Blippy Publishes User Credit Card Numbers
google.com
google.com
Why would you want to automatically share information about every purchase you make with your credit/debit card with the world? It just sounds like a recipe for disaster with very little upside.
Can anyone who uses this service (if any HN members do) explain the usefulness of it to me? I might just be misunderstanding the purpose.
Even if this turns out to be test data, it's still pretty shocking and will tarnish the service forever.
If you buy something and then a number of your 'followers' buy the same item a few days afterwards, that information is very valuable.
Then they will monetize by giving it to the only people who really care how much you spend at Starbucks: Starbucks (and competitors).
It's the easiest way to share your credit card information with the world.
2) Submit photo to hacker news
btw i cant believe nobody point a finger on google yet, this part of their fault too. there should a 'proper' mechanism on their webmaster tool an option to excluded a sensitive data Or make it an opt-out features Or add one regex line to detect an anomaly data on their search.
ffs they have billions to tinker around with it
On a more serious note, I think Blippy's main use is efficient bragging.
Don't get me wrong, I don't care for Twitter myself. I don't use it, and I do find most of it to be trite and little more than navel gazing. But I can see some useful signal on Twitter, I just cannot see how it could not get buried under an avalanche of noise.
Blippy seems totally vacuous.
I can see it catching on with kids definitely.
I am also keeping in mind that there are many jokes in the podcasts about Mr. Laport's proclivity to purchase tech items, at times in quantity, as an early-early adopter.
Kids that don't have a credit card?
Doesn't look like a test number.
Some line items 'comments' field had credit card details included in them, which they didn't bank on.
Not as apologetic as one might expect.
The question is, why would banks put your credit card number on the description of transactions in the first place? I've never seen that done before.
I think they're perhaps not as apologetic as you'd like because the premise (Blippy publishes credit card numbers) is incorrect. They made a mistake in a beta period which they fixed.
Some times people mess up. But there's a difference between "oh oops in the beta period we didn't realize that banks put credit card numbers in descriptions :/ and we didn't realize Google would index that. 4 people were affected and we're sorting it"
and
"We routinely share credit card numbers!!!"
Personally I'd give them a break about it. They're probably feeling pretty crappy about it all already without people blowing things out of all proportion. (This is one of the worst things about the internet IMHO - blowing tiny things up into mammoth proportions through rumor, misunderstanding and incorrect assumptions. And always assuming everyone is evil).
* They got some data
* The data has a "description" field
* They naively displayed that description field
* They then found to our horror that sometimes this
description field contains CC numbers :/
I don't think you can really blame them too much for that.It would be another story if they were actually storing CC numbers and 'accidentally' published them, but that doesn't seem to be what happened.
if(/\d{4}((\s|-)?\d{4}){3}/){
# don't print it
}n.b. not trying to be a smart-ass, just saying it can't be that hard.
It seems like a ridiculous idea, and while it makes sense in some corner cases, I'm not surprised that they missed something that was only a problem for four users ever.
Perhaps what we should be doing here is asking why Google kept a cache of months-old HTML instead of updating their cache instead?
To that I would say, one should be very very very paranoid about what you print, given that you know that you're printing things from people's credit card bill statement.
Blippy shouldn't have output'd the cc numbers, whether or not Google caches it or not is a secondary to this. Note that Google's cache wasn't explicitly out to get Blippy, they just happened to cache whatever Blippy was emitting.
...to a point.
What other 'bad information' might be in that description? Social Security # for a USA customer? Social Insurance # for a Canadian customer? Pretty soon you'll have a laundry list of 'bad numbers' that you have to try and filter out.
And I agree, that a root cause analysis should be done. E.g. asking the 5 why's (as Eric Ries advocates), for behind every technical problem, there's a human problem.
This is actually pretty common. It happens on my statements, and while I think that my bank could do something better (last 4 digits would be enough), there is at least a reason. For my joint checking account with multiple debit cards, it helps figure out who bought what. Since each purchase has the exact card number, we can figure out who went to Starbucks 3 times in one day...
Personally, I am not sure why any digits need to be on sales receipts. Or why I even need a receipt.
Also you have the CSV on the back of the card and expiry date. You also have the "Verified by Visa" stuff where you have to enter your password for any online purchase, also you'll usually have to enter the card holders full address.
I agree though, receipts are mainly useless wastes of paper these days, and the less paper with personal details on the better.
Given the massive library of photos available on Flickr, it'd be unlikely that there aren't some credit cards on there - perhaps a credit card left on the coffee table in the background that can be enhanced... Maybe even a credit card in someones very thin see through shorts :/ Wonder how long it'd take to find some examples.
It's true. A friend of mine moved to Canada from the UK with tickets bought on her card, changed her credit card's billing address to Vancouver, and called the card issuer to let them know she would be moving.
Immediately after she made her first purchase in Canada, they put a hold on her card. She had to call back to get the hold released, but it was put back on as soon as she made another purchase. This continued until she got a new (Canadian) card.
It's too bad the banks in the UK don't scrutinize themselves.
The one time this happened to me, Amex called me to tell me they thought there was a problem. I looked, noticed that there was, and I had a new card / account number the next day. Very convenient, and only an 8 hour or so window where I couldn't use my card.
Someone was careless with my card data, but it didn't matter -- it didn't cost me any time or money. So I guess that's why I don't get too upset about stories like the original article.
I'm no security expert by any means but still I'm sure that it must be possible to design a lot safer system. Of course you can never defeat human stupidity / irresponsibility / malevolence but it should be a lot harder to commit card fraud.
Yes, only someone with the temerity and tenacity to ... click "View Source".
If as they say, all they released were 4 credit card numbers, I understand why they act like this isn't a big deal.
Their system works and has worked the entire time for 99.98 percent of all people. Those few people who did get their numbers published, well, send them a ham or something. At worst, if the cards are used, the user will have a couple days of saying "Chargeback X chargeback Y". This isn't even about a bug currently in their software, but a small one from a long time ago from a credit card processor arguably doing something incorrectly (or at least, quite strangely).
I wonder if this is something to do with test data.
edit: I was wrong, it's the full number that's a test number. 5424 0000 0000 0015
(Edited to remove actual numbers in case they're not test numbers)
The two numbers listed on that site are test numbers. 5424 is a very common MasterCard prefix.
"VentureBeat reporters deduced that all are Citibank-issued MasterCard numbers. We’re reluctant to publish further details yet." http://venturebeat.com/2010/04/23/blippy-credit-card-citiban...
Yet they're showing a screenshot with the exact Google search term to get all the data.
Why do they (or any other startup) even know what actual credit card numbers are?
How many of you operate in the same way? Why? Are you PCI compliant?
You can use a 3rd party gateway that acts as an intermediary between you and the bank that issued your merchant account and the 3rd party gateway will offer services such as scheduled rebilling. The gateway has to store the number though because the APIs at the highest level have no clue how to deal with internet and subscription type billing. They're still stuck in a very brick-and-mortar mindset. In this case it's the 3rd party gateway that has to deal with PCI compliance, not you.
If your transaction volume is high enough to justify it you can save a lot by cutting out another middleman and writing your own gateway. In this case though you generally have to be PCI compliant and have regular security audits to stay compliant.
PCI compliance only makes sense when you store CC numbers since PCI is a set of requirements on how to store them. Saying you don't store CC numbers and are PCI compliant makes no sense. EDIT: As andrewf points out below I'm wrong about this paragraph.
Yes I know, that's why I didn't say that.
I'm wondering why you would ever (as a startup) choose to write your own gateway and not outsource this to a company that can be PCI compliant (i.e. the Gateway)
Why is simple. It's the economics. If you're a startup that does lots of micro-transactions you're paying a good chunk of overhead in gateway processing fees. If you feel it's worth the continual development effort (because don't kid yourself, writing a secure internal gateway takes a long time and essentially never ends) then you do it.
In Blippy's case they probably had to write their own because I don't know of any 3rd party gateway that has an API to return a list of user purchases when you give them a credit card number. I'm actually surprised the banks even support that kind of request.
I would think that when you start thinking your first application requires a second application (that you have to build yourself) just to efficiently exist, you should be taking a good solid look at the viability of your idea.
In Blippy's case they probably had to write their own
Case in point I suppose.
PCI compliance isn't something a startup should be looking to saddle themselves with, in my mind. Once you're established and can analyze whether you want to internalize an outsourced function, it's on the table with everything else I suppose.
Exactly.
That's the point I was trying to get across. Guess I wasn't very clear. =)
If a system accepts CC numbers from a form and then passes them to a 3rd party gateway for processing, it's within PCI scope, even if it doesn't store them.
From that, I'm guessing that Blippy lets users automatically import their credit card statements, but they didn't anticipate that the entries in those credit card statements would occasionally include full credit card numbers. Embarrassing but a corner case.
Is this just an accepted danger of using 3rd party APIs for information, or can they (Blippy) do something that doesn't look like they're just trying to shift the blame?
I wonder what other awesome bugs are lying in wait in Citi's API...
Why would only Citibank cards show up?
Is there any way to report this to Citibank?
http://blippy.posterous.com/blippy-and-credit-card-numbers
There's also this:
"While we take this very seriously and it is a headache for those involved, it's important to remember that you're never responsible if someone uses your credit card without your permission. That's why it's okay to hand your credit card over to waiters, store clerks, and hundreds of other people who all have access to your credit card numbers. "
That's true, but how does this diminish their security breach, is beyond me.
In the past when I've forgotten my password and phoned my bank to get a new one, typically they ask for a shared secret (like mothers maiden name, first school, etc.) but if you say "I don't remember" they then ask you to verify your address and your recent transaction history.
Blippy makes that last bit public and so probably creates a backdoor in the manual security protocols of a lot of banks.
They could clearly mark the stricken text as having been done to potentially protect privacy and provide a contact mechanism to un-obscure false positives.
I think the harm of a few false positives -- remember, we're talking about obscuring a 16-digit string that has a particular valid checksum, not a very common occurrence -- is greatly outweighed by the harm of having someone's financial identity stolen from a Google search.
But, for the summaries of search results, I see no reason why scrubbing the numbers would be a bad thing. I can't imagine complaining about seeing XXXX XXXX XXXX XXXX in a result summary instead of 5424 0000 0000 0015
Until then, why do it?
I find it difficult for me to swallow the title of the article and makes me want to flag it.
Okay, so my question then, after getting the response that Blippy could do a better job processing their data, is why Google is indexing data that isn't being displayed?
What I mean is, I understand crawlers go through pages to gather data for search results. Why is it gathering data that isn't going to be rendered to the user, performing search queries, since that is empirically the most relevant data users need to see in search results?
This is a HUGE trust issue and you can somewhat foreshadow the companies future by how they handle the crises especially with these 4 users.
Also, I'm only responding to you because you have this account for one year and I thought you should know better. Eat your downvotes like a man and stop acting like a primadonna.