Non-US Cards Used At Target Fetch Premium
krebsonsecurity.com
krebsonsecurity.com
This is getting ridiculous! 1st Adobe who I will never do business with again (had to cancel my accounts & open new ones) and now Target!
Simple also sent me a new debit card automatically without prompting, their systems having noticed I'd shopped at Target last week.
The problem with the two factor system as you describe is that while it works for 'cardholder not present' transactions (and there already exist standard two-factor methods for such payments, not that many banks use them), it would make retail POS payments incredibly slow. You'd have to wait for a text/push, you might not have any reception, then you've got to reply, etc. This is one reason why EMV is, for all its failings, more attractive than mag-stripe: it is considerably harder and more expensive to clone EMV cards.
Just use a time-based one-time password.
It's instant, secure, and simple. And already available free in Google Authenticator.
https://en.wikipedia.org/wiki/Time-based_One-time_Password_A...
Just because a solution solves your use case doesn't mean it's a good idea. The fact is, this would be a total nightmare to bars and B&M retail establishments, to name two examples, and any significant change to the credit card system requires merchants to be on board.
The best solution for customers is still chargebacks. Unfortunately, merchants still have to eat the cost when a chargeback happens, which is why security provisions like chip and PIN typically come with the revocation of chargeback privileges. But if merchants are the ones driving these security features, they have absolutely no reason to go along with something that creates a worse experience for them.
Also, if you have this enabled, your purchase doesn't go through until you approve the charge. As for wireless reception... 4G & 3G solves that as it justs a text message going through.
Further banks who offer this could set a high default amount like $500 and the end user could change it to something higher.
Further, further as noted by another here, the user has the ability to enable this or not. If you know you are a irresponsible drinker then this would not be a solution for you. Also, if your passed out drunk how are you going to pay your bill anyway?
This is something I want after being hacked and a solution that would suit my needs and many others who choose it.
Anyone have any other solutions?
> Also, if you have this enabled, your purchase doesn't go through until you approve the charge
That's the problem. You already drank the drinks. How's the bar going to get paid? Even in a retail situation, the amount of time it takes for the SMS exchange to go through, or for you to argue with the person at the register about it not working, makes bottlenecks even worse and makes more hassle and more loss for merchants. Since merchants are the ones driving adoption of security features, they'll never sign onto something that doesn't help them.
> As for wireless reception... 4G & 3G solves that as it justs a text message going through.
How does that solve the problem? Lots of places have poor mobile reception.
> Further, further as noted by another here, the user has the ability to enable this or not. If you know you are a irresponsible drinker then this would not be a solution for you.
That's not the problem. The problem is that merchants can't control which cardholders have this feature turned on, nor can other customers. So as a bartender (not that I am one, but for sake of argument), let's say you forgot to charge your phone and it died and as a result I can't close your tab at the end of the night. What am I supposed to do? There are 20 people trying to close their tab at the same time. That's why merchants will never allow this kind of thing to be implemented.
> Also, if your passed out drunk how are you going to pay your bill anyway?
I'm not talking about "passed out drunk", I'm talking about "leaving the bar at closing time but still capable of closing the tab" drunk. Although if you are pass out drunk, the bar will kick you out and hold onto your credit card to make sure they still get paid. Otherwise, drunk people are perfectly good at signing receipts or remembering their PIN for their chip and PIN, or else bars wouldn't accept credit cards already.
> This is something I want after being hacked and a solution that would suit my needs and many others who choose it.
As I said, just because a solution solves your use case doesn't mean it's a good idea.
> Anyone have any other solutions?
Yeah: file a damn chargeback. Problem solved.
Failing that, chip and PIN for in-person purchases and 2FA for online purchases only.
That said, I'd still love to get proper two factor auth on online purchases.
I generally agree, but it would suck if I'm travelling and my phone isn't roaming.
They are not "buying back" anything. The cards can be resold at will.
I see you have never carded. The banks are searching by BiN to find their own cards, and according to Krebs, buying them back. They said they did this to avoid having to reissue cards during Giftmas which is their biggest shopping holiday thus saving money.
The question is whether the chip-and-PIN technology would have revealed less information (i.e. insufficiently much to allow online purchases, etc.).
What always weirded me out about Target is that they used the credit card number (or name, or something on the card) as the key into their "loyalty program". If you bought some generic drug last time, this time their machine will print out a coupon for the name-brand version. This always weirded me out a little bit, though there is nothing preventing them from just storing a hash. Of course, the average developer never stores just a hash, and here we are.
At least in the Minneapolis store I shopped at during the breach, it was a simple swipe terminal.
The shop was selling data stolen from the magnetic stripe of each card, which thieves can re-encode onto new, counterfeit cards and use to go shopping in bricks-and-mortar stores for items than can easily be fenced or resold.
Is that possible to do with a chip and PIN card? Most of the focus from these articles seems to have to do with replicating the cards and using the replicas in stores, not online.
I remember maybe a decade ago there was a kind of scare (well, at least the TV news talked about it) about YesCards, some kind of fraudulent EMV cards, but according to Wikipedia[0] it doesn't look like they would still work today.
[0] https://fr.wikipedia.org/wiki/Yescard (for some reason, the English article is deleted).
Chip-and-pin won't help you with online sales, but for any card-present sale (brick-and-mortar) it should ensure counterfeits cannot be used, and the PIN of course is the second factor to ensure only you can use the card.
When I buy something online using my CC, and if the payment processor supports that (mostly local/european shops), I get redirected to a page on my bank for verification. Some banks require the PIN to be entered, some others to enter your login credentials, some coordinates from your code card or even verify with a SMS code.
Not exactly using the chip, but it involves the PIN surely.
If an attacker intercepts that, they can get the account number from it and potentially use it for online purchases. But they wouldn't have the postal code or security code, which most but not all ecommerce merchants require.
It's a rather flawed system - there are strict protections around certain cardholder data like PINs, but none of that really prevents fraud since just the account number is enough to make certain purchases.
(Yes, this adds cost to the transaction. But as long as people want to take each other's money without permission, there is always going to be a cost to using money, whether it's an interchange fee, higher taxes, or just getting $500 bucks stolen on the subway from time to time.)
Just because its not a line item somewhere on your bank statement doesn't mean you're not paying for it.
However it isn't really used as a currency, and more as a transport mechanism for cash (seeing how Bitcoin isn't anonymous at all, I'd imagine the strongest reason for these guys to use bitcoin is you can't chargeback with bitcoin)