3 ms·
Credit card theft like you describe is already possible and already happens
by bouk 13y ago
Credit card theft like you describe is already possible and already happens
- sequoia 13y agoThis sure makes it easy tho, no?
- vklj 13y agoBut with Coin, they can potentially copy all your cards, instead of just one, by pressing the button multiple times. It's not obvious how to prevent that without affecting the UX.
- dragonwriter 13y agoIt affects the UX somewhat, but since it has to be in proximity (implying data contact) to your phone to operate, you could just move the "switch active card" feature to the mobile app, not the Coin itself, then you wouldn't have to worry about people in posession of the Coin (e.g., when you put use it to pay the bill in a restaurant) toggling through the other cards stored on it for nefarious purposes. Or, for less impact on UX, put a "lock active card" option on the mobile app, and still leave the actual card switching on the Coin.
- rexreed 13y agoYes, card cloning devices have existed for decades, but this automates the process, allows you to carry a single (disguised) device that can store multiple cards. If one doesn't work, try another card, without eliciting suspicion, and simply replace / swap cards that are cancelled. The old method requires use of credit card blanks, a duplicating device, and the card itself doesn't look like the card when presented in person. In this case, as someone mentioned, Coin doesn't display the card #s on the front, so it's like a Card Not Present (CNP) transaction, but needs to be treated as if it was. This doesn't bring anything new to the card skimming operation, but it simplifies, optimizes, and can in some ways facilitate it. They need some sort of ideally biometric authentication and/or a server that identifies when two Coin devices carry the same cards on it to avoid this sort of fraudulent use.
- bri3d 13y agoThis makes it less suspicious. Traditionally a lot of small-time (i.e. Vegas) skimmers write mag-stripes onto other cards ranging from hotel key-cards to expired credit cards, but in places where skimming is common gas attendants and cashiers are trained to watch out for warning signs including lots of expired cards, trying lots of cards, name on computer doesn't match name on card, and especially hotel keycards at gas stations. This device defeats all these human security measures by letting me use a startup bling device to try up to 8 cards at once without looking suspicious at all. "Declined? shit, my newfangled e-bling card must have messed up - try it again!" (while silently changing cards using the button). "No name on the card? Card isn't signed? You want my ID? But this is the hottest new toy! Promise it's fine!"
- superuser2 13y agoThis is interesting. You can just buy blank magstripe PVC cards in bulk for very cheap on Amazon. You can buy an ID printer for a couple grand. Why the need to repurpose old cards?
- bri3d 13y agoI'm not actually experienced with street-level card skimming beyond anecdotally, so I'm not sure. But my initial speculation is this: - Centralized location / evidence. A stash of blank cards and an ID printer have to go somewhere, and look suspicious to start with. The gear to skim cards and write them onto existing magstripe cards can be stored in a small space or on one's person and thrown away quickly; there's no centralized location. I believe hotel keycards are used because of their availiability. There was a sensationalized national news piece a few years ago about pimps giving women hotel keycards with credit cards written on them to buy gas with. - Start-up cost. A couple thousand $$ in an ID printer is more than $0; that's what would divide street-level carders from professionals who probably wouldn't be passing overwritten cards at retail anyway.