mountainX.com > Forum Home  >  Community  >  Internet & Technology  >  Thread
Forum Rules

 
Credit card security
 
Nov 05, 2009  12:04 PM
Avatar
Moderator
RankRankRankRank
Total Posts:  900
Joined  09/2008

After eating lunch at Thai Basil yesterday, I noticed that when I was signing my receipt they had printed my whole credit card number on there. I hadn’t seen that happen in years, and I immediately scratched it out. I happened to be with a group of cyber security guys, and they were all in disbelief as well.

It would be very easy for a thief to pick up your receipt just after you leave, then go home and have an online shopping spree. The server or anyone else handling your receipt could do the same thing.

I looked up the laws on this, and it is in fact a federal offense to print out the full credit card number on the receipt:
http://www.ftc.gov/bcp/edu/pubs/business/alerts/alt007.shtm

So, be warned if you eat there, and always be vigilant about looking at your receipts anywhere you use a card.

The other annoying credit card related issue is when there are establishments that tack on a surcharge for using a credit/check/debit card. For example, if your purchase is not over $5, they tack on a $0.50 fee for using a card. This is in fact in violation of Visa and MasterCard terms of service:
http://fso.cpasitesolutions.com/premium/LE/06_le_ic/fg/fg-merchants.html#C

Additionally, they cannot require a minimum purchase amount to use a card. This is a very common thing to see, and I can think of 5 places in Asheville that do it off the top of my head:
http://fso.cpasitesolutions.com/premium/LE/06_le_ic/fg/fg-merchants.html#B

So, be vigilant when using your card, and ask to speak to a manager if they require a minimum purchase or try to tack on a fee. You can send complaints about a merchant here:
http://fso.cpasitesolutions.com/premium/LE/06_le_ic/fg/fg-merchants.html#F

Visa Terms of Service (PDF):
http://usa.visa.com/download/merchants/card_acceptance_guide.pdf

Signature 

O o .

 
Reply #1 • Nov 05, 2009  01:56 PM
Avatar
MX Boarder
RankRankRankRankRank
Total Posts:  1137
Joined  04/2008
The Imposter - 05 November 2009 12:04 PM

After eating lunch at Thai Basil yesterday, I noticed that when I was signing my receipt they had printed my whole credit card number on there. I hadn’t seen that happen in years, and I immediately scratched it out. I happened to be with a group of cyber security guys, and they were all in disbelief as well.

It would be very easy for a thief to pick up your receipt just after you leave, then go home and have an online shopping spree. The server or anyone else handling your receipt could do the same thing.

I looked up the laws on this, and it is in fact a federal offense to print out the full credit card number on the receipt:
http://www.ftc.gov/bcp/edu/pubs/business/alerts/alt007.shtm

So, be warned if you eat there, and always be vigilant about looking at your receipts anywhere you use a card.

That is very odd, but Thai Basil has no control over what prints on their receipts. When the laws changed, the credit card processors changed the way they transmit the data back to the terminal. It is not a setting that is switched on and off at the retail end. They need to call their processor.

Signature 

“because I am having a clash with a headless dog, seize him when he comes and release me”

 
Reply #2 • Nov 05, 2009  02:27 PM
Avatar
Championship MX Boarder
RankRankRankRankRankRank
Total Posts:  2294
Joined  04/2007

Luckily, most merchants online now ask for the Card Verification Value (CVV) code of the credit card being used for them to secure “card not present” transactions occurring over the Internet, by mail, fax or over the phone for just such reasons. That code is usually only on the card itself and not printed on any receipts. I understand it is mandatory in many western Europe countries due to fraud.

 
Reply #3 • Nov 05, 2009  02:47 PM
Avatar
Moderator
RankRankRankRank
Total Posts:  900
Joined  09/2008
brebro - 05 November 2009 02:27 PM

Luckily, most merchants online now ask for the Card Verification Value (CVV) code of the credit card being used for them to secure “card not present” transactions occurring over the Internet, by mail, fax or over the phone for just such reasons. That code is usually only on the card itself and not printed on any receipts. I understand it is mandatory in many western Europe countries due to fraud.

True, but with Visa and MC, there are only 999 possible combinations because the CVV codes are only 3 digits long, which really isn’t that many to roll through if you script it. Could be discovered in milliseconds. All you have to do is find a mom & pop web shop (there are millions) with minimal protections their shopping cart application from the server side, and auto-submit the form over and over until it works. This would be child’s play for a hacker.

The same goes for the expiration date.

Signature 

O o .

 
Reply #4 • Nov 05, 2009  03:43 PM
Avatar
Championship MX Boarder
RankRankRankRankRankRank
Total Posts:  2294
Joined  04/2007

Maybe, but at least they can’t use the receipt to jimmy their way though a locked door.

 
Reply #5 • Nov 05, 2009  07:03 PM
MX Boarder
RankRankRankRankRank
Total Posts:  1571
Joined  10/2007
The Imposter - 05 November 2009 02:47 PM

True, but with Visa and MC, there are only 999 possible combinations because the CVV codes are only 3 digits long, which really isn’t that many to roll through if you script it. Could be discovered in milliseconds. All you have to do is find a mom & pop web shop (there are millions) with minimal protections their shopping cart application from the server side, and auto-submit the form over and over until it works. This would be child’s play for a hacker.

The same goes for the expiration date.

Thanks for the tip, willc!

Time to get a job at Thai Basil!

Signature 

I normally don’t pile on the richey is an idiot bandwagon, but you are exhaustingly stupid - my tat in arms

 
Reply #6 • Nov 05, 2009  10:59 PM
Forum Xtremist
RankRankRankRankRankRankRankRankRankRankRank
Total Posts:  8345
Joined  12/2008

you and i think alike tat.

 
Reply #7 • Nov 05, 2009  11:05 PM
Avatar
MX Boarder
RankRankRankRankRank
Total Posts:  1137
Joined  04/2008

Just hit the dumpster-no need to work.

Signature 

“because I am having a clash with a headless dog, seize him when he comes and release me”

 
Reply #8 • Nov 05, 2009  11:17 PM
Forum Xtremist
RankRankRankRankRankRankRankRankRankRankRank
Total Posts:  8345
Joined  12/2008

i think you’re in the wrong thread.

 
Reply #9 • Nov 05, 2009  11:28 PM
Avatar
MX Boarder
RankRankRankRankRank
Total Posts:  1137
Joined  04/2008
˙˚∆˚ - 05 November 2009 11:17 PM

i think you’re in the wrong thread.

Sorry I’m messing up your sweep.

The receipts are in the dumpster behind the Thai place.

Signature 

“because I am having a clash with a headless dog, seize him when he comes and release me”

 
Reply #10 • Nov 05, 2009  11:36 PM
Forum Xtremist
RankRankRankRankRankRankRankRankRankRankRank
Total Posts:  8345
Joined  12/2008

oh. yeah, i’m kinda slow. i see now.

and i wudn’t sweepin. that’s almost all leftovers from the sweep i did over a week ago.

sweeping is played out.

 
Reply #11 • Nov 06, 2009  12:12 AM
Avatar
Administrator
RankRankRankRankRankRankRankRankRank
Total Posts:  5592
Joined  01/2007
Mr. Yuck - 05 November 2009 11:28 PM
˙˚∆˚ - 05 November 2009 11:17 PM

i think you’re in the wrong thread.

Sorry I’m messing up your sweep.

The receipts are in the dumpster behind the Thai place.

Hot Spot dumpsters are very secure.

Signature 

“What will you do with free will?”—Uatu the Watcher

 
Reply #12 • Nov 06, 2009  11:09 AM
Avatar
Championship MX Boarder
RankRankRankRankRankRank
Total Posts:  2627
Joined  05/2009

The Imposter - 05 November 2009 02:47 PM

  True, but with Visa and MC, there are only 999 possible combinations because the CVV codes are only 3 digits long, which really isn’t that many to roll through if you script it. Could be discovered in milliseconds. All you have to do is find a mom & pop web shop (there are millions) with minimal protections their shopping cart application from the server side, and auto-submit the form over and over until it works. This would be child’s play for a hacker.

  The same goes for the expiration date.

You realize some 18 year old is down loading a CVV code generator and in 6 months will be doing 5 to 10 for credit card fraud ...

The FBI is surrounding Piffy’s compound as we speak..

This is the beginning of the end of the MX forum.. see you guys in the slammer…

Signature 

Have we not come to such an impasse in the modern world that we must love our enemies - or else? The chain reaction of evil - hate begetting hate, wars producing more wars - must be broken, or else we shall be plunged into the dark abyss of annihilation.
Martin Luther King, Jr.

check out ..All About Richey, All the Time.. http://www.mountainx.com/forums/viewthread/2237/

 
Reply #13 • Nov 20, 2009  08:55 AM
Avatar
Moderator
RankRankRankRank
Total Posts:  900
Joined  09/2008

Another local restaurant discovered doing the same thing. My full CC # was on the Merchant copy of the receipt (the one I signed).  This time it was at China Wok on Merrimon Ave.

Signature 

O o .

 
Reply #14 • Nov 20, 2009  10:20 AM
Forum Xtremist
RankRankRankRankRankRankRankRankRankRankRank
Total Posts:  8345
Joined  12/2008

the lesson is not only is eating out bad for you and the planet, its also bad for your credit.

 
Reply #15 • Nov 20, 2009  11:07 AM
Avatar
Championship MX Boarder
RankRankRankRankRankRank
Total Posts:  2473
Joined  02/2008

And Asians aren’t trustworthy, apparently.

Signature 

Get richey or Die Tryin’

More like the whiskey washiest.

Also an Obvious Racist.