Japan facing credit card number shortage
mainichi.jp
mainichi.jp
Also, we still haven't had an easy to use open tool set to make usage of Public Key Cryptography friendly to average Joes. No, GnuPG doesn't count - it's hard to use and cumbersome to configure it securely. You need to be a cryptographer or a mathematician to pick the right parameters in order to stay current and secure. Definitely not friendly even to most programmers.
Obviously, using government-controlled PKI for communications would be unwise, but there's very little risk to using government PKI for financial transactions as governments already have warrantless access to this data.
Even if you don't have to show government ID for every financial transaction, you need to show government ID (and, often, a lot more government paperwork) to open a financial account that can be used to make transactions. Your ability to move money is entirely predicated on the banks knowing who you are by linking your accounts to a tombstone government identity document.
Using PKI controlled by government to authenticate identity for transactions doesn't give government any more control over your affairs than it already has. All it does is add one more layer of authentication to the transaction process by allowing all parties involved to verify that their counterparty is the legal entity they claim to be.
Whereas the whole point of a public key system is that nobody needs your private key. So we don't need to provide individuals and businesses with a way to give their private key to somebody else. The only reason you'd give your private key to somebody else is because you want them to seamlessly impersonate you forever, so there's no need to make it any easier than, for example, giving your kidney to somebody else.
Concrete example: A WebAuthn/ U2F "Security Key" offers no way to get the Private Keys out. If you want to "steal" the credentials used to get into my GitHub your best bet is to somehow trick me into physically packaging up the USB authenticator itself and sending that to you by FedEx or something. Or maybe you could try putting a knife to my throat or something?
https://en.wikipedia.org/wiki/National_identity_cards_in_the...
I have that!
> and all you will have achieved is replicating the user experience of bitcoin.
I've never used bitcoin or any other cryptocurrency. What's the user experience like?
I would describe the first-time-user onboarding procedure as "complex enough that it's unlikely to become mainstream"
Onboarding is elaborate to avoid fraud, but not really complicated, and basically a necessity if you don't want to have to go to a bank office to manage your account and make transactions.
It is a pretty secure system I think, but government procedures make it a pain to work with.
This also makes your next sentence nonsense, anyone advocating for PKI is advocating for a technology that has trusted authorities, that's how it works, it's as though you claimed computer evangelists don't like mathematics because it uses symbol manipulation.
And then it makes your next sentence nonsense, something like Signal isn't a PKI, it has no CA role, who "Janet" is on Signal is only a matter for you and Janet. Signal also isn't purely TOFU, you can insist on manually verifying every identity just as you can on SSH.
But even though I believe the Web PKI is the only successful public PKI there are plenty of other PKIs in use that are successful in a narrower sphere, and we're already in a discussion thread about such a sphere, the global banking system.
† The Web PKI isn't strictly just a PKI for the World Wide Web, it's actually a PKI for TLS services on the Public Internet. But it exists only because Netscape built SSL, and in practice its oversight is from the major browser vendors (most notably Mozilla but of course also Microsoft, Apple and Google). There was once a good chance the only TLS client implementation you had with any useful PKI enforcement was your web browser, today it's likely other tools on your system also do this... but always relying on the Web PKI.
And also just as simple to use.
So some aspects of our products dont “need a blockchain for this” but the proliferation of standardized signing tools and size of the niche has made it extremely viable to cater to that market.
PGP had 30 years to get anywhere, and all we have are some pretty bad, cumbersome businesses releasing poorly integrated signing software on modern OS’ that even privacy advocates can barely tolerate for their email and other messages. People want to try to say the same thing about cryptocurrency over half of a decade or a whole decade but they’ll just have to wait for the Ivy league business school case studies to start coming out about the rest of us that have already figured this out for business.
Turns out changing consumer behavior isn’t hard when there are economic incentives to do so that benefit the consumer.
You can't do crypto with dumb block storage.
But if you have a chip you should absolutely do _something_ smarter than storing and reciting the number verbatim.
I don't believe the majority of fraud is stolen physical credit cards
Why not allow plugging the card into the computer just like a yubikey for online payments? It would be quite difficult to pull off, but credit card companies can save a lot on fraudulent transactions if it is implemented.
And as for transactions on mobile phones, most of them have NFC as well; contactless payments could work there too.
In most countries, the card number is only used for online and phone transactions. There's probably no way to do better than this without abandoning cards entirely in favor of some kind of device (or app) that has enough of a user interface to do a human-readable challenge response.
we don't use a pin, because that doesn't help with fraud. most fraud is either online, or someone at the store, who can easily skim or see your pin. online you can use 3dsecure, which has a pin.
processing a transaction doesn't mean your money's gone. you can dispute any fraud charge for 2 months. so the pin doesn't do anything. and for bank accounts, where it's debit, and your cash is immediately taken out, we've had a pin since before europe had an atm card.
I think it's just not widely known about/common usage in the US even though the infrastructure seems to be widely there.
The rest of the world reached that point around 15 years ago, including countries with high credit card use (UK, France) and high debit card use (Northern Europe).
Right now all of the burden is on the credit card companies. Any fraud is their liability.
If we switch things up, and implement something like passwords or pins, WE get the liability. That’s worse than our current situation. And given how badly people get hacked or phished, all it means is that consumers lose.
Right now, those “magic little numbers” work great, and in the case of fraud, we are protected. I don’t want the situation to reverse itself and have us the first to suffer from fraud.
This the way card networks have encouraged migration to systems that support tokens and cryptograms to limit fraud.
See https://www.creditcards.com/credit-card-news/understanding-e...
For card-not-present transactions (i.e., all online credit card transactions) the liability is the merchant's. There is no recourse for a merchant who is a victim of a stolen card, the money is simply removed from their account.
Tell that to retailers who lose a gazillion dollars to fraud reversals every year.
so a system that prevents them losing a gazillion dollars is available, and they opt to instead lose the gazillion dollars. it's their fault, and they should lose that money. we don't need to tell them anything -we just need to point and laugh.
PIN in stores and 2FA online is already the norm in the developed world. It didn't exactly cause a disaster for retail.
There are a few countries where it still isn't completely rolled out (US being the most notable one) but those are now outliers.
> customers are generally happier without it
Again I think this perspectivve is US centric and not global (?).
I'm not in the US or talking about the US per se.
I as a customer want 3D Secure because I don't want to deal with fraud at all but AFAIK it's not that liked among users. And I did run into issues where the 2FA setup my bank offered took a physical letter to initialize/reset and I couldn't actually buy flight tickets I quickly needed (ended up changing cards). So I can sort of see how people can get a bit annoyed as long as 3D Secure is a bit frictionful.
Online businesses would like it if it helps them avoid fraud as well. The problem is that conversion rates drop and so only few businesses implement/enforce it unless it's the law (see EU). Given how simple it is for a customer to ask for a chargeback I don't think there's a clear winner here for using 3D Secure except for acquirers and brands. Issuers don't really gain anything either given their already strong position when handling chargebacks.
Unless you can eliminate fraud, those are basically your two choices.
Which is exactly the purpose of good security measures.
Bad or nonexistent measures and an insurance against fraud slapped on all prices is a local maximum. Good security measures which really push back the fraud and allow prices to drop the insurance premium is obviously a better local maximum.
You also don't have to eliminate 100% of fraud, just make it so rare that you can basically ignore the risk because it happening to you is as unlikely as being struck by lightning (or any other risk of life that people are comfortable to ignore due to it being vanishingly small). The classic credit card fraud with magstripes was the exact opposite of that: there was almost no credit card owner who didn't get hit by it, and while people generally didn't lose money due to reimbursement by the cc companies, they still lost time and nerves over some stupid interruption in their lives that was entirely unnecessary in the first place.
I myself had one of my cards suddenly deactivated by the bank because of alleged fraud (it wasn't even real fraud, just some heuristic going crazy over an actually intended payment). I was on a cruise ship in the Caribbean sea when it happened and all of a sudden couldn't pay my beers with my ship card anymore. Fortunately I had a second card with me that was working so I continued using that, but in order to switch my onboard expenses account over to it I had to spend some time at the customer service desk on the ship, where there was a row of passengers standing at phones, occasionally speaking with someone in various languages, but most of the time they seemed to be waiting in silence for some kind of response. It took me a few minutes of overheard conversation until I realized that these guys were in the same spot that I was, but less well prepared; they didn't have another credit card with them and thus had to call their banks back home in order to get them to unlock their accounts again.
If you don't keep your card safe, it's your liability, just like with passwords. Read the manual.
State orgs wouldn't surprise me in the least tho.
For what it’s worth, in the US, chip is pretty much everywhere. Main difference is that it’s chip and signature vs chip and pin. I wish we’d switch to pins as well, but it’s not like it’s the dark ages or anything.
At least that's my understanding of it, might not be that clearcut.
Issuers will start to decline card transactions for any merchants that submit payments that haven't gone through 3DS.
https://breakdev.org/evilginx-2-next-generation-of-phishing-...
Instead banks should use WebAuthn. WebAuthn's credentials are directly bound to the DNS name. So anything that involves fooling the human like a phishing site can't work. The only site your authenticator can give the real-bank.example credentials to is... real-bank.example.
Not to mention that in order to have a decent WebAuthn experience, you need a Yubikey with NFC, which go for 30-60$ if I remember correctly. Cost of authenticators is why everyone switched away from RSA SecurID.
I don't see what a Yubikey with NFC is getting you here. For a laptop/desktop user any of the Security Key products in an appropriate USB form factor (USB C for some newer laptops otherwise USB A) would be suitable.
The high end phones are or in the case of the iPhone very shortly will be WebAuthn platform authenticators, there's nothing extra to buy. Apple released a video of the pleasant UX journey they want to promote, obviously being Apple it doesn't actually say this would work on non-Apple devices but I use it already so I know it does.
Use using credit card numbers is IMHO a very conventient way of paying with the liability for fraud being setup exactly in the right customer-friendly way.
1. I have a dongle that creates a number code when prompted. 2. My phone is set up for 2fa, again through the bank. The screen shows the same keyword as the website and I enter a pin into my phone to authorize the transaction. I can't remember if I need to use the fingerprint option on the phone or if that's just for the bank's app.
And anecdotally, I cannot speak for the entire world, but European banks have no problem disputing fraudulent charges that happen overseas.
Obviously I can block it for all transactions abroad but that doesn't seem like the best idea either.
The only working solution is to generate temporary card numbers for international transactions, but that leads to the shortage issue.
I admit the ability to reverse a credit card payment is nice, but that mostly means that it's also a risky form of payment to accept for the merchant. They might send the goods and still have the customer challenge the transaction. And of course you still pay for this; credit card transactions are relatively expensive.
I absolutely agree that banks should not be the ones discharged with consumer protection but unreversible payments are not nearly as beneficial for consumers even if insured in some ways by the government.
I'd rather have a market protecting me with verified reviews and as close to zero costs for sellers. Not unlimited refunds that put small sellers out of business, leaving only Amazons and eBays.
Banks have developed and signed off on the ideal system; THEY are saying the system is safe, therefore THEY are responsible if something goes wrong with your payment.
Smaller specialty game webshops sadly don't.
IIRC, SOFORT used to just ask you for your banking credentials, and then it would just log in to your online banking and put a regular transfer through.
Amazon.de does a nice job by offering direct debit: you put in your IBAN and they automatically debit your account, which works across SEPA. But this seems very fraud-sensitive (you could put in anyone's IBAN), which is probably why it's not more common.
Not using a CC is just leaving insurance money on the table for no reason. I've done chargebacks after getting fraudulent goods transferred over with relatively little hassle, and would probably never managed to reverse a bank transaction.
The thing is something that works, and works well is hard to displace. Especially when it makes money. And when you are running a business and you have to choose:
- keep making money
- update system that is making money and hope it will work and it will stop making money
What really is the sane option here?
Also one other point the credit card companies are way better option for customer over say paypal.
If you're doing it over the phone though things like public key won't really work - to be long enough would make the numbers impossible to read out reliably, let alone the calculation I would need to do with my private key to prove I own it.
It's how to authenticate and authorise an offline cardless transaction that's hard
Visa does support this scheme and I hate it when it happens. I try to use my bank password the less possible. I also believe it's a huge phishing risk as people don't look at the URL.
I personally prefer that the bank assume the current risk. It's not like it's making them bankrupt to do it right now...
Is this really a thing in the USA?
I feel for you guys.
Benefits?
What I really don't understand is why the article makes it seem like a national problem given the prefix is assigned to the companies, rather than countries as such. (Although companies will get ranges and then assign specific IINs countries normally)
It seems that IINs are undergoing changes anyway and April 2022 is a deadline for everyone to support 8-digit prefixes correctly.
In reality there are so many POS devices out there that don’t support 6 digits, it actually ends up being safer to use a 4 digit PINs because the 6 digit PIN fallbacks are completely insecure and unreliable.
What are the risks here, and why aren't they already present by someone generating credit card numbers with a RNG? AFAIK credit card transactions are authenticated by at least expiration date and cvv, so there isn't a risk of reusing credit card numbers.
>and a source close to the credit card industry said, "Increasing the number of digits is the only real way to deal with the problem. There will likely be a shift toward increasing the number of digits in the first half of this decade."
ipv6 deployment all over again
Also, I'm not enthusiastic about trying to communicate an IPv6 address over the phone to the wage slave working at the pizza joint. You'd have to implement one of those address-to-word setups, which would make for some amusing card "numbers". How would you like getting a card with "chinky challis uta ablow wiry rehaul a carotin" on the front?
Something like: http://jubei.ceyah.org/cgi-bin/ipv6toenglish
All in all not a bad direction to go in. I wouldn't really miss phone payments.
After doing that for a week or two (I was bike commuting at the time), I had it pretty much memorized.
But it'd take at least 3 generation to use in non-english speaking country since in different languages same letters might be pronounced vastly different. Then you have immigrants and foreigners who might now know this alphabet so clerks would still be able to recognize ad-hoc and NATO alphabet. In the end, it would extend requirements while not providing universal benefit.
Phone service is always in a specific language, I don't see why the use of such alphabets would be harder in non-English-speaking countries than in English-speaking ones.
Depends upon how it is implemented as could go full on 1984 very fast without that ever being intended.
The whole aspect of a static fixed CC number you share with people is what really needs to change. A One Time CC per transaction would be more useful and negates many potential issues in a way that protects the customer and in turn the bank itself.
That's what Google pay does. It generates a new credit card number for each transaction that charges the CC you have on your account. It's kind of like a password manager for credit cards.
If we allow for the representation to be 0-9 and then another ten letters selected for uniqueness and clarity, overlapped with appropriate non-roman pictographs, etc, the same 16 characters jumps to 600 quintillion range, or about 60 bits by napkin math.
That's more than realistically enough for hundred billion people to each have millions of real payment IDs with millions more one-time use ones that contained some sort of transaction hash for authorization.
Which conveniently fits in a 64 bit word with some left over. I suspect someone involved in the payment space already figured that out a long time ago, but no cataclysmic event has yet happened to de-rail the existing money train.
If you wanted to do that in IPv6 you'd still have the upper 64 bits left over :)
Issuers simply need tabs on this. This means, a) they only allow this for merchants that have had previous transactions. b) They reset this when a card is reused (owner of the number changes).
Ultimately you just need a system that turns on stricter checks when reuse-induced issues are likely.
Once a card is reused the issuer simply needs to turn off the recurring billing laxness until the card gets close to expiration again, i.e. a few years, which should suffice to detect any sort of problematic patterns.
This wouldn't affect the customer at all as any legitimate transaction would have been made with up to date expiry and CVV.
If the same number were reassigned to someone else, the subscription wouldn't transfer.
These subscriptions are supported by look at if the payment appeared as a “card-on-file” payment, and many banks will just keep accepting charges to expired cards.
If you’re lucky they’ll be using the PAN + expiry date to uniquely identify the card the payment belongs too.
The CVV isn’t stored by the merchant or their processor, and is only used for the initial checkout flow.
In the EU this sort of behaviour is now heavily frowned upon, and with the slow roll out of Strong Customer Authentication will become unacceptable. With banks needing to prove that they’re compliant.
As for the rest of the world, regulators don’t always act with the interest of customer in mind. The US has a few notable examples of regulators protecting companies rather than consumers.
The right solution is not to have a number that you give out to random people who then gain access to your money. Also the righ way is not to trust the few giant credit card corporations to move all the money in the world
The right way (EU is introducing it) is that you get a payment request that you can paste into your bank app and there authorize it. See SEPA or PSD2
The customer manually creates the billing agreement with a specific invoicer at the customer's online bank, and can set payment limits, notifications, and either automatic or manual approvals.
These are distinct from the "SEPA direct debit", which is not used in Finland domestically. Due to their rarity I think "SEPA direct debit" payments are usually/often disabled or each payment requires a specific customer authorization via their online bank (so IBAN of such an account cannot be used to get money out of the account).
Classic example of this is Tesco bank where they only checked that the expiry date was in the future, not if it actually matched the card.
They also made a number of other insane mistakes, and FCA report does a good job of explaining them [1]
[1] https://www.fca.org.uk/publication/final-notices/tesco-perso...
Is it not possible for an issuer to get a second prefix if they run out of digits?
I also wonder if credit card numbers aren't living on borrowed time anyway. Instead of adding more digits it might make sense to remove the digits entirely and only allow token based transactions. This does assume we figure out a way to do online purchases not using the digits.
Someone else said the number is 'hidden' from the users but it's not hiding versus not hiding that's the problem. It's that for e-commerce the human has to transcribe the number by hand. You can't hide it, except via another system.
AFAIK, that's how the first version of 3D secure worked: you were redirected to your bank site and authenticated the payment there.
Meanwhile, with my Samsung phone and its mag strip emulation, I can use my phone nearly everywhere anyway even if the store doesn't want to support NFC.
During the pandemic, I haven't used cash for the last 6 months.
https://en.m.wikipedia.org/wiki/International_Standard_Book_...
When possible some more complex key/token is passed, maybe via nfc, or some other mechanism.
When not possible, a 4x4 number is generated and challenge/response is required to confirm intent before approving the spend.
You pay by logging into your bank account.
Credit cards - and payment methods generally - are in their Cambrian explosion phase right now in Japan, particularly given the pandemic. Every company, big or small, is pushing their own. I recently had to open a new credit card because the gym I wanted to join only accepts payment via their partnered credit cards. It came with a linked electronic money card (as well as having native integration for a different electronic money format) that has what looks like its own 16 digit credit card number, presumably for internal payment infrastructure reasons, and an offer to apply for a separate linked credit card for shopping in China, three other kinds of linked electronic money cards (one for a supermarket chain, one for a local transport network)...
Every shopping mall is pushing their card. My phone provider offered two olympic tie-in cards and a regular version (that would actually save me money if I could face going through the application). A theatre troupe I follow has a deep partnership with a card issuer and has their own branded cards. Bands have their own cards. Virtually any outfit with a loyalty/membership card is trying to turn it into a credit card. And so people can easily have multiple cards that they never use, because their loyalty card became a credit card but they're still only using it as a loyalty card.
I wonder how big the incentive is, and if anything changed to enable this. As for the incentive, I'd guess they get transaction fees cut from some ~2.75% to 0.5%ish with their own card, and then some kind of additional cash (maybe $50-$300?) from the issuing bank for gaining a customer?
The way that the 16 digits are allocated is defined as per https://en.wikipedia.org/wiki/Payment_card_number#Structure
So of the 16 digits for the majority of cards:
Digit 1-6(8): Scheme and issuer identification Digits 7-15: Account identification Digit 16: Check digit (Luhn algorithm)
So most issuers have 10 digits to "play with" to identify the account.
So Japan is either running out of issuer identifiers, which sounds excessive, or they have been allocating them badly.
There's also a lot of "virtual credit card" offerings right now to pair with peer-to-peer payment apps. I imagine that those need to get cycled through frequently.
8 is not an exageration.
Issuers won’t issue every number, because that would make it trivial to enumerate valid card numbers. I know that PANs are printed in plain view, but they’re considered sensitive.
> I also wonder if credit card numbers aren't living on borrowed time anyway. Instead of adding more digits it might make sense to remove the digits entirely and only allow token based transactions.
It’s already happening! The tokenisation tech that powers Apple/Google pay can now be used by merchants. Buts it’s currently got very low uptake.
To give the European perspective, there's much less "churning", available, partly because of laws that limit transaction fees. Sign up bonuses are usually around $50-$150, and many cards have no benefits _and_ an annual fee. Cashback, if you do get it, is usually 1% or less, with exceptions going up to 1.5% or so.
For no annual fee card, Signup bonus without paying is around 1000-9000 JPY depending on running campaign. Some cards also offers bonus with paying, rate is vary but around 4-20% and max bonus is around 2000-10000 JPY.
I'm not very familiar but for annual fee card, signup bonus without paying is around 5000-30000 JPY and bonus with paying is similar rate and max is around 10000-100000 JPY.
To get max bonus, you should use cashback sites.
For transaction bonus, 0.5% return is basic (card from bank, gold card, random shop's card), 1.0% is standard for return-oriented card (like Rakuten, d-card), 1.2%-1.5% is top return-oriented card (like Recruit). Most return-oriented card is no annual fee.
* Now 3% is super prominent top return rate by LINE Pay card (that's no annual fee) but it's run by campaign until 2021/05.
Cards for airline is different story, maybe 1mile/100 JPY is good return on annual fee card (I'm not familiar but IMO airline card isn't majority due to less people travel to overseas).
Transaction fee for merchant is rumored below 2% for big player (like 7-11), around 3% is standard for real shops. Old contract may charges much more fee.
Big difference with US is that Most cards is monthly-clear style so less revenue from revolving credit fee. Card issuers trying hard customers to using revolving payment.
[1] https://en.wikipedia.org/wiki/Payment_card_number#Structure
It still seems like a comfortable amount of numbers.
The main problem is that in Japan everybody has like 5 credit cards, because every big company has its own financial branch and issues cards (maybe to profit from a "reservoir" effect of the accounts?). So you have a credit card linked to your clothes shop, one from your supermarket, one from Rakuten (Japan's Amazon), etc. You get points when you buy things from the company linked to your card. I don't know how it is in US, but it certainly isn't like that in France for example.
This is a fascinating departure from my expectation, because when I was in Japan, I distinctly noticed that credit cards were not accepted everywhere. One could load money into Suica/Pasmo cards and use those at convenient stores, but I learned that carrying cash was imperative -- Japan seemed very much to be a cash-oriented society.
So they are now in the absurd situation where they do not have enough credit card numbers, but still many shops do not accept card payment.
(I edited my previous comment for realism: it's more 5 cards/person than 15)
It's more 5 cards than 15, I admit... I edited my comment accordingly. It still seems a lot to me, why not just one?
We have a credit card for a mall, only for the free parking at said mall. We never actually pay anything with it, only scan it in the parking garage.
That said, cashless transactions have gone way up in the past year though, though the introduction of PayPay QR code payments (which means that waaay more small mom&pop stores accept a cashless payment system since adopting it is basically free), the government 2-%5% cashback cashless incentive that ended earlier this year, and the coronavirus.
It will be interesting to see the new cashless usage numbers next year.
Japan has a population of 150M.
If you can't give folks a number from SIXTEEN digits - something is wrong with the folks giving out the numbers.
Some answers to the excuses. The 6 digits at front, if a company legit runs out of numbers, ask for another prefix.
The reality. Instead of using the numbers properly (random ID to tie to a user account) they are probably putting some kind of structure into the digits that results in very inefficient use.
These are the 10 digits available PER PREFIX!
1,234,567,890
Even with a check digit you are at a billion numbers PER PREFIX! You can't get 125 million folks into this address space?
Absolutely pitiful.
Come ON! STOP with these clickbait / alarmist headlines.
I think some people are now using a new card number per transaction, with these disposable card numbers, aren't they?
https://www.theukdomain.uk/virtual-credit-card-numbers-every...
Credit card numbers are assigned by payment organizations in the form of prefixes (BINs -- https://binlist.net/, https://www.bindb.com/bin-list.html)
The worst that will happen is that Visa/Mastercard will issue more BINs to those organizations. There isn't going to be a shortage of credit card numbers.
The difference is that Credit Card numbers are much easier to manage. The routing tables for Credit Cards are distributed by Visa/Mastercard to acquirers in the form of BIN files and it is extremely easy to add arbitrary mapping. So if someone gets an unnecessarily large prefix like "1" then the next day you can change it easily to ten prefixes "10", "11", "12" and so on and have a different organization for each.
Or equivalently it increases the length by the length of the checksum (usually 1 for credit cards) and doesn't otherwise affect the available numbers.
Think of all the extra information we could encode in the number!
They also cannot ask for an extra prefix, since all their forms and systems assume the same prefix is used everywhere.
(Note, I have no idea if this is actually the case, I’m just extrapolating from my experiences here)
The solution to reuse a number is bat shit crazy. Perhaps they can use expired cards (and not cancelled).
In the long run the sensible solution (just like IP addresses) is to move from a "IPv4" system to a "IPv6" that will largely multiply the available numbers per country/bank/entity and will solve the problems, for the next many decades.
For example, Mastercards start in the range 51 to 55. That leaves 4 digits of the 6 digit BIN to allocate to MC issuers. So that's a total of 50K issuers of MC world wide, then each of those issuers can have 1 billion cards.
So each issuer of a MC in Japan can issue a card to each member of the population and only use an eighth of their allocated range.
The problem isn't the individual card account ID, from the article, it sounds like Japan has been allocating too many BINs.
Assuming your calculations are correct, this means an issuer can only emit 8 cards in average to the total population.
Cards have an expiration, people lose them, break them, they change and come back to banks. For the main issuers it’s not ridiculous to have to issue 20 or 30 cards per account to a user in their lifetime.
Then people have multiple accounts (e.g. my mortgage was on a separate join account).
There’s just enough normal circumstances to run out of numbers, not even considering freak cases.
You understand that every possible prefix / range has a billion numbers minimum? That japans population is only 125 million?
And actually - you can near randomly assign numbers if you wanted, looking up card issuer is not difficult. Can basically issue card numbers in blocks of 100 if you wanted to reduce lookup tables a bit. This is already happening and available actually. Visa and other (apple) offer tokenization services to randomize your card number. Every phone number uses this type of system to enable number portability as well (you can take your phone number from t-mobile to sprint).
With 16 digits (1,234,567,890,123,456) you have 999 trillion numbers you can assign. As my original comment pointed out, the idea that we are running out of credit card numbers is absolutely ridiculous.
Amex for example have got only 6 digits per prefix. 15 digit card number, 6 digit BIN, 7 digit account number, 1 digit representing which card it is (1 for the first, and it gets bumped up with any replacements), and 2 digits for the position on account, allowing you to have 99 supplementary cards on account that can then be identified.
Obviously this is just Amex and it's an absolute non issue for them seeing that they own the entire 37 and 34 range, but I can assure you that virtually no financial institution actually use all of the 9 digits like that.
I hate saying this but I'll say it anyway, as someone who has spent considerable amounts of time trying to get things done in Japan, I would say that you're right.
There is likely some ridiculously inefficient process which obviously requires changing but for cultural reasons it's hard to change things so they're stuck in this strange situation.
This is literally a non issue. Amex cards have 15 digits and a 4 digit CVV I've literally never had any issues with it.
And the acceptance was great, when I was in Japan I never had to resort to my backup MAsterCard.
This is just one of those things that looks like it should be last_number += 1
But then again if they used something like a 32 bit int and don't us sequential numbers, I suppose retrofitting for a 64 bit int might take a decent amount of work.
Eliminates risk of 'stealing' a credit card, mostly.
But it would use a butt-ton of numbers. Maybe a UUID?
Sounds like it would take longer at checkout though?
Lets try to imagine a better future?
But merchants don't implement it... because it's an extra step and consumers don't like it. The very last thing a merchant wants to do is put an extra step in front of someone just about to buy.
Do you go to an app? That's a separate step. Consumers demonstrably don't want extra steps.
Do you integrate it with the merchant and do it automatically? Then it's no safer as there's no authorisation.
It is very neat although I got into strange situations a few times when I needed to prove I was the card owner for a refund or for insurance claims.
Billing address verification is extensively used in the UK.