MasterCard Serbia asked ladies to share FB photos of their credit card
svedic.org
svedic.org
The problem here seems to be that people don't read what's written, but instead do what they think was written (Edit: apparently because it was shown in the example picture).
I also read the official rules linked there. The rules state that only the winners need to prove they own the card by contacting MasterCard directly with a slip from any transaction made with that card. So, even if you win, you don't have to show the card, only to prove you have used it.
I don't know about you, but all people I know hold their CC in their wallets. So, if you just empty your purse on a table, it wouldn't show the CC immediately.
> At the very least, they shouldn't have used that example image, and probably should have explicitly said NOT to post your credit card.
Agreed.
Mastercard on the other hand should have thought about this and avoid putting the card on their photo, as "normal people" will tend to mimic without spending those 30 seconds thinking about "I ain't giving you my real name/surname/card details"!
But hey.. it worked :)
Now let's sit back and soon we'll learn how many hits would their cards have, from websites that don't require the card verification value (CVV) :)
No, the problem is that Mastercard created a situation where you would show your credit card (since it's in your purse), and created an example which included a credit card, despite knowing full well about credit card fraud. They fucked up the contest, and your attempt at passing the buck on to random internet denizens, who aren't as familiar with the details of credit card fraud as Mastercard is, is misguided. Mastercard fucked up here, not the people who entered their contest.
Are these still out there?
Getting a credit /debit card has always been a rite of passage for young people. Before online social networks, showing off your card to your friends was a low-risk activity. Now broadcasting the same information to all your peers places you in danger.
As of this post, the latest guy who tweeted his card (Mar 9) has a... rather ironic username.
Edit: See http://www.independent.co.uk/news/uk/crime/criminals-guess-v... / https://news.ycombinator.com/item?id=13099949
choose(5000,0)*0.999^(5000-0)*0.001^0
But that means, by brute forcing, while you should crack at least one card, there is still a non-zero chance that this will be your unlucky day... (Cracking all cards with this methods, is - essentially - a zero-chance game, but even for that an infinitesimally small chance is left, that my computer cannot reproduce.)So, lacking the CVC may cause some cautious companies to refuse to take the card, but that's just their decision. You can still use it with less-cautious companies, or your own merchant account.
Edit: Also as far as I know there's no specific address attached to my card or account except for the purpose of contacting me via snail mail.
While a bad security practise, a transaction can still go through if the other verification signals like expiry, name, billing address, etc (most of which are accessible through social media, btw) provide sufficient confidence in the legitimacy of the transaction.