That leaves only 6 digits to guess to obtain a valid card, and you're given the check digit to limit the search further.
That leaves only 6 digits to guess to obtain a valid card, and you're given the check digit to limit the search further.
https://www.pcisecuritystandards.org/pdfs/pci_fs_data_storag...
First6 will give you ability to know the issuing bank of the card (so an email can be crafted to look like those banks emails). Plus last4 tends to be used by banks as a "hey, we know who you are!" when they send emails.
It is not required for charging a card, it is for reducing fraud.
Facebook was providing:
Cardholder Name
First 6
Last 4
Expiry Date
Billing Address.
The only bits missing were CVV and the middle 6.Yes, first 6 and last 4 are not considered sensitive for PCI compliance. However, like most security standards, the standard is a minimum, not what your target should be.
Given the ability for attackers to quickly guess CVV and the remaining digits[1], the attack becomes a numbers game. They don't care about _a_ card, they care about _any_ card.
This is why Visa and MasterCard are pushing to tokenize all cards - so the stored information is linked to the merchant storing it and can't be reused.
That's even before we take into account the account take over possibilities since those card details are used by other companies as verification for account recovery[2]. Yes, those vulnerabilities were closed, but that doesn't stop new companies from making the same mistakes.
Yes, it's impressive that they managed to prune the fields so quickly. Shows a very efficient escalation path!
[1] https://www.theregister.co.uk/2016/12/05/undetectable_sixsec...
[2] https://www.wired.com/2012/08/apple-amazon-mat-honan-hacking...
I'm not sure what types of enterprises actually use formal verification since it's very costly. Writing software is much faster than verifying it. Embedded auto, aerospace, industrial applications, sure. Facebook? I doubt it.
Such methods could be useful, maybe coupled with fuzzing, for breaking software too. It might suggest avenues for exploit.
Systems like coq are used more naturally in math proofs, but even there it's very hard to apply.
I noticed how similar the thought process was to GDPR work I've been involved in, where, for example, we can keep track of Last name and Phone Number in our company, but they could never be at rest unencrypted and unhashed in the same system. Or First Name + Job Title + Location but only 2 of those three can co-exist. It seemed like the kind of thing that would have a formal way of expressing. Our GDPR consultants were unhelpful in that.
Kudos to facebook team that they responded shortly, I cannot tell if it was work hours or not, but either way, this is very very short in the context of large corporations.
A: that was fast!
B: that's because it was very serious!
Where is the cynicism? Can it not be summarized as: they fixed a serious issue very quickly?
Sounded to me more like "of course they fixed it fast, this is a serious issue", and undermined the speed it get resolved. Probably my bad.