6 ms·
Credit cards are vulnerable to brute force kind attacks
- sixtyj 5mo agoPeople should have a separate card for online payments and have just enough money on it for a payment. I know that I am naïve :) Back to the article: Weak point was a password that lead to another merchant not using 3D secure. It seems from the article that bad actors have fully automated system, so (big) merchants should have handle automatic login attempts from the same ip address with different accounts. I see it from our wordfence logs that ip rotation is not so quick so it could be handled with some permanent ip blocking.
- kodbraker 5mo agoI agree with the seperate card. That was my seperate card and luckily the amount was not quite big because of that. >Weak point was a password that lead to another merchant not using 3D secure Well leaking a password shouldn't cause leaking a whole ass credit card data imo. The same data is printed on physical receipts the markets print, sometimes 4 digits, sometimes 10 digits. It's still possible to brute force from unattended physical receipts on the market.
- mrbluecoat 5mo agoNot affiliated, but Capital One Eno virtual cards work well for this purpose.
- kadoban 5mo agoTbh, fraud for credit cards is covered by the bank, so I typically just don't care. I just check my statements for anything that looks off.
- stavros 5mo agoI think https://privacy.com https://privacy.com is the best solution we can have with the current system.
- Foofoobar12345 5mo agoMercury now offers personal bank accounts. You can create virtual debit cards just like companies can with Brex/Mercury/Ramp etc.
- psychoslave 5mo agoMy previous bank provided this virtual card service on demand. You create the card for a single purchase with a specific amount and that’s it. I moved to an other bank when getting an affordable mortgage loan became impossible in it for me.
- lxgr 5mo agoWhy should they, if they're not liable for any resulting fraud of the status quo?
- badgersnake 5mo agoOh okay, so this is why Amex launched the online card in the app that changes the Cvv2 every few minutes.
- dogma1138 5mo agoAmex was late to the party with virtual cards.
- majorchord 5mo agoNone of my banks or credit cards support them... not sure how widespread it really is.
- ranger_danger 5mo agoI had no idea amex offers virtual cards... but I looked everywhere in the app and cannot find any such option?
- kmoser 5mo agohttps://www.americanexpress.com/en-gb/services/ways-to-pay/digital-card/ https://www.americanexpress.com/en-gb/services/ways-to-pay/d...
- ranger_danger 5mo ago>We have invited a small pilot group to the Digital Card feature now. The feature will become available to more Cardmembers soon.
- fph 5mo ago3-digits? What is this, an OTP for ants?
- badgersnake 5mo agoAmex uses 4 but sure it ain’t a lot. Enough to stop this attach though.
- janalsncm 5mo agoAt least with a credit card you have some fraud protection. Report it and the charge should be reversed. And chargebacks are possible. With a debit card you’re playing with your own money.
- tptacek 5mo agoThat has not been my experience with debit cards in the US at major banks, at all, over decades. (I'm pathologically avoidant of credit cards, which I think are mostly pointless.)
- yladiz 5mo agoWhy do you think they’re pointless?
- tptacek 5mo agoFor most of my adult life I haven't been able to get a credit card --- even after we sold Matasano Security, with the proceeds of that acquisition sitting in a money market checking account at the giant bank I use, that bank would still only issue me a secured card. I pay my bills and all, but at some point when I was like 19 I bought a shirt at Nordstroms and they signed me up for a card and I didn't pay enough attention so I presumably still somehow owe them $40, and it wrecked my credit score. No part of my life has been harder for not having revolving credit. I had a family, with two kids, starting in my very early 20s; I have lived on ramen wages several times since then; I've bought houses, rented cars, all that stuff. There's really been no point I can think of where I felt like having a revolving credit card would have made any of it more manageable. I'd get points and stuff (I have a card now, it has a fuckload of points on it) but that's just an incentive to use the cards, not an intrinsic case for them. I think most people would be much better off just using debit cards, and operating with the funds they actually have. And, again: it is in fact easy for me to say that today, but I believed the same thing when I was younger. The crazy thing is coming to realize how little your credit score matters if you decide not to play this game. People say it will impact your ability to get a mortgage or a lease, but: not my experience!
- bediger4000 5mo agoSome have speculated that the entire credit card system is compromised, end to end. I think the real question is why NSA didn't intervene in the early 1990s. Online commerce was just beginning, and the importance of electronic funds transfer was obvious, but the method wasn't set in stone. NSA knew about public key crypto well before the rest of us did. They could have helped set up very secure electronic payments, but chose not to for unknown reasons.
- yieldcrv 5mo agoNSA prefers compromised security so that answers your question Credit card system was already around for decades before though
- fhdkweig 5mo agoI heard a rumor that NSA suggested changes to DES encryption that strengthened it from differential cryptanalysis attacks that the public cryptologists weren't aware of yet.
- plorkyeran 5mo agoThat isn't a rumor? It's a pretty well documented fact that the NSA was involved in the design of DES and that the magic numbers that people initially assumed were a back door of some sort turned out to make differential cryptanalysis more difficult than randomly chosen ones would have.
- jongjong 5mo agoReminds me of when I wrote a lightweight blockchain from scratch including the Lamport OTS (quantum resistant) signature scheme and then most of the leaders from my crypto community at the time turned against me for no reason. The signature scheme I implemented was thoroughly tested. Implemented from reading the Lamport and Merkel academic papers and under 1000 lines of code in total so pretty easy to audit... Nobody found an issue with it in 5 years. But the suppression was suspicious. The narrative of "Don't roll your own crypto" is suspicious... Is it really better to use the same library as hundreds of thousands of other projects? Is that really lower risk? Didn't we learn from the Axios hack that popularity doesn't provide security.
- amluto 5mo agoAnother mistake: > The data they took with the attempt of purchase is the card is still usable (not cancelled) The payment flows should not distinguish between a nonexistent card, a cancelled card, and a valid card that needs 3D Secure. I bet the banks could even implement that without any cooperation on the part of the merchants.
- gardenhedge 5mo agoWhy not debit cards too?
- J8K357R 5mo agoI once had a person that was hired by my company and then started bragging about finding a way to add stored value to gift cards. Then come to find out they were under investigation by the FBI. This was a government contractor mind you, so the biggest security guard I’ve ever seen showed up to escort them out.
- kyleee 5mo agoWhat does “add stored value to gift cards” mean?
- dboreham 5mo agoI think it means "take a gift card with $10 value stored and make it a gift card with $20 stored".
- Sohcahtoa82 5mo agoI'm guessing it means they can fraudulently add money to a store gift card without it costing anything.
- janpeuker 5mo agoPayment processors don't allow just brute forcing all card numbers a.k.a. card enumeration or card testing [1][2] and card schemes penalise merchants and payment processors heavily if they don't take measures against it [3]. 1) https://stripe.com/newsroom/news/card-testing-surge https://stripe.com/newsroom/news/card-testing-surge 2) https://stripe.com/blog/the-ml-flywheel-how-we-continually-improve-our-models-to-reduce-card-testing https://stripe.com/blog/the-ml-flywheel-how-we-continually-i... 3) https://docs.stripe.com/disputes/monitoring-programs#enumeration-monitoring https://docs.stripe.com/disputes/monitoring-programs#enumera...
- kodbraker 5mo agoThe rate they try becomes very non frequent when they use multiple card validation apis. I'm not sure how it can be related when it's different pan numbers, different source ips etc. Enumerating CVC2 with a single PAN is a different story.
- opengrass 5mo agoUntil 6 years ago Stripe didn't obfuscate card numbers in API logs at all.
- e28eta 5mo agoThat’s untrue. While I would be willing to believe that for a brief period of time there was a bug that could expose it, having been at Stripe between 2017 and 2020, it was my experience that they had a robust system preventing PANs from being disclosed. That included efforts to mask PANs that were in the wrong place. We didn’t want them in our internal logging systems, and we certainly didn’t want to leak them back to the merchants.
- SkiFire13 5mo agoThis is pretty much a PCI DSS requirement for anyone that directly handles PANs.
- dataflow 5mo agoOkay but... so what? Authentication is a means, not an end. They seem to be missing that what matters at the end of the day is how much money/time/resources actually get lost, and who's on the hook for it. If that's negligible then isn't that mission accomplished? If we could live in a society where your name was enough and you didn't need a card number at all, and yet theft was still low and you still got your money back, that would be even better, not worse.
- julienchastang 5mo agoRelated story and wondering if the OP may have been chasing red herrings. I recently noticed an unauthorized charge for a small amount on my credit card (something about FB/Meta). Likely someone probing the card to see if anyone would notice. I called the CC company, had them removed the charge, canceled the card and had them send me a new card (5-7 business days). With the brand new unused card (new CC number, new expiration date, new CVV), the fraudulent payments resumed (again FB/Meta). How is this possible? The reason: digital wallets. Your credit card number, etc. transfers via digital wallets even when you cancel the card. I again called the credit card company and this time, told them to cancel all the digital wallets (there were 99 of them!). There is no way to do this online. You have to speak to a human in a call center. You then have to sit through a lecture about how all your renewing payments are going to reset and you will have to re-establish them will all merchants. "Yes, I understand that. Please cancel the card and all digital wallets!" Then you have to hold for twenty minutes (why? what are they doing? manually canceling all the digital wallets?). The lesson I learned here is that canceling your credit card may not be what you think. Also recurring payments must be incredibly lucrative and canceling them must amount to a big loss in revenue. (Edited for grammar.)
- kodbraker 5mo agoFor my case, it was almost certain. As it happened single day, the card i use was a virtual card only used in couple big ecommerce websites etc. If it was leaked somewhere else, i think they wouldn't bother logging in some unrelated account of mine in an ecommerce website.
- cj 5mo agoI’m not sure about “digital wallets”, but the concept of updating credit card details after a new card is issued does exist, and it’s a service offered by credit card companies. Blog post from Stripe: https://stripe.com/resources/more/what-is-a-card-account-updater-what-businesses-need-to-know https://stripe.com/resources/more/what-is-a-card-account-upd...
- SkiFire13 5mo agoThere are also "network tokens" that allow you to skip this step and instead remain linked to the new credit card when it changes.
- bradley13 5mo agoCredit cards as a while use a security model from...what, the 1970s? Sure, they've patched by adding the 3-digit CVC, but really? A huge industry can't do better than that? Honestly, it's pathetic...
- psychoslave 5mo agohttps://en.wikipedia.org/wiki/3-D_Secure https://en.wikipedia.org/wiki/3-D_Secure
- huggsboson 5mo agoBBVA has dynamic CVC
- lxgr 5mo agoBetween 3DS for online payments and EMV for POS payments (both launched in the 1990s), payment cards could be plenty secure – if the industry were to decide to mandate them for every payment. The fact that it hasn't is an interesting study in game theory and economics.
- evan_a_a 5mo ago>As a consumer, I thought I was safe; when saving my credit card to a billion dollar valued european merchant, or when i purchase something from supermarket and ignore the receipt, but the reality is slightly different from that. >I got the money back via chargeback in short time. So as evidenced, you are protected by the fraud infrastructure. The bank ate the loss for the fraud and you were made whole. In the end, the banking system cares about fraud loss. And they are exceptionally good at finding the fraud. Making changes to the card payment system is extremely difficult, due to the vast scale of the systems, so without a very good justification that a particular change will move the needle on fraud rates, the banks will opt to not make the changes.
- mothballed 5mo agoIt's my experience that the bank will give up against a motivated chargeback counterparty. My experience with ebay (stolen credit card) in particular was that things were going well until e-bay sent their stack of paperwork to my bank. Then my chargeback was reversed and shortly after that even my bank account was closed. So you're not in the clear once you get your chargeback back. That is done initially while they give the other party time to respond. I think it took 30 days or so for ebay to bury me in paperwork, get the chargeback unwound again, and their schpeel was so effective that my bank themselves then accused me of being the fraudster. As for > The bank ate the loss for the fraud I'm not 100% that's true. The entire reason why the chargebackee wants to contest it is because either the chargebackee or the chargebacker is eating the loss. The bank isn't eating that loss. There is no way E-bay would have bothered contesting my chargeback and paying their white collar workers for professional time researching if the bank was just going to eat it.
- NavinF 5mo agoin what country?
- mothballed 5mo agoUSA. In USA your chargeback initially is usually taken on face. They'll usually reverse the charge within a week or so. But after that they let the merchant appeal it. Most merchants won't. But if they do, your bank isn't going to bat for you. If it looks like it's going to take them much time or effort to deal with it they're liable to just throw up their hands and let you duke it out in small claims court. In my case they had a megacorp ready to fight it on one side, and little old me on the other. So some lady on the phone just insinuated I was a lying scammer and told me my case had been reversed. There was some sort of appeal process I tossed my hat into but it went straight to radio silence and I've not heard from them in years. I would have taken them to court but I moved cross country around the same time and it would cost me $2000 or so for airfare and hotel rooms to show up to the right courts to get $1000 in judgements.
- akersten 5mo ago[dead]
- mcoliver 5mo agoVirtual credit cards have been a thing for years. I remember bank of america or Citi providing them to me 15+ years ago. If I recall it was a java app or maybe even a standalone exe. Shocked they never took off more broadly. Robinhood absolutely nails this. Best virtual credit card system I have ever used. So seamless. Can auth a card for one time use, 24 hours, or indefinite until you cancel. Such a great UI / UX
- EvanAnderson 5mo agoMBNA (which got bought out by Chase) had a Flash-based virtual card app back in the early 2000's. I really enjoyed using it. I also can't understand why they haven't taken off, especially in the world of Everything Is A Subscription we're living in now. I adored being able to set expiration dates and spend limits to save ugly negotiations about ending subscriptions.
- AnonEM00se 5mo agoIt didn’t take off because it was easier to eat the costs of fraud than to maintain the system. It didn’t catch on simply because it’s pro-consumer.
- chaqchase 5mo agoRate limiting and anomaly detection are the real gatekeepers here. A lot of "fraud prevention" is still reactive.
- jonathanlydall 5mo agoIf 3D secure was mandatory everywhere that would help a lot, but if I understand correctly, it’s not really used in the US and with them being so big, card issuers are largely forced to allow non 3D secure requests or their clients will be unable to use their cards for too many things. So an enormously good anti-fraud mechanism is severely handicapped. It’s really frustrating for most of the rest of the world. I don’t get it, do US citizens prefer being defrauded over what is perceived as a slight inconvenience? Even for non-victims of fraud, they still pay for the fraud as all merchants up the prices of their goods to cover fraud costs/insurance.
- gnopgnip 5mo agoHow much is lost to fraud that would be prevented by 3d secure, 0.1%?
- beejiu 5mo agoIn Europe, the max interchange fee is 0.3%. In the US, the average is 2%. So the relative impact of fraud is much higher.
- SkiFire13 5mo agoThere is also an additional (usually pretty high) fee for getting chargebacks.
- mercutio2 5mo agoHuh? Your conclusion does not follow. A large fraction of the interchange fee is kicked back to customers. The size of the pie being so much bigger means the issuer’s tolerance for fraud is much larger, but it’s orthogonal to whether there’s actually more fraud. In practice credit cards fraud actually impacting customers is vanishingly rare at this point.
- lxgr 5mo agoA large fraction, yes, but I believe in absolute numbers, US issuers still retain much more interchange than European ones. The numbers are even public: https://usa.visa.com/content/dam/VCOM/download/merchants/visa-usa-interchange-reimbursement-fees.pdf https://usa.visa.com/content/dam/VCOM/download/merchants/vis... If you take a look at some of the more "expensive" cards, interchange is often higher than 2%, yet issuers often pay as much only on certain categories, and flat cashback cards usually pay 1.5% (2% is relatively rare). Compare that difference to a total interchange of 0.3% in the EU.
- netik 5mo agoOne other thing to add to the story is that the merchants can’t select what level of security they want from the credit card processor. For example, with authorize.net, you can accept the payment with the address doesn’t matter it doesn’t match. I guess the real question here is how are they able to steal from you? Were they purchasing gift cards from a merchant with lax security? It’s one thing to guess a number it’s another thing to get the money out of the system
- Denvercoder9 5mo ago> merchants can’t select what level of security they want from the credit card processor That really depends on the processor; many processors do allow merchants specify your acceptance rules in quite deep detail. There's a bit of a dichotomy in the processor market: on one side you have those that aim to make it simple for their customers and unburden them, while on the other side you have those that expose all the complexities and give intricate controls. The first side won't allow you to specify security requirements, while the second side will give you a hundred options (of course there's also processors positioning them in between). The two sides generally target different customers.
- jwrallie 5mo agoRecently I got an sms from my bank about a suspicious transaction overseas from my wife’s card, it was literally listed as zero USD, at a time when she was not using her phone or computer. I initially thought the sms itself was phishing, but after checking online, the sms format matched and the bank webpage ensured the feedback process will not ask for any information so we proceeded to confirm that we did not purchase anything. The bank immediately cancelled the card and shipped a new one. My initial thought is that the bank safety system could be overreacting, but it was likely that someone was doing exactly what is described in this article and the bank detected it earlier.
- nout 5mo agoI'll get the usual hate for this, but in this instance using bitcoin is safer, since it forces you to verify the transaction on your phone (i.e. you use your phone to pay - either scanning QR code or now NFC). In the US the Square payment terminals can now accept bitcoin from any lightning enabled wallet app, CashApp does it natively, etc.
- tatersolid 5mo agoBitcoin has no dispute/chargeback mechanism in case of error or fraud. That inherent unsafety trumps just about all other safety concerns for a practical payment network.
- nout 5mo agoIn case of error you talk to the seller, if they are reasonable and care about their reputation, they pay you back (e.g. the Square seller devices have options for this). If they don't, you can try suing them. There's a wide group of people that are stealing from sellers (especially on Amazon and similar) by using the product and then returning it with made up issues. Bitcoin would help these businesses, since the settlement is final.
- tialaramex 5mo agoThis blog doesn't mention the most critical part Settlement the part where the bank agrees to transfer money from your account (in this case increasing your debt on the card) to the merchant is completely separate from Authorization. Authorization is the modern EMV ("Chip and pin") authentication, the CVV stuff for online, and any other mechanism by which the bank protects themselves from your fraud and, maybe, as an afterthought protects merchants. The network is completely OK with Amazon saying here's a card number, we say they're paying us $400. That's just a settlement, goes on your bill. No sophisticated cryptography, nothing even as clever as a 4 digit PIN, or remembering your mother's maiden name, just OK, we trust you. Which means you, as a consumer, need to read your credit card bills and dispute anything you don't recognise or you'll pay. There is very little incentive for the networks to care if you get ripped off. If you don't dispute it then everybody is happy, and if you do they just claw it back from the merchant and it's not their problem.
- lxgr 5mo ago> if you do they just claw it back from the merchant and it's not their problem. This is true for non-3DS online payments, but not for in-person payments or when using 3DS online. In those cases, the issuer is usually liable.
- devanshranjan 5mo ago[dead]
- XorNot 5mo agoWhy credit card numbers are full persistent baffles me. They were never meant to be memorable, and the whole process is electronic: surely this can be replaced by cryptography at this point? I've deliberately demagnetized me and my wife's cards and we have black electrical tape over the numbers in public now. Online purchases are the last remaining problem which would be completely solved if payments were to random keys rather then depending on everyone having the same number.
- hocuspocus 5mo agoPANs are indeed going away and every transaction could already be tokenized, today. But then the US were 20 years behind on EMV, and SCA is still not a thing.
- jongjong 5mo agoCredit cards are a horrible idea. We are essentially forced to use them. It's like giving every person you buy from the password to your bank account and trust them not to steal your money. Wire transfers are better.
- lxgr 5mo agoArguably it's even more ironic how credit card applications work in the US: Based on yet another, even shorter number used as both an identifier and a bearer token, and that one you can't even change ever...
- maxgashkov 5mo agoThey absolutely are. Fun example: when Revolut launched in Japan few years back they had a period of a relatively explosive success (especially within the immigrant community), so most of the cards of the period were issued with the same expiration month and with the same IIN (I'm assuming specific to Japan as well) which left very little entropy and lead to brute-force attacks via merchants not requiring 3DS (Uber etc.). Within only one community (approx. 1.5k people) we have had a handful of a 100% verified cases when the card was compromised without any exposure at all (i.e. the card was not used online or offline). In all cases Revolut promptly reverted the charges and eventually they did a complete reissue of the cards for Japanese market (not sure how they've got around the entropy issue: maybe they've randomized the expiry dates or spread out IINs some more).
- deleted 5mo ago[deleted]
- edward1033 5mo agoUnlike US, in some regions such as JP,TW,HK, almost every online card transaction requires 3D Secure. But many real-world cases show that banks then refuse to take responsibility for fraudulent transactions once 3DS was completed, even when the OTP leak was caused by failures in the banking and telecom systems rather than by the cardholder.
- hocuspocus 5mo agoThe EU has banned plain SMS tokens for SCA. You need an OTP + PIN or password, or more likely authorize the transaction from a mobile app with biometrics.
- 8cvor6j844qw_d6 5mo agoPretty standard now to keep your card frozen when not in use, at least for me personally. Some banks let you set specific limits for recurring payments.
- fortran77 5mo agoWe had a 5.15 cent charge for "TikTok" on a business card we never used. We have very good password hygene, and we have Ubikey authentication for all our business accounts. The bank initially told us to file a police report (!) for identity theft. I knew it wasn't identity theft. We got a notice a week later that the charge had been reversed; we never bothered with a police report, we just cancelled the card. It had been flagged as suspicious by the bank when it was initially processed, but I'm not sure what was wrong. Perhaps one factor, like expiration date or zip code wasn't right. I have a feeling it was stolen with some scheme like this where people just guess numbers by some algorithm.
- exabrial 5mo agoIt’s 2026, I have a laser guided vacuum robot that auto cleans my floors… we just flung people around the moon… And we still don’t use public/private keys to secure transactions. Why
- expedition32 5mo agoWhen I use my credit card I have to approve the transaction in my banking app. Which is pretty much unhackable. But that's too much friction for the average American because it gives you about 5 seconds to realise what you're doing lol.
- fleroviumna 5mo ago[dead]
- hashlock_p2p 5mo agogeçmiş olsun
- hashlock_p2p 5mo agobuyuk gecmiş olsun
- mcabert321 5mo agoPlease just enter into your Google search and review this platform” and educate yourself before joining. Read BBC, Guardian, and Reddit articles/posts. Selfie camera doesn’t work, and they refuse to offer an alternative login method, so I can’t access my money. Keep getting same automated response(do some work you twits). They heavily spam my email, though. No customer service so imagine being stuck abroad with these absentee idiots as your lifeline, best learn to beg or busk in the local language. Am happy jeffsilbert 39 g mail com was my savior in getting my refund possible.