanks for sharing!
- bze12 3y agoSome advice I got a while ago about detecting fraud through stripe is you should probably train your own fraud detection model if you’re serious about limiting it and have enough volume. Even something like a simple logistic classifier would work. Stripe radar isn’t tuned to the specifics of your business, and there are other signals you can account for (like which products they’re buying, how long it takes them to buy after opening your site, etc). Custom Radar rules work to an extent. I get that a lot of indie businesses probably don’t have the resources/want to do this, so there are solutions you can buy, but they’re expensive and mostly targeted at high volume merchants anyway. Maybe stripe launches a fine-tunable radar product someday?
- xyst 3y agoYet another reason why the credit card industry needs to go. Security protocols non-existent or haven't been upgraded since the turn of the 21st century. The amount of middleman abuses is innumerable as well. The costs of dealing with these nuisances is passed on to the merchant (via higher transaction fees, charge back fees, ...), and inevitably passed on to the consumer. Let's not forget that the CC industry encourages the worst spending habits for consumers thus perpetuating the never ending cycle of slaves to debt.
- tamimio 3y agoCredit cards payments are exactly just like SMS 2FA, both are insecure by design and served the purpose before the internet, trying to shove old tech into new one and expecting it to work well is just naive. Instead of spending time and resources by big corporations to create such “web environment integrity”, how about creating a better more secure, fraudulent proof system instead?
- codedokode 3y agoIt is ridiculous that you can simply enter somebody's card number and buy something without confirming a purchase via SMS code.
- mrguyorama 3y agoStripe is god awful at fraud prevention and it's intentional. They are explicitly outsourcing the cost of risk management to their clients. It's obscene. I work in the credit card fraud prevention field, and I'm not even that good at my job, but our team of like 3.5 people easily built and maintained a system that prevents this exact kind of carding attack. The primary way for a business to prevent carding attacks is to just be slightly more annoying to attack than the next guy. As far as I can tell, Stripe is happy to be the easiest large network to attack because they outsource the pain and cost of any attack to you, their users. They could easily, and for very little cost, prevent this from hurting you. Stripe is choosing to let you suffer to save a few bucks.
- KRAKRISMOTT 3y agoThey want to nickel and dime you and make you pay for Radar. It's the exact same strategy with Stripe Taxes and their terrible currency conversions. Provide no service up front and eventually you realize your stripe transaction hits two digit percentage of your overall price.
- johnsimer 3y agoWhat do you recommend as an alternative to stripe?
- KRAKRISMOTT 3y agoYou pool your payment providers using something like https://hyperswitch.io https://hyperswitch.io
- chasebank 3y agoAny suggestion for a crm that’s integrated to a platform like hyper switch? What’s the difference between them and spreedly?
- chinathrow 3y agoAnd pay another provider?
- 90K_MRR_Hacker 3y agoI've been using a platform called Chargeblast.io and it's been doing wonders; literally saved my business from closing down. I haven't found another platform like it - best price, best value
- pard68 3y agoWorked as the catch-all systems/CI/infrastructure/software engineer for an ecommerce company last year. This sort of stuff was so common. I'd spend at least one day a week trying to determine the newest pattern and prevent it. They were using our system to validate credit cards. Eventually I stopped more or less all attacks on our cart/checkout. But the requests were still coming. Eventually while trolling logs for an unrelated PHP problem one of the software engineers mentioned there was a huge amount of traffic hitting our page to save a payment for later. The platform would issue a $1.00 charge to verify that the CC was real and they'd moved to using that to "churn" cards. These CC thieves are very resourceful.
- Scoundreller 3y ago> We learnt that 15% of the successful fraudulent charges resulted in chargebacks. I Hope the other 85% are just recent transactions that haven’t been scrutinized yet. Or did the fraudsters target a bank with high net worth clients that don’t scrutinize smaller billings??? I can see a lot of people not really scrutinizing a random Spotify transaction or something. Especially vendors that let you store multiple cards and then you don’t always keep it straight which transaction went to which card anyway.
- edwinwee 3y ago(Edwin from Stripe here.) Worth noting this is copypasta from an older post from a month ago (https://piotrmierzejewski.com/p/card-networks-exploitation https://piotrmierzejewski.com/p/card-networks-exploitation). We've fixed most of these issues since then. This type of card testing has dwindled—Radar should now be catching these types of attacks. On the chargeback point—we hate chargebacks too and we want to limit them as much as possible (we're actually working on a few things over here that we think will help with this). The banks levy chargeback fees (in varying amounts) and an average of them show in the form of a $20 fee—it's not a Stripe-specific fee and we don't profit from chargebacks. We've just finished company planning for the rest of the year and reducing this type of fraud is a top priority. So if you think you're seeing something similar, please email me at edwin@stripe.com.
- chinathrow 3y ago> Radar should now be catching these types of attacks. No, your base offering should catch these. Sincerely, a customer of yours.
- edwinwee 3y agoRadar is included for free in the base offering.
- chinathrow 3y agoMy bad, I mixed that up with Radar for fraud teams.
- mndgs 3y agoThe contents of the article do not match with the title. Article is how they experienced and fought chargebacks. Simple, nothing spectacular. Stop whining, have the US adopt PSD2 (SCA in particular) and your problems will go (most of them)..
- bigbacaloa 3y agoAs an end user of banks in both the US and EU, the banks in the US seem way, way behind technically and in terms of online usability. Both less secure and more cumbersome to use.
- jon_adler 3y agoI imagine that the fraud rate in Europe is lower since the introduction of PSD2. This legislation required a combination of 2-factor authentication (3DS2) and transaction analysis to achieve low overall fraud rates.
- alberth 3y agoOff topic: Why don’t more non-European merchants use 3DS? Entirely classes of liability and fraud is shifted to the issuer and no longer on the merchant.
- rowls66 3y agoCustomer friction at checkout. The more difficult a merchant makes the checkout process the more likely customers are to abandon the checkout. Some of those abandoned checkouts are fraudsters, but other are legitimate customers who don't want to deal with the hassle. It is up to the merchant to decide how to weigh fraud against lost sales.
- cryptoegorophy 3y agoPro tip. Get ekata. All of this could’ve been avoided. Another pro tip - get 3dsecure to work all the time. If not - ekata that transaction.
- cryptoegorophy 3y agoAlso this is one the reasons why i absolutely love PayPal. It gets a lot of hate but i never lose any chargebacks.
- Ubergeek99 3y agoCloudflare has tools to prevent too many form submits. You can specify which page, how many submits and so on. I found out about this when I had a problem of somebody running a script of trying different credit cards over a two hour window. My payment processor told me I should prevent these types of things. So I investigated and never had this problem anymore. Cloudflare is amazing at preventing all kinds of attacks. I love Cloudflare.
- newusertoday 3y agoare you using cloudflare workers for this? i don't see any tool for form submission and rate limiting in cf. Can you elaborate what tool are you using?
- kentonv 3y agohttps://developers.cloudflare.com/waf/rate-limiting-rules/ https://developers.cloudflare.com/waf/rate-limiting-rules/ maybe?
- Sxubas 3y agoI worked at a credit card network company some years ago and thought the article mentioned an exploit on the actual network. It is instead a showcase on how mediocre issuers can be when authorizing transactions, and how non-sensical the system has become that the merchant ends up paying the price for chargebacks.
- EconomicsDense 3y ago[dead]