Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If it's possible for employees to be able to make such a mistake, that's a standard broken process. It should not be possible for them to reveal the last four no matter how badly someone wants them to and how clever their social engineering skills. It shouldn't be possible from a technical perspective, not from a "we told employees not to do this" perspective.


If you display 4 digits to the user for CC validation, as basically everyone does, then there will always be someone who can read those 4 digits and give them to someone else.


You don't need to display them to the user. The user can ask for them from the customer. The user types in the 4 digits the customer provides. The computer compares the two strings. The user need never see the real stored digits.


Sorry, in my argument I meant user with what you've called customer.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: