We've been neck-deep in payments stuff on the card issuing side (getting a BIN sponsor, ACH origination, etc), so happy to answer any questions on that front as well.
P.S. For new users, your first $5 donation to watsi.org is on us :)
We've been neck-deep in payments stuff on the card issuing side (getting a BIN sponsor, ACH origination, etc), so happy to answer any questions on that front as well.
P.S. For new users, your first $5 donation to watsi.org is on us :)
Say there are 3E9 people on Earth, each with 3 cards. That's around 10 digits right there. There's 1 digit for checksum. I imagine you'd want to leave space for least 1000 financial institutions around the world, so that's another 4 digits. Which means you can only have 100 transactions per person.
None of this takes into account the fact that the same people are issued way more than 3 card numbers either.
So my question is, how are we not close to running out of card numbers? How is this not even a problem yet?
If you're curious about the number scheme, check out https://en.wikipedia.org/wiki/ISO/IEC_7812
Using the number scheme, this person calculated^1 that (assuming Amex starts issuing 16 digit cards) there would be 3*10^14 + 10^11 or 4.001e+14 possible combinations.
[1]: https://www.reddit.com/r/theydidthemath/comments/3wj8eb/requ...
You vastly overestimate the number of people with credit cards.
It isn't there, and disclosing it is mandatory under the Google Analytics T&C's (Section 7 here, it's crystal clear with the language "You must..." https://www.google.com/analytics/terms/us.html )
Can you please add it to your privacy policy? It's one of the first things privacy-conscious users look for when evaluating a website or service.
Anyway, thanks for bringing it up. We've pushed the updated terms.
I generate Citi's virtual credit card numbers every month for numerous online shopping payments and I haven't run into issues.
It seems that it's not possible to determine if a card is a virtual number by parsing the digits.[1] Do you have other information stating that merchants know how to reject virtual cc numbers?
[1]"As there is no way for a merchant to identify a card as virtual up-front," https://support.cybersource.com/cybskb/index?page=content&id...
That's fascinating. Perhaps PayPal killed it for multiple reasons because the (possibly biased) answer from a PayPal said not enough people were using it: "The one-time card numbers -- technically they were MasterCard virtual debit card numbers -- were discontinued as a public user-facing feature because they were not generating sufficient transaction volume and revenue to warrant further development."
[1]https://www.quora.com/Why-did-PayPal-discontinue-their-one-t...
If a lot of merchants were flagging and rejecting transactions from Paypal's virtual CC BIN numbers, that would prevent people from using it very often, leading to "not generating sufficient tx volume", right?
Tell me about AVS please.
Existing virtual card services have me covered on the virtual card front - both cost and (limited) privacy. I want something that gets me past the virtual card + AVS issue. All the virtual card providers seem to suck on this front...
I work at a small ecommerce company and we'd be effed without our AVS service to help with CC fraud.
>Do you want your address actually verified or a feature that makes AVS useless?
Either is fine with me. I just want a virtual card (to protect my bank acc) that I can use in as many places as possible.
Currently I've got a virtual card that only works like half the time...That's pretty underwhelming by any criteria.
Either is fine with me. I just want a virtual card (to protect my bank acc) that I can use in as many places as possible.
Currently I've got a virtual card that only works like half the time...That's pretty underwhelming by any criteria.
irl, Card acquirers do verify transactions without AVS, but they charge higher provided the merchant can demonstrate pre-transaction fraud mitigation
>AVS dropped fraud rates on card-not-present transactions dramatically, and it'd skyrocket without it.
AVS was less than moderately effective 6-7 years back, but it's less effective now, almost not at all. Most "researchers" have the card dumps with the addresses already so AVS does nothing to decrease the attack surface. Pre-transaction approval risk mitigation and post transaction fraud review is the only thing that works.
What do you do when you get subpoenaed? Do you link all the accounts to the real identity? Lavabit-style exit?
I'm pretty sure that KYC trumps privacy, in this case :(
Lavabit wasn't doing financial transactions. Openly, anyway.
Do you have any plans to add batching+noise to foil global passive adversaries? For example, I opt to keep a running balance target of ~$50 and today's charge for $34.56 is debited as $31.37 a week later.
It's a long story, but there's probably a good blog post in this.
I’m working on an idea that will need to pay hundreds of vendors for the services they perform for our customers. We want to pay the vendors electronically where possible so having unique card numbers for each vendor would be a great thing.
After looking at Privacy.com I want to take it a step further by generating a unique card number for each of our customers. We’d need higher spending limits and the ability to manage the cards via API. Other than that, what you’ve built sounds like a perfect fit for our use case.
Another: https://dl.dropboxusercontent.com/u/1237941/Screen%20Shot%20...
The expiration date and CVV aren't fully visible - and for some reason clicking the "Open" button does nothing, so I can't close it.
The money is transferred from your account before the card is issued / transaction go through so it's pretty much a charge card.
Though Privacy's approach of being extension-first and launching first is probably the right one.
* Can I use your card to pay for FreedomPop?
* Can I pay for your card using prepaid credit?
They are punishing themselves! Why!?
No matter. I shall browse on, without Javascript, safe in the certitude that I am only missing the content of people too foolish, ignorant, or uncaring to use HTML and CSS properly.
(sighs)
And, to "modern web requires Javascript" critics, modern life expects credit, web surveillance, Facebook, etc. That doesn't mean you have to support or force it on others. Let's look at it really quick to see if a HTML4 w/ CSS site could've handle it. Yep, we did more interesting stuff back in the "DHTML" days (eg dynamicdrive.com). So, it's a privacy site pushing risky, higher-overhead crap on us just for fun. Hypocrites.
Alright, now let's look at the security. I should eliminate stealing a specific card or using malware on the machine to forge transactions. These are main attack vectors. Might mitigate the first. Looks like it will be vulnerable to the second. Admittedly, most methods are vulnerable to the second and those that aren't stay niche due to "inconvenience." So, still could be value in mass market where people get compromised anyway but want to knock out a common attack. The third risk is an unknown with some of the claims looking good on paper but to abstract to evaluate.
Note: The split-keys between employees part on the security page is funny. It's a banking control for sure. I'll just let your imaginations work out how little protection it brings from hackers, management, or the government. ;)