7 ms·
> With their consent, I had entered the rider’s credit card information—data that is often easy to buy from criminal marketplaces
by chrisbolt 3y ago
> With their consent, I had entered the rider’s credit card information—data that is often easy to buy from criminal marketplaces
- netsharc 3y agoAt first I do think this site is being sensationalist again (3rd story from 404media I've seen on HN lately), but for the stereotypical guy meets girl, guy stalks girl, storyline: I can imagine a guy working in a store seeing a girl he finds attractive, getting her CC number through some sleight of hand while she was paying, or something like a camera pointed at the payment machine, and then using this number to figure out what station she usually gets off on at what time in the evening. I wonder what protection can be built in. An online CC transaction needs the exp. date, CVV and ZIP of the customer, could OMNY ask for these values before showing people the ride data associated with the card? The people might be wary "wait, what are they making me buy?", but maybe a big fat warning that they just need this info "for your protection" is sufficient... Then again, those values are also easy to buy from "criminal marketplaces", and the guy above can just tell the girl that the store is doing a survey where their customers live, and what her ZIP is (the other info are on the card he took a good peek at)
- J_tt 3y agoIt’d be great if they could trigger 3D-Secure without a purchase, but that would probably be a whole mess to work out. Edit: looks like it might be in the spec from some very brief research, or at least “coming soon”: https://3dsecure2.com/non-payment-authentication/ https://3dsecure2.com/non-payment-authentication/