3 ms·
Slightly tangential question but why is credit card security so weak in the first place? I mean all we need is 16 digits of card number, 4 digits of expiry date
by mapreduce 3y ago
Slightly tangential question but why is credit card security so weak in the first place? I mean all we need is 16 digits of card number, 4 digits of expiry date and 3 digits of CVV. The 23 digits can leak from so many places.
In this day why don't the credit card payment systems require multi-factor authentication for online payments? Why don't payment machines challenge you for PIN for payments?
- Gare 3y agoSimple: because it adds friction, and the optional amount of fraud is not zero. https://www.bitsaboutmoney.com/archive/optimal-amount-of-fraud/ https://www.bitsaboutmoney.com/archive/optimal-amount-of-fra...
- deleted 3y ago[deleted]
- deleted 3y ago[deleted]
- mcv 3y agoEvery time this comes up, people claim that this lack of security doesn't matter because it's easy to reverse these payments. But if that's true, then why is the woman so upset and why is Barker handled so aggressively? It should be easy to revert both payments.
- rootusrootus 3y agoThis case is probably not a great example to use, because the woman's card wasn't stolen. Her account at Walmart was hacked, and the purchase was made there with the shipment sent to a different address.
- mcv 3y agoWhy would that not make it a good example? It's still a case of fraud, enabled by the lack of security on credit card payments. The payment hadn't been authorised by the woman.
- JaggedJax 3y agoThis looks like an easy thing for Walmart to prevent if they bothered. On Amazon if you add a new shipping address, you can't ship to it until you re-verify your credit card CVV. With just that simple check this attack would be blocked (unless they steal the entire CC info of course).
- deleted 3y ago[deleted]
- everybodyknows 3y agoThat's a question for Amazon, which makes the whole thing possible by: 1. Lulling naive or hurried customers who like to think they're buying "from Amazon" into buying from fraudsters, and 2. Paying the fraudsters so quickly that the seller's account is closed before action is taken the fraud, and 3. Vetting sellers so promiscuously that the individual fraudster's cycle can continue. In this light, Krebs diagram is deficient, because it omits Amazon from the loop. It's not "triangulation", the more accurate word would be quadrilateralization -- but spell-check says that's not a word.
- zerbinxx 3y agoThe woman was presumably upset because she thought she was scammed and had caught the scammer red-handed, and probably didn’t fully understand how credit disputes happen, or had some extenuating circumstances (poor credit, no credit) that she was actively trying to fix by having a CC only to get defrauded (although I don’t think credit fixes actually affect your credit score). It’s safe to assume the average person doesn’t really understand credit.
- rootusrootus 3y agoNit: you also need the five digit zip code
- toast0 3y agoAddress verification is optional. Depending on your merchant account, you can request address verification for a customer, and you may get a lower discount rate with correct address information. But you can also run charges without it.
- BobaFloutist 3y agoThat's the idea with the expiry date, and the CVV, and the zip code. The problem is, it doesn't seem possible to convince businesses not to hold on to whatever security info is required to charge the card in plain text, so whatever the relevant details are inevitably get leaked from some hotel or eCommerce giant that really shouldn't have them in the first place, but hasn't set up a way to securely verify credentials with the bank without literally recording them. You can keep adding on additional pieces of bullshit information customers need to remember all you want, none of it will matter as long as banks and credit card companies don't force businesses to treat them as actually sensitive information.
- mainde 3y agoI think that enforcing what you're suggesting is incredibly hard and I don't think can scale, it's what PCI-DSS and similar are meant to tackle, it really doesn't work in my experience. This is a protocol/product problem, it's wild that to make a payment all the crown jewels need to be put on the wire. It's about time that payment devices and the whole ecosystem adopts some sensible cryptography that, at minimum allows signing payment requests, and ideally keeps its keys private. Although this whole problem is kind of already solved by 3DS2, albeit not in a great way.
- markus92 3y agoIn the EU it’s not uncommon to have some 2FA. My bank asks me to confirm online CC purchases all the time on their app with 3D secure.
- bpye 3y agoThis is also true for me in Canada. I often get an SMS based 2FA prompt…