mountainX.com > Forum Home  >  Community  >  Internet & Technology  >  Thread
Forum Rules

 
Credit card security
 
Nov 05, 2009  11:04 AM
Avatar
Moderator
RankRankRankRankRank
Total Posts:  1158
Joined  09/2008

After eating lunch at Thai Basil yesterday, I noticed that when I was signing my receipt they had printed my whole credit card number on there. I hadn’t seen that happen in years, and I immediately scratched it out. I happened to be with a group of cyber security guys, and they were all in disbelief as well.

It would be very easy for a thief to pick up your receipt just after you leave, then go home and have an online shopping spree. The server or anyone else handling your receipt could do the same thing.

I looked up the laws on this, and it is in fact a federal offense to print out the full credit card number on the receipt:
http://www.ftc.gov/bcp/edu/pubs/business/alerts/alt007.shtm

So, be warned if you eat there, and always be vigilant about looking at your receipts anywhere you use a card.

The other annoying credit card related issue is when there are establishments that tack on a surcharge for using a credit/check/debit card. For example, if your purchase is not over $5, they tack on a $0.50 fee for using a card. This is in fact in violation of Visa and MasterCard terms of service:
http://fso.cpasitesolutions.com/premium/LE/06_le_ic/fg/fg-merchants.html#C

Additionally, they cannot require a minimum purchase amount to use a card. This is a very common thing to see, and I can think of 5 places in Asheville that do it off the top of my head:
http://fso.cpasitesolutions.com/premium/LE/06_le_ic/fg/fg-merchants.html#B

So, be vigilant when using your card, and ask to speak to a manager if they require a minimum purchase or try to tack on a fee. You can send complaints about a merchant here:
http://fso.cpasitesolutions.com/premium/LE/06_le_ic/fg/fg-merchants.html#F

Visa Terms of Service (PDF):
http://usa.visa.com/download/merchants/card_acceptance_guide.pdf

 
Reply #1 • Nov 05, 2009  12:56 PM
Avatar
MX Boarder
RankRankRankRankRank
Total Posts:  1455
Joined  04/2008
The Imposter - 05 November 2009 11:04 AM

After eating lunch at Thai Basil yesterday, I noticed that when I was signing my receipt they had printed my whole credit card number on there. I hadn’t seen that happen in years, and I immediately scratched it out. I happened to be with a group of cyber security guys, and they were all in disbelief as well.

It would be very easy for a thief to pick up your receipt just after you leave, then go home and have an online shopping spree. The server or anyone else handling your receipt could do the same thing.

I looked up the laws on this, and it is in fact a federal offense to print out the full credit card number on the receipt:
http://www.ftc.gov/bcp/edu/pubs/business/alerts/alt007.shtm

So, be warned if you eat there, and always be vigilant about looking at your receipts anywhere you use a card.

That is very odd, but Thai Basil has no control over what prints on their receipts. When the laws changed, the credit card processors changed the way they transmit the data back to the terminal. It is not a setting that is switched on and off at the retail end. They need to call their processor.

Signature 

It’s not like there is a local Sunday paper handing out free zeitgeist anymore.

 
Reply #2 • Nov 05, 2009  01:27 PM
Championship MX Boarder
RankRankRankRankRankRank
Total Posts:  2813
Joined  04/2007

Luckily, most merchants online now ask for the Card Verification Value (CVV) code of the credit card being used for them to secure “card not present” transactions occurring over the Internet, by mail, fax or over the phone for just such reasons. That code is usually only on the card itself and not printed on any receipts. I understand it is mandatory in many western Europe countries due to fraud.

 
Reply #3 • Nov 05, 2009  01:47 PM
Avatar
Moderator
RankRankRankRankRank
Total Posts:  1158
Joined  09/2008
brebro - 05 November 2009 01:27 PM

Luckily, most merchants online now ask for the Card Verification Value (CVV) code of the credit card being used for them to secure “card not present” transactions occurring over the Internet, by mail, fax or over the phone for just such reasons. That code is usually only on the card itself and not printed on any receipts. I understand it is mandatory in many western Europe countries due to fraud.

True, but with Visa and MC, there are only 999 possible combinations because the CVV codes are only 3 digits long, which really isn’t that many to roll through if you script it. Could be discovered in milliseconds. All you have to do is find a mom & pop web shop (there are millions) with minimal protections their shopping cart application from the server side, and auto-submit the form over and over until it works. This would be child’s play for a hacker.

The same goes for the expiration date.

 
Reply #4 • Nov 05, 2009  02:43 PM
Championship MX Boarder
RankRankRankRankRankRank
Total Posts:  2813
Joined  04/2007

Maybe, but at least they can’t use the receipt to jimmy their way though a locked door.

 
Reply #5 • Nov 05, 2009  06:03 PM
Avatar
MX Boarder
RankRankRankRankRank
Total Posts:  1879
Joined  10/2007
The Imposter - 05 November 2009 01:47 PM

True, but with Visa and MC, there are only 999 possible combinations because the CVV codes are only 3 digits long, which really isn’t that many to roll through if you script it. Could be discovered in milliseconds. All you have to do is find a mom & pop web shop (there are millions) with minimal protections their shopping cart application from the server side, and auto-submit the form over and over until it works. This would be child’s play for a hacker.

The same goes for the expiration date.

Thanks for the tip, willc!

Time to get a job at Thai Basil!

Signature 

All of us failed to match our dreams of perfection. So I rate us on the basis of our splendid failure to do the impossible.

 
Reply #6 • Nov 05, 2009  09:59 PM
Avatar
Ultimate Boarding Master
RankRankRankRankRankRankRankRankRankRankRankRankRank
Total Posts:  10040
Joined  12/2008

you and i think alike tat.

Signature 

I’m just holding space until the serious business starts.

 
Reply #7 • Nov 05, 2009  10:05 PM
Avatar
MX Boarder
RankRankRankRankRank
Total Posts:  1455
Joined  04/2008

Just hit the dumpster-no need to work.

Signature 

It’s not like there is a local Sunday paper handing out free zeitgeist anymore.

 
Reply #8 • Nov 05, 2009  10:17 PM
Avatar
Ultimate Boarding Master
RankRankRankRankRankRankRankRankRankRankRankRankRank
Total Posts:  10040
Joined  12/2008

i think you’re in the wrong thread.

Signature 

I’m just holding space until the serious business starts.

 
Reply #9 • Nov 05, 2009  10:28 PM
Avatar
MX Boarder
RankRankRankRankRank
Total Posts:  1455
Joined  04/2008
˙˚∆˚ - 05 November 2009 10:17 PM

i think you’re in the wrong thread.

Sorry I’m messing up your sweep.

The receipts are in the dumpster behind the Thai place.

Signature 

It’s not like there is a local Sunday paper handing out free zeitgeist anymore.

 
Reply #10 • Nov 05, 2009  10:36 PM
Avatar
Ultimate Boarding Master
RankRankRankRankRankRankRankRankRankRankRankRankRank
Total Posts:  10040
Joined  12/2008

oh. yeah, i’m kinda slow. i see now.

and i wudn’t sweepin. that’s almost all leftovers from the sweep i did over a week ago.

sweeping is played out.

Signature 

I’m just holding space until the serious business starts.

 
Reply #11 • Nov 05, 2009  11:12 PM
Avatar
Administrator
RankRankRankRankRankRankRankRankRankRank
Total Posts:  6953
Joined  01/2007
Mr. Yuck - 05 November 2009 10:28 PM
˙˚∆˚ - 05 November 2009 10:17 PM

i think you’re in the wrong thread.

Sorry I’m messing up your sweep.

The receipts are in the dumpster behind the Thai place.

Hot Spot dumpsters are very secure.

Signature 

Magneto was right

 
Reply #12 • Nov 06, 2009  10:09 AM
Avatar
MX Boarding Legend
RankRankRankRankRankRankRank
Total Posts:  3131
Joined  05/2009

The Imposter - 05 November 2009 02:47 PM

  True, but with Visa and MC, there are only 999 possible combinations because the CVV codes are only 3 digits long, which really isn’t that many to roll through if you script it. Could be discovered in milliseconds. All you have to do is find a mom & pop web shop (there are millions) with minimal protections their shopping cart application from the server side, and auto-submit the form over and over until it works. This would be child’s play for a hacker.

  The same goes for the expiration date.

You realize some 18 year old is down loading a CVV code generator and in 6 months will be doing 5 to 10 for credit card fraud ...

The FBI is surrounding Piffy’s compound as we speak..

This is the beginning of the end of the MX forum.. see you guys in the slammer…

Signature 

The more you can increase fear of drugs and crime, welfare mothers, immigrants and aliens, the more you control all the people.
Noam Chomsky

 
Reply #13 • Nov 20, 2009  07:55 AM
Avatar
Moderator
RankRankRankRankRank
Total Posts:  1158
Joined  09/2008

Another local restaurant discovered doing the same thing. My full CC # was on the Merchant copy of the receipt (the one I signed).  This time it was at China Wok on Merrimon Ave.

 
Reply #14 • Nov 20, 2009  09:20 AM
Avatar
Ultimate Boarding Master
RankRankRankRankRankRankRankRankRankRankRankRankRank
Total Posts:  10040
Joined  12/2008

the lesson is not only is eating out bad for you and the planet, its also bad for your credit.

Signature 

I’m just holding space until the serious business starts.

 
Reply #15 • Nov 20, 2009  10:07 AM
Avatar
Championship MX Boarder
RankRankRankRankRankRank
Total Posts:  2660
Joined  02/2008

And Asians aren’t trustworthy, apparently.

Signature 

Whiskey washy obvious racist.