Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 

xpd

xpd
Geek @ Coastguard NZ
13767 posts

Uber Geek

Retired Mod
ID Verified
Trusted
Lifetime subscriber

  #2909761 3-May-2022 17:19
Send private message

I checked all my emails with them over past year, and NONE have shown CVV or anything else I'm concerned over.

 

 





       Gavin / xpd / FastRaccoon / Geek of Coastguard New Zealand

 

                      LinkTree

 

 

 




richms
28187 posts

Uber Geek

Trusted
Lifetime subscriber

  #2909764 3-May-2022 17:29
Send private message

xpd:

 

I checked all my emails with them over past year, and NONE have shown CVV or anything else I'm concerned over.

 

 

 

 

Likewise, the one time I used a card because it was too much for zip, it just had first 6 and last 2 and expiry. If they have CVV on their system tho they need the book thrown at them.





Richard rich.ms

freitasm
BDFL - Memuneh
79290 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2909767 3-May-2022 17:38
Send private message

xpd:

 

I checked all my emails with them over past year, and NONE have shown CVV or anything else I'm concerned over.

 

 

 

 

I thought this was explained already - perahps someone entered the number in the name field?





Please support Geekzone by subscribing, or using one of our referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSync 




  #2909833 3-May-2022 19:48
Send private message

I'm amazed that they even retain any credit card information at all - they don't need it. I mean, now that you've taken all this information & stored it in your state of the art plain-text database, what do you plan on doing with it? Are you going to use it for more purchases somewhere else? Or?

I've been the vendor in hundreds of commercial online transactions, selling digital products worldwide. My database does not even have a field for CC entry, I have not captured CC details of any customer ever. I wouldn't have a clue whether or not a returning customer used the same card as last time - because I don't care, it's none of my business.

All the vendor needs to record is that they got paid - & it's the bank that tells them that. Which card paid them is irrelevant, if the bank accepts the transaction then the vendor gets paid - end of story.

The vendor's website hosts a secure gateway that enables the client to talk direct to their bank (in private!) so that they can authorize a payment from that bank to the vendor. Bank checks that the customer is legit & funds are available then fires off a confirmation to the vendor that payment is approved & has been made.

Where does credit card detail capture / retention fit into that procedure? It doesn't.

What could possibly go wrong?

It's databases like these that provide outlaw employees or hackers with a steady income stream as they feed those high-quality details to resellers on carding sites.





Megabyte - so geek it megahertz

richms
28187 posts

Uber Geek

Trusted
Lifetime subscriber

  #2910017 4-May-2022 11:22
Send private message

1024kb: I'm amazed that they even retain any credit card information at all - they don't need it. I mean, now that you've taken all this information & stored it in your state of the art plain-text database, what do you plan on doing with it? Are you going to use it for more purchases somewhere else? Or?

I've been the vendor in hundreds of commercial online transactions, selling digital products worldwide. My database does not even have a field for CC entry, I have not captured CC details of any customer ever. I wouldn't have a clue whether or not a returning customer used the same card as last time - because I don't care, it's none of my business.

All the vendor needs to record is that they got paid - & it's the bank that tells them that. Which card paid them is irrelevant, if the bank accepts the transaction then the vendor gets paid - end of story.

The vendor's website hosts a secure gateway that enables the client to talk direct to their bank (in private!) so that they can authorize a payment from that bank to the vendor. Bank checks that the customer is legit & funds are available then fires off a confirmation to the vendor that payment is approved & has been made.

Where does credit card detail capture / retention fit into that procedure? It doesn't.

What could possibly go wrong?

It's databases like these that provide outlaw employees or hackers with a steady income stream as they feed those high-quality details to resellers on carding sites.

 

Even if its not intentionally put in a database there is a good chance that one of the advertising or tracking scripts on their own payment page has done something with it, or else they have misconfigured logging and its been put in a plain text log somewhere that was turned on for debugging by someone once and forgotten about.

 

I really don't trust sites that host the payment form on their own site, or put an iframe from a payment provider onto their site.

 

Why iframes ever became acceptable for that sort of thing escapes me since it would be trivial for a compromised crap ecommerce website to just replace the iframe with a look alike and there is no signs of that as any source information for the user as to where the page came from or where it submits to. All the iframe protection crap in the browser means nothing if someone just changes the real gateway to a fake lookalike.

 

 





Richard rich.ms

isaacmercer

6 posts

Wannabe Geek


  #2910025 4-May-2022 11:40
Send private message

freitasm:

I thought this was explained already - perahps someone entered the number in the name field?



Although the name is not always required to authorise the payment, if the number and name were swapped the payment wouldn't work - so this can't have been the issue. It was a new card, hence with a new CVV, expiry, etc and it was the first time I'd used that new issue card online, so I was vigilant with the details.

richms
28187 posts

Uber Geek

Trusted
Lifetime subscriber

  #2910074 4-May-2022 12:10
Send private message

Name never seems to matter. I put all sorts of crap in the name field and payments happen.





Richard rich.ms

 
 
 

Trade NZ and US shares and funds with Sharesies (affiliate link).
0x994c1d
5 posts

Wannabe Geek


  #2910092 4-May-2022 12:36
Send private message

Yea, been through all my warehouse emails and no addition of a CVV 

 

 

 

are you able to share a screenshot?


Kyanar
4089 posts

Uber Geek

ID Verified
Trusted

  #2910194 4-May-2022 17:08
Send private message

Detruire:

 

My TW confirmation emails show (partial) number/name/expiry, so I think it's more likely that the CVV was in both fields. While an incorrect CVV leads to a failed payment, an incorrect name doesn't seem to matter (in most cases) IME: I usually put my initials in the name field, and I've only had a few payments denied (seemingly) because of this.

 

 

It's worth noting that the CVV is not actually required to process a card (ever noticed that when you give your card over the phone, merchants don't always ask for the CVV?). The way it works is that the CVV is not required to be provided, but if it is provided it must be correct. It is not entirely impossible that the two fields were in fact flipped in the data entry process somehow, and the alpha characters failed to save into the CVV field - meaning that the charge would have been submitted without a CVV, something which TWL is likely to be permitted to do due to their size.


ANglEAUT
2325 posts

Uber Geek

Trusted
Lifetime subscriber

  #2910236 4-May-2022 19:43
Send private message

Can you make some sort of FOIA / credit report request with TWL asking them to provide you with all the details they have on record linked to your person? If they provide you with that data, search for your CC details?

 

 





Please keep this GZ community vibrant by contributing in a constructive & respectful manner.


freitasm
BDFL - Memuneh
79290 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2910385 5-May-2022 07:54
Send private message

ANglEAUT:

 

Can you make some sort of FOIA / credit report request with TWL asking them to provide you with all the details they have on record linked to your person? If they provide you with that data, search for your CC details?

 

 

Yes. Office of the Privacy Commissioner | Your privacy rights

 

Also Office of the Privacy Commissioner | AboutMe (Request My Info Tool)

 

 





Please support Geekzone by subscribing, or using one of our referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSync 


1 | 2 
View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.