It's kind of silly though. They are no more "secret" than your credit card number itself or expiration date. Once you give it out once or hand your credit card to literally anyone, it's out. Now instead of acquiring N numbers, the hacker needs to acquire N+3 (or N+4) numbers.
Our payment system needs something like:
struct {
string credit_card_number;
string expiration_date;
string insecurity_code;
};
...to complete a credit card transaction. At some point that record is in a computer or in your restaurant waiter's brain, so it's vulnerable to exfiltration, regardless of what part of that record gets redacted for long term storage.We are living in a world with bozos in charge who can't seem to develop a secure payment system, so we as users need to simply assume that all information required to make a purchase on our behalf is public knowledge, and instead diligently check our records for inaccuracies. I don't sweat these "breaches" because I freeze my credit and review all my bank and credit card transactions daily now.