Skip to content

Comment on American Express fails miserably at basic security

Comments

This sounds scarier than it really is. Why? Because credit card companies focus on identifying fraudulent transactions rather than verifying your id.

From Bruce Scheier's blog[1]:

"But once you understand that the problem is fraudulent transactions, you quickly realize that authenticating the transaction, not the person, is the way to proceed.

"Again, think about credit cards. Store clerks barely verify signatures when people use cards. People can use credit cards to buy things by mail, phone or Internet, where no one verifies the signature or even that you have possession of the card.

"Even worse, no credit card company mandates secure storage requirements for credit cards. They don't demand that cardholders secure their wallets in any particular way. Credit card companies simply don't worry about verifying the cardholder or putting requirements on what he does. They concentrate on verifying the transaction."

[1]:http://www.schneier.com/essay-153.html

Strong disagree. In reality, and especially for small-ish transactions, card companies are terrible at detecting fraud and customers are terrible at noticing it. Criminals can make second-order money off innocuous transactions through affiliate scams.

The only reason this isn't a big deal is that it remains incredibly easy for attackers to get CC#'s without capturing packets off the wire.

Don't know, obviously you know a lot more about this than me, but in my experience as a consumer, at least my bank (HSBC UK) has been pretty good at identifying fraudalent transactions on my account. They actually spot them before I do and call me right away.

My credit card companies are so good at identifying fraud they've caught 17 of my last 0 fraudulent transactions.

(OK, I sympathize: buying a thousand bucks of stuff in four transactions from central Japan at 2 in the morning is not exactly typical behavior for a Bank of America customer.)

btw, as a fellow B of A customer who has had to deal with their crappy fraud algorithm as recently as last week, apparently you can go into the branch and have the 'fraud protection' removed.

Yes, but for the most part those will be swipe transactions, not online transactions. And they keep an eye out starting at $100 or so because that's when it starts to add up if you fail to spot a fraudulent charge. The majority of online transactions is pretty small though, and falls right in the gap between 'don't care' and 'card issuer spots fraud'.

Interesting. Mine (Barclay's) is overly aggressive: it calls me every two weeks, and blocks my cards about 4 times a year.

I have pre-paid phone, buy small items from Google checkout, and travel frequently. Barclay's knows this, but still keeps calling to confirm my (quite regular, very normal) transactions and blocking my cards.

And also they offload most of the risk onto merchants for accepting fraudulent transactions, so merchants have to be extra vigilant.

> credit card companies focus on identifying fraudulent transactions

That had me laughing, you really clearly have not dealt with large numbers of $10 to $50 transactions.

Card companies don't care at all about such charges, if you have a valid card number, expiry in the future and a cvv that matches the charge will be accepted.

VBV and its sister programs has been designed to combat this and passes most of the responsibility back to the consumer or their bank in five-way handshake between the consumer, the merchant, the IPSP, the bank and the issuer.

But doesn't this attitude screw the merchants? If an online merchant accepts a payment from a stolen CC they have to foot the bill for the product they sent out. Thats how I thought it worked?

And the problem is? Users love this policy. Banks love this policy. Merchants don't, because they get screwed. And it's even worse. Not only are they out the product, but they also get charged, even if they provided a CVV in the transaction. So, you lose the cost of the product, the time involved, AND you get fined.

Disclosing ID and verifying it are completely separate issues. Also, the information leak here causes problems for more than just the credit card company; the data transferred in plain opens up the possibility of more than plain credit card fraud (although that is the most obvious exploit).

I seriously doubt that Schneier would consider this information disclosure OK based on this loose interpretation of his blog post.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.