The first 6 digits of a card number is called the BIN code. That leaves just 9 digits that have to be spammed.
The fact that BIN lists are publicly available is reducing the space significantly.
I used to work at a big bank in the US and the parent's description sounds exactly like how it would work.
Bonus, if they can't separate which exclusions were from legitimate requests and which came from this script, they can't just delete those entries from the database.
Of course, no one should do this...
I think they would probably just declare them all invalid, and roll back to yesterday.
For Visa it was 835ms for valid, 762ms for dummy, prefix and check digit appears to be checked client side.
Also in infosec: what is old is new. We still find shitty comparison routines (timing attacks) and SQL injection... some day :)
Or more likely "someone will notice, eventually"
If the rand function produces uniform random numbers, then with enough samples the signal comes out ontop the noise.
If it is non-uniform, then with enough samples you can determine the non uniformity, and you are at square 1 again.
Use proper security instead of obscurity.
And it's not a thing anyone has a legitimate interest in submitting more than that per second.
I.e. the padding to add is (5 - duration_of_operation) with duration of operation being far lower than 5 s.
What would be a proper first step to harden API for timing attacks?
An easy mitigation would be to just drop the card number into a queue and process asynchronously without waiting and returning to the user.
An expiration date will get you a bit farther, but you really need the CVV also.
There's some exceptions (tokens etc.), but not relevant to this use case.
The net result of submitting all card numbers will not be "oh, well, I guess all card numbers are private now.." it will instead be "clear that table and start over."
Doing otherwise -> access in excess of authority -> CFAA violation
Just because you can easily walk through an unlocked door doesn’t mean doing so is always legal.
Maybe I’m misunderstanding.
It's like lockpicking a door lock. Even if you don't get in, I'm sure it's still a crime.
Who decides? On what criteria? Can you appeal? Are they elected or appointed officials? Who supervises the “list makers”?
Act of DOS could be considered damage, not to even metion opt-out from revenue source...
Still pretty expensive if you wanted to do every single Valid CC #, though.
Wasn't something I mentioned earlier but using the reCAPTCHA audio is also another solution for gcap. I haven't ever used it personally but always seemed like a cool idea.
It’s also very satisfying to know I’m not an unpaid mechanical Turk for google anymore and that it’s a machine solving another machine’s challenge.
This one in particular is simple enough that nearly any technique you wanted to throw at it would succeed with minimal fine tuning. I'd be shocked if it took an afternoon even if you'd never broken a captcha or done any image processing before, and that's without borrowing an off-the-shelf ML solution.
Plus, even if you had a 50% failure rate you'd just need twice as many calls. That's not trivial, but it doesn't really affect the viability of the idea.