I'm asking because I saw a lot of in-house tokenizer with hashes or deterministic encryption that could get reversed in a few seconds by brute force since the space to cover is so small.
https://stripe.com/docs/api/tokens/create_card (notice the request has no charge, but the response contains a fingerprint).
To state the obvious: it's not determinstic outside of Stripe, and there's no way to revert it, or even iterate over all CC numbers and brute force the space. You'd need Stripe's secret, e.g. assuming they use HMAC.
It’s fine with PCI DSS as long as it is not reversible.
[1] https://gist.github.com/epixoip/a83d38f412b4737e99bbef804a27...
I would be completely unsurprised to find that other than having the data in some poorly secured database it isn't used for anything useful.
“...But don’t dismiss malice.” Dismissing reasonable concerns about a nearly universal practice is best done through reasoned argument, not aphorism.
Does that make it malicious and stupid?