But i wonder what the limits to effectiveness is on this attack. I usually randomly swirl around with a smear tool to blur out things...
But i wonder what the limits to effectiveness is on this attack. I usually randomly swirl around with a smear tool to blur out things...
This may be only in Washington and Idaho though, as there are several different legacy BofA backends as a result of M&A bullshit.
Also, not all online merchants use CCV. Also consider the risk of creating fake physical CCs, no address or CCV necessary.
Online merchants are supposed to comply with PCI-DSS - not store your CCV ever, never transmit your number unencrypted, never store cardholder information unencrypted, plus tons of management controls and audit controls over the same.
In practice, let's just say lazy programming is everywhere. I've seen many people who handle online transactions and violate PCI-DSS to some degree, including storing CCV numbers.
You're definitely right about adding entropy though, but why bother? Just blacking it out guarantees how much information is available - zero.