Smarter saved cards
stripe.com
stripe.com
How can I make sure that an online shop will not be able to draw money off my card after the expiry date? If I understood the technical magic here, that would help.
(For people outside the US, both Target and later Home Depot got hacked. Many banks proactively replaced their customer cards if they had transactions at those stores, which meant new numbers, expiry and CVC even if no fraud occurred on the card.)
At least with my banks, when they send me updated cards, only a handful of the digits actually change and most of those changes have tended to be in the last 4 digits — which Stripe lets you see, along with the updated expiry month/year.
At this point, it's just a matter of brute forcing the remaining permutations. Am I misunderstanding something or are there countermeasures to protect against such attacks?
However I have never had a vendor try to rebill an expired card, even though the CVC's and the expiration year are the only data which changed.
We spent a couple of puzzled hours wondering how in the world Google could have possibly gotten that information before concluding that it must have been a service made available to them by the issuing bank -- Navy Federal in our case -- but not having any real way to confirm it.
We'd scoured the paperwork that we did have and found nothing indicating those terms anywhere, and shockingly, this is our first indication that such a service exists.
Note, I did not call the bank.
I realize it costs stripe money to have that happen but from a security standpoint and for purely cleaning up rouge charges every once in a while some people like being able to start over.
Does whatever mechanism the bank<->Stripe communication uses know not to notify Stripe of the new details if the card is being replaced for fraud rather than natural expiration?
I expect somebody on Stripe's end has thought of this and figured out how to handle it, I just don't know enough about how this kind of information-sharing works to know how they solved it.
Stripe handles the entirety of the card processing infrastructure, the website (user of their API) can only talk about cards in an abstract sense, they can't get details from it. So businesses using stripe can't leak those sort of card details because they never had them (although a form of java-script "skimming" of the card details might be possible, like skimming an ATM).
If a business using stripe is accused of fraud (because improper charges show up on a customer's card) then stripe removes/limits the API access from that business (until they fix their infrastructure, business practices, or pony up the money, etc). This has nothing to do with having your card details stolen, this is them lying to you and stripe (and they can be sued; unless it was criminal/hacking). This is Stripe's API being misused.
If your card details have been stolen you merely change the card's details. They have only stolen the information required to impersonate you (this is, of course, because cards are poorly designed: they are non-active and don't do any sort of active cryptography, no way to verify physical ownership). Because Stripe has relations with these processors and banks they can be trusted with (limited) access to the information behind the card. Think of the card as a time limited API token. Just because the token was stolen doesn't mean all the actions taken by that user token were fraudulent, and if properly setup, those actions can continue. Of course the user must still be vigilant with fraudulent actions taken on behalf of the card (but at this point they are easier to notice, and the bank will be more vigilant), and those relationships Stripe has will allow it to cancel, pause, or verify any transactions that may have been initiated during the period after the card was stolen.
Having the cards automatically update is a game changer.
Can the next thing on the list be a way to present Stripe Checkout with a customer ID, and have Stripe handle the rest (ie. cards stored, which card to use, updating expired cards)?
Currently, the "remember me" function causes extra friction and doesn't allow for services that already have the customers phone number registered - and Checkout is meant to be straight forward.
Appreciate this isn't a feature request thread, but as you're looking to make the process simpler for end users, helping sites handle repeat customers in a clean, simple way seems like a big win!
Is this feature pretty unique to Stripe or do competitors also have it?