Based on wikipedia [1], the first 6 digits are used to identify the issuer (although from looking at this listing [2], it appears to be standard practise to assign some institutions blocks of IINs, and given that an institution could control multiple IINs, it is probably relatively safe to consider these to be part of the unique card ID. When we start to run out, we will probably see a market for these emerge in the same way we see a market for IPv4 subnets today.
The only area of fragmentation where I see potential trouble for secondary markets is the first digit, which is restricted by industry (banking only has 4,5,6); but if it ever becomes an issue, I am sure they will re-purpose the address space of other industries for banking
This leaves only the checksum digit itself of deeply problametic for maximum utilization; and that is literally a single digit.
[0] I wish this were a joke. https://webstore.ansi.org/Standards/ISO/ISOIEC78122017
[1] https://en.wikipedia.org/wiki/ISO/IEC_7812
[2] The official listing is not publicly available https://www.bindb.com/bin-list.html
It would of course require a massive amount of work across the board, so it's very unlikely to happen.
It's true that the number of organisations that interact with the message formats for sending card transactions is significantly smaller than other things, but we're talking about every single bank, every single PSP, every single embedded card device, and probably many more organisations beyond that, currently in operation today. Given the glacial pace of most banks' IT operations I would not expect them to do be able to achieve this within a time frame of several years or perhaps even a decade.
Sure these are not the same challenges as IPv4 and such, but it is in no way a trivial change to tweak a message format that has been in use since before most HN users were born :)
And it really should be enough. With 10^18 numbers you can allocate 1000 numbers per day to each of 10 billion people, and go 10 years between reusing numbers, and still have only a few percent of numbers reserved at any point in time.
Then factor in that CC numbers have an ~2year expiry date and a 3 digit CCV number, so old numbers can easily be reused.
Further the name of the holder could be added as a key to the number, further increasing reuse.
We won't run out of CC numbers anytime soon.
There was a period between the old expiration and the new issue and not common, but it did happen from time to time.
I'm sure you've seen the idea that an upgrade to IP could have just added another octet or two and changed nothing else. It would have worked pretty well to prevent us running out of addresses, with 40 or 48 bits.
Well, 16 digit credit card numbers are a hair under 50 bits. And full-size 19 digit credit card numbers are a hair under 60 bits. That's plenty. You can give out a million of them to every person. If we couldn't reuse, they would eventually run out. Because we can, they won't run out.
Also CVVs won't match even if you reuse the number