Takeaways from the $566M BriansClub Breach
krebsonsecurity.com
krebsonsecurity.com
I'm just reaching out for anyone who knows about any grand plans, initiatives or rehabs of how credit cards currently work. Keen to read more.
You have 16 digits on a Visa/MasterCard, the first six is the bank identifier and the last is a checksum digit thus you have 9 digits to "waste" -- and you can recycle them.
The impression I've gotten is that since most of the costs of fraud are on the bank, rather than the cardholder, there's not much incentive for the cardholder to go through the trouble of using single-use cards. And so it's a better investment for the bank to develop good fraud detection algorithms.
In my anecdotal experience, the fraud detection has gotten really good. Every time in the past decade that someone's gotten hold of my credit card number, the bank's caught it nearly immediately.
I've had BoA fraud detection ping me about a monthly rent check before, so I'm not sure it's really good.
Funnily enough PayPal and Stripe were lobbying against this "harming of consumer experience."
Active confirmation of purchases would be great if it were available, but I. Not aware of any US card issuers that allow you to opt-in to such a service.
Krebs should publish those card numbers to light a fire under the feet of the bankers to re-issue the cards and get them to demand better security on merchant terminals or servers or wherever the info came from. Of course he should publish only the numbers, without the associated names, CVVs, expiry dates, PINs, or other security info.
I don't think there is a risk in publishing just numbers, is there? The search space for valid card numbers is so tiny that I find it hard to believe that anyone could generate a false transaction with just the number and no other associated info.
Krebs could go a step further and provide a verification site à la haveibeenpwned.com where your enter your card number, or the last ten digits or something, and it tells you whether you've been pwned.
A good podcast I would recommend is called dark net diaries. They have lots of episodes on cryber crime. Episode 32 specifically talks about carding and how the secret service took down a guy who acquires the credit card numbers. Most of it involves putting malware on point of sale machines or hacking companies.
BTC is really "psuedoanonymous" because while you can certainly trace my transactions if you know a wallet address, you still have no idea who or where I am as long as I do not reveal that wallet to be connected to any "real world" identity.
This is still not easy though. For example, if you're serious then you must only transmit transactions within Tor, otherwise the originating IP may single you out. Ideally you should use different wallets for each transactions, and only pool them together after they have each been converted to XMR or similar.
There's lots of gotchas but frankly it's a decent system.