Why blurring sensitive information is a bad idea
dheera.net
dheera.net
But i wonder what the limits to effectiveness is on this attack. I usually randomly swirl around with a smear tool to blur out things...
This may be only in Washington and Idaho though, as there are several different legacy BofA backends as a result of M&A bullshit.
Also, not all online merchants use CCV. Also consider the risk of creating fake physical CCs, no address or CCV necessary.
Online merchants are supposed to comply with PCI-DSS - not store your CCV ever, never transmit your number unencrypted, never store cardholder information unencrypted, plus tons of management controls and audit controls over the same.
In practice, let's just say lazy programming is everywhere. I've seen many people who handle online transactions and violate PCI-DSS to some degree, including storing CCV numbers.
You're definitely right about adding entropy though, but why bother? Just blacking it out guarantees how much information is available - zero.
Blacking out the section entirely is the only proper way, since you really want to be sure you are destroying the information in the image, not just dispersing it.
Even then, if you are removing a single digit it can be partially recovered by observing kerning statistics, etc.
Incidentally, while I was looking for that link, I found an implementation in the form of a Photoshop filter: http://tlrobinson.net/blog/2008/10/08/recovering-censored-te...
3 years ago (3 comments) http://news.ycombinator.com/item?id=79405
9 months ago (no comments) http://news.ycombinator.com/item?id=1115919
I don't see that this is easy. Surely you have to test a number of offsets and sizes of text? And without knowing the digits, this is not going to be totally accurate.
Honestly, I don't think the lesson has to be "don't blur"... it can just be "blur enough". If I blur something out, I just use a radius big enough to erase all of the information.
In that case, why not erase the numbers and replace them with random digits?
Check out "High Quality Motion Deblurring from a Single Image", for some quite impressive photo reconstruction done by actually fitting a spatially varying set of blur kernels to an image.
I eagerly await your impending purchases.
Black it out. And I don't mean the stupid PDF trick where they draw a black box over it (but you can still copy/paste the number from underneath). I mean actually black it out. Print it out, draw on it with a marker, and scan it again if you have to make sure.
But I've seen so many blurred out numbers that I could just about figure out with my eyes, let alone a computer program that could decode it algorithmically. And yes, standard (and non-standard, i.e. Photoshop) algorithms are fairly well known and can be tested against known data. Also, people really can tell what font was used. That gives them more than enough information to decode it.
But why are you giving people information in the first place? Never, ever try to distort information you should be destroying.