20150824 I Have Spoken To A Lot Of People About

Keith I MyersKeith I Myers2015-08-24 23:14:29-0400 – Updated: 2015-08-24 23:14:29-0400I have spoken to a lot of people about the #AshleyMadiso Database Dump and was shocked to see how many people downplay it as the dump does not contain Full Credit Card Numbers. What many fail to realize is that it is fairly easy to convert the last 4 digits into the entire credit card number by simply asking nicely. Here is how it is done and how to protect yourself from falling victim.

Ashley Madison : The Danger of The Last 4 Numbers | Keith I Myers

Shared with: Public, Keith I Myers, Nikhil M+1’d by: Eddie Daniels, Josh Beach, Aaron HoneycuttNikhil M – 2015-08-24 23:23:40-0400 – Updated: 2015-08-24 23:25:34-0400Don’t you still need the transaction password for buying stuff online? My card has something called Verified by Visa. It is another password that I need before my transaction can go throughKeith I Myers – 2015-08-24 23:30:39-0400+Nikhil M – The Verified By Visa system is an extra step that has not caught on like it should. They system is not “mobile friendly” so it is rarely setup on mobile sites as well. I have used my Visa card hundreds of times over the past few years and can only recall seeing the Verified By Visa page 3-4 times.Nikhil M – 2015-08-24 23:31:53-0400 – Updated: 2015-08-24 23:32:37-0400+Keith I Myers​ I think that is a US thing. I can’t use my card anywhere without the verified by Visa. Keith I Myers – 2015-08-24 23:33:58-0400+Nikhil M – One other thing to keep in mind is that the Mastercard and Discover Card versions of the verify system are nowhere as mature as the Visa. An attacker could also create a physical card with all of the details and attempt to use it.Nikhil M – 2015-08-24 23:51:49-0400No one I know has a MasterCard. To create and use a physical card, won’t it ask for the pin to be typed in the machine? Keith I Myers – 2015-08-24 23:53:48-0400+Nikhil M – If the transaction is ran through as “Credit”, the PIN will be bypassed so it is only a factor for “debit” transactions. The US has not adopted “PIN+CHIP” for anything. Nikhil M – 2015-08-24 23:57:27-0400So there is no security for a credit card? Keith I Myers – 2015-08-25 00:02:58-0400+Nikhil M – There is the CVV2 number, as it is printed on the back rather then embossed, it is a (minimal) security measure. Of course in the scenario posted on my website, I demonstrated how this can be defeated with little effort. 

Fraud is a multi-million dollar a year business for a reason. 

Leave a Comment

Join the New Chromebook Community at Chromebook.Community
Join the new Technical Chat Community at Technical.Chat