I’ll Take 2 MasterCards and a Visa, Please
krebsonsecurity.com
krebsonsecurity.com
I'm pretty sure this article was written with tongue firmly in cheek, but it's just so... out there.
I dare the author to make this $2.10 purchase using one of his own valid credit cards.
Obviously this is just cynicism. I assume the main reasons are 1) imagine justifying that to shareholders, 2) it creates a market.
Having said that, the banks could offer a "reward" system for anyone who manages to report a stolen credit card number.
Say your credit card is stolen, and used to purchase 5 items from 5 stores. Each of those 5 stores will be forced to return all of the money they charged, no matter how impossible it might be for them to know the credit card was stolen. They will also collectively pay $100 in chargeback fees to your bank, which is likely more than it cost to move the couple pieces of paper it took to handle the situation and inform the customer.
The bank has now made a profit.
Each store that accepted the stolen credit card has lost:
- The payment they accepted
- The transaction fees paid on the payment they accepted
- The product they shipped, potentially hundreds or thousands of dollars
- The chargeback fee
And if chargebacks ever amount to more than about 1% of any of those store's transactions, their processing fees can go up, they can have their cash flow abruptly cut as a reserve fund is created to hold their future charges for some time, or they can lose their ability to accept credit cards entirely.
Also chip or no chip doesn't matter for online/telephone/mail order purchases which I would guess would be the only place you can use this stolen credit card info.
--- I now have a 12-digit PIN code.
Actually, that money most likely never made it very far - the businesses where the cards where used almost certainly never saw a cent of it. Worse, they probably still had to pay for the transaction fees (of the now reversed transaction) and a chargeback fee. The bank and any other service providers in the payment processing chain made more money than if the transaction had been legit, and the thief made off with the goods. Yup, accepting payment by credit card sucks.
The other aspect of the problem is the length of time the NSA sat on public key encryption. It's within the realm of possibility for credit card companies to have used public key encryption to at least validate that the human user of a card number knew something, a PIN or whatever, related to the card number. The payment authorization system grew up without that math, so it pretty much depends on everyone (like the call center reps or the programmers of shopping cart software) keeping the card number and the CID/CVC/CVV secret and off their disks.
Or am I missing something? Are these cards all (or mostly) deactivated? And so the buyers are not using them directly, and rather using them as leads/information to do some other nefarious activity?
Um, who says they're not?