Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Call paypal and ask them which card you have on file, you cannot remember.

Exactly. I've done this before when services ask me for my full credit card number or expiration date (to verify), and I ask them for the last four digits (to remind me which card I used).

What PayPal did may be bad, but what GoDaddy did (use the last six digits) to verify is even worse.

If you know the last four digits, you have a better than 1% chance of guessing the previous two, since they are not uniformly distributed: http://en.wikipedia.org/wiki/Luhn_algorithm

(There are actually even more restrictions than the Luhn algorithm on credit card numbers, but I won't go into them here. Suffice to say, there's a reason than the attacker says he was able to guess it in a single try - he was lucky, but not that lucky).



The last 4 digits are known, and the first 6 digits are based on the type of card (VISA/MC/AMEX + Bank/Issuer), so are guessable. Apply the Luhn algorithm to these, and you're left with only 10-100K possibilities for the remaining middle digits.

If you're only required to specify the last 2, you can narrow it down significantly by only looking at valid combinations of those last 2, which is far smaller than 100.

I've written up some of this here: http://tech.bluesmoon.info/2011/01/how-guessable-is-your-cre...


You are right that Last Six is a miserable password.

One correction thought: the attacker didn't guess the two digits in a single try, they guessed them in a single phone call. The GoDaddy agent allegedly let them just try numbers until they got it.


Someone should just record a video of themselves doing it to their own account and post it online, that would be proof enough I'd think.


Unless you know every other digit in the card number, I don't see how knowing the luhn algorithm is going to narrow the possibilities of guessing just the two digits.


Also credit card can never be used by itself for any purchase, ever. You must have the name, expiry date, and if you're doing transactions online, often the address and ccv2 as well.


More than likely you dont need the name or cvv, sometimes not even the expiry.


As far as I know, not true. Merchants get discounts for asking for more information, but it's not strictly required to process your card.


It depends on the bank. Some require more data than others. In either case, though, if the transaction turns out to be fraudulent, it's the merchant that pays, so the merchant has a strong incentive to ask for more rather than less.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: