Hacker Newsnew | past | comments | ask | show | jobs | submit | skeuo's commentslogin

The real solution here is to have contactless chip & pin systems at the pump, but apparently that is years away because of cost. In the meantime I find the best way to monitor my CC expenses is to enable SMS/Push alerts for any transaction above $0. This way I always expect to get an alert at the point of sale for any transaction. Anything unknown is a red flag and it also works well for subscriptions that I may forget about and want to cancel.


What service or cards offer SMS alerts for any transaction? The best I have it American Express which will alert me only when I have a transaction over $10. V.me by Visa used to offer an alert service for any amount and it was great, but unfortunately that service got shut down.


When I added my American Express card to Apple Pay, it started sending me push notifications for every transaction. It's crazy how fast it is, before I can even put my card back in my pocket my phone buzzes. You see pre-authorizations too, so when you swipe at a gas pump it usually shows a $100 authorization check.


Is that not only for Apple Pay transactions? I'd expect payments made directly w/ Amex wouldn't buzz you.


For Amex, adding the card to Apple Pay will notify you of all transactions.


Does it have to be SMS? My Simple card notifies me every time the card is used. https://www.simple.com/


Any push notification would be ok, but SMS is preferred because it's more reliable for me. The Visa service V.Me was great because you could use any card, even all the specialty rewards cards, and they didn't even have to be Visa cards!


I have "in-app" alerts (push notifications) enabled for a Discover card and two AmEx cards but they are set at relatively high amounts ($500, IIRC). I haven't checked to see how low they can be set. That requires you have their apps installed, however. I'm not sure if you can get them via SMS.


All the banks I deal with offer it. Chase. USAA. Citibank. Capital One.


> The best I have it American Express which will alert me only when I have a transaction over $10.

You can configure that amount in the online settings; change it to $0 and you'll get an alert for every transaction.


I don't know about alternatives, but I noticed that when I hooked up my Amex to Apple Pay, every transaction shows up as a push notification on my iPhone, nearly instantly.


I believe this is the case with any credit card placed into an Apple Wallet for Apple Pay, regardless of the card issuer. Every charge initiates a notification.

I found this useful when I was wondering about a charge that I wasn't expecting pop up. I logged into the card issuer's online portal and found that it was something I care about, but simply forgot it was pending. Though if it was a fraudulent charge, I could've just gave them a ring. It certain can help in noticing fraudulent transactions in a much shorter time frame than simply waiting for a statement.


That hasn't been the case for me. I get ApplePay notifications for every POS charge for my Amex Platinum even if it's not via ApplePay. But I have cards from Chase, Citi, and Bank of America in ApplePay as well, and I only get notifications if it's an ApplePay transaction. I wish they all did it the way Amex does.

Edit: Actually, I mis-remembered. Internet charges on the Amex do cause a notification. But not for any of the other cards.


You need to enable this with credit card providers. I had to confirm a mobile number with Chase then set it up with >$0 auth.


I have cards from Chase, Citi and Barclay. Every charge yields a notification just like the AMEX.


Internet charges on my American Express shoot me a notification as well.


I found these alerts really useful. I spotted a random travel site charge and thought maybe my wife had reserved a hotel for an upcoming trip. The next day I saw two more alerts on my phone and called Amex. Yep, fraud, new card issued now. Amex thanked me for keeping a close eye on the charges. I guess they realize it helps them catch/prevent fraudsters too.


I just checked (and enabled) the texts for any amount over $0 on my Chase card.


Same, but I chose $1.


The first sign I got that my card was stolen was a 69 cent transaction at a Marriot in Vermont (I live in the Bay Area so this was weird).


Do you really get that many sub $1 purchases that you want to avoid getting text messages for?


I know both Simple and Capital One (their credit cards, at least) offer near-instant iOS and SMS notifications of all transaction.


Is this really necessary though? Personally, none of my cards will allow me to dispute a transaction until it posts as a charge not merely an authorization.

Seeing as you have 60 days after posting to dispute a charge, immediate notification seems like overkill.

I could see the usefulness for subscriptions or to shutdown a shopping spree before it gets out of hand I guess.


> Seeing as you have 60 days after posting to dispute a charge, immediate notification seems like overkill.

It's often much more than 60 days.

We had a chargeback at work that was a couple months over a year old. That surprised me...I had thought that a year was the limit.

That's not actually the most surprising thing I learned about credit cards last year, though. We got a notification from the payment processor near the end of the year that a charge from March had been reported as a success but actually failed. By "reported as a success" I do not just mean that the API had reported success on the charge. The payment processor had also reported later that it had successfully settled. They just never actually transferred any money to us.

While talking to them on the phone the payment processor rep then told me that the same thing had happened on the charges on this customer's monthly subscription for all subsequent months.

According to the payment processor rep, the customer had told his bank that he no longer wanted our service (but neglected to tell us...). The card was still good, and so the bank still said "approved" when we would try to charge it, then would apparently later notice that the customer did not want the charge and somehow arrange to block settlement, and the payment processor apparently has no way to report this.

Notice how messed up this is: you can put through a charge on a credit card, have the issuing bank and payment processor tell you it went through, have it settle according to the payment processor, have it show up as successfully settled in all reports from the payment processor...but the money just doesn't show up.

Unless the payment processor tells you about this, the only hint you'll have that something is wrong is that there will be a discrepancy between what is supposed to have shown up in your bank account and what actually showed up, and you won't have any way to tell which charge is the one that silently failed.


That's crazy! My business is heavily involved in CC processing and I've yet to encounter this.

Do you mind if I ask who the processor was?


I never heard of that happening before either. I suspect the problem is with the issuing bank, not the processor. (I don't recall offhand what bank was the issuing bank, other than it was small and obscure enough I've never heard of it).

I'd prefer not to name the processor since I suspect that the same problem could happen at any processor when dealing with cards from that issuing bank so I don't want to drag the processor's name through the mud.


It would be nice if you could have some kind of "leading edge" trigger on it, so if there's a transaction from a merchant that's unique in, say, the last two months, you get an SMS. If someone steals your credit card and goes on a shopping spree they're unlikely to do it at the same stores you go to.


It's a shame that chip and signature is used in the states though..


The problem with chip and pin is:

A) you want me to type my pin into a compromised device, the pinpad at the pump

B) you expect me to remember seven pins, I carry seven credit cards (yes that's excessive) and each should have a separate pin for security, right?


No, an actual chip should be secure enough to make skimmers pointless. However, we somehow desided to built and roll out a completely insecure chip system.

Ex of a simple and secure system. cc shows transaction cost, user clicks ok on the card. Card digitally signs a transaction with time stamp, vender ID, and amount.

Want safe online transactions, add a USB dongle or Bluetooth.


Do you have a reference for why it's "completely insecure"?


I think the idea is that it's reasonably-secure against skimmers taking your data and then re-using that data in another session or location when the card is absent.

But it won't save you from a compromised point-of-sale system that lies to you about how much you're paying or which commits fraudulent transactions while the card is still in the reader.


Which is why the amount should be displayed on a display embedded in the card itself. The control for authorizing the transaction should also be part of the card.

Now, if only we carried around a device that included a display and some sort of input mechanism, plus a near-distance communication chip...

(Ok, if the device is a general computing device, a special secure operation mode might be needed for this sort of use case, one which can't be subverted by normally installed software, but still...)


> special secure operation mode might be needed for this sort of use case, one which can't be subverted by normally installed software

Now people will complain that "the app doesn't run on their rooted, bootloader unlocked, jailbroken phones"


No reason why it shouldn't. This is not DRM, is your own credit, secured on your behalf. It should just be resistant to software based tampering by default. Specially, as I said, "normally installed software". If you can make sure that rooting your device requires a explicit knowledgeable user interaction (say: rebooting, erasing all data, then re-keying your device to your bank account somehow - in person visit?), then I see no reason why you should be prevented from changing the secure operation mode code itself or building your own compatible device.

I mean, you can mod the brakes on your car if you really want to, at your own risk. What is a bit strange is when your media player can affect your brakes without you even noticing. Same principle here, less lives on the line.


I believe he's referring to the current scan card + signature combo, which is very well known for being insecure because you t can be man in the middled, and the card is transmitting enough of it's information to duplicate the card if that data was captured by a skimmer.


the pin is useless without the chip. it's only one half of the something you have + something you know.


What is the point of the sigature? Mine never look even close to the same. Is this a serious security mechanism?

If you're not going to do chip and PIN (and you should), why not just chip and nothing?


When working a retail job I once (and only once) saw a credit card with a photo of the person it was issued to on the back. It was also about the only card I really bothered to check ownership on because signatures were useless.

Thankfully we've now got chip & pin, completely removing the need for minimum wage retail staff to verify ownership of credit cards.


Is this a serious security mechanism?

NPR's Planet Money recently did a story on the signature in CC payments. The answer seems to be "not really".


Here it is, Planet Money Ep. 564: The Signature (16:20)

"Today on the show: the signature. It's supposed to say, "This is me." But where did the idea come from? And why are we still using it? We consult a rabbi, a lawyer and a credit card executive."

http://www.npr.org/sections/money/2014/08/29/344034815/episo...


The signature is just a bit of evidence to check if you dispute a charge. It isn't a 99.99% key like in encryption.


I wonder if it would be secure enough/cheaper to retrofit these pumps with NFC readers.


When I lived in Canada almost 10 year ago, most pumps have contactless readers... so if Canada can do it then it's probably doable here.

(It wasn't NFC exactly, but similar technology)


Canada has an oligopoly of banks, so there are things Canada can do that seem to be difficult for the US, and vice versa.

In this case, when all five banks decided to go to pin-enabled credit cards, they just did it. Retailers were given a certain amount of time to switch over, “or else.” There are few alternatives, so the entire country moved forward.

Whereas, south of the 49th parallel, there is all kinds of competition for credit cards and for merchant services, so if a few banks don’t feel like sending out cards with chips an PINs, they don’t. And if a few retailers don’t want to go to the expense of upgrading their systems, they don’t have to.

On the flip side... There is nearly zero Apple Pay up here.


NFC is limited in the amount you can charge and what's to stop the bad guys fitting their own nfc and taking $5bucks.

Some one has demoed a proof of concept system that you could hide in a back pack and walk through a crowded train/tube station and harvest small sums from hundreds of people.


Almost all recent snack vending machines in the UK support contactless payment. if it's economical to do for £0.50 snacks, it'll work for fuel pumps.


Current contactless payments are limited to transactions of £30 or less. That rules it out for 99% of fuel transactions.


However the same technology would allow chip and pin transactions with the addition of a keypad, if only the US hadn't gone for the ridiculous chip and signature nonsense.


Hah, foiled by gas taxes!!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: