On the Day of Victory!!!
Ccardzone - Credit Card blog

Security flaw could expose credit card data

1 Star2 Stars3 Stars4 Stars5 Stars (1 votes, average: 5.00 out of 5)
Loading ... Loading ...
Debit Card

If you have a credit card account with Bank of America or Chase, two of the nation’s largest banks, a major security flaw has been exposed that could make your information vulnerable to an Internet crook – or even a nosy neighbor.

Consumer advocate Edgar Dworsky of ConsumerWorld.org, who discovered the flaw, says anyone who knows your phone number and has the last four digits of your Chase or BofA credit card number might be able access your account.

Here’s the flaw Dworsky uncovered: When you call a bank’s automated credit card account information system, the computer uses caller ID to compare the number you’re calling from with the one on the account (usually your home phone).

At BofA and Chase, if the phone number is a match, the verification process is streamlined. Rather than requiring the entire credit card number to be entered, the caller can usually access the account with only the last four digits. In some cases, a zip code is also required.

“The last four digits of your credit card number are just out there so predominantly,” Dworsky says. “If you look at any sales receipt, it always has those last four digits.”

In order for someone to take advantage of this security loophole, they’d have to trick the bank’s computer to make it appear the call is coming from your home phone. Internet “spoofing” sites make this incredibly easy to do. Con artists have been using this technology for years, and it is how those British tabloid reporters were able to hack into so many voicemail systems.

The banks respond
I contacted Chase and Bank of America and asked them to respond to all of this. Both banks e-mailed me statements that said they take customer security very seriously, but they do not think the scenario Dworsky outlines is a significant security threat to their customers.

“Our objective is to balance customers’ need for convenience and quick access to general information with industry best protection of their accounts,” wrote Betty Reiss at Bank of America. “In addition to at least two levels of authentication required to access very limited information over our automated system, we have additional security controls in place to detect potential abuse of our automated systems. We understand that there will always be individuals who are trying to beat the system, and we’re constantly looking at measures to better protect and service our customers.”

I got this response from spokesperson Eileen Leveckis at Chase: “Chase takes data protection extremely seriously and we have numerous fraud-detection tools in place to best protect our customers. We are always engaged in research and development for new anti-fraud and data-protection technologies and we are an established leader in data security.”

Adam Levin, co-founder and chairman of Identity Theft 911, was disappointed to hear how the banks responded.

“The fact that people can spoof phone numbers and then use just four digits and then come back with account information is a woefully insecure security system,” he says. “These banks really have to rethink their strategy and develop a much more serious security protocol when it comes to credit cards.”

Pam Dixon, executive director of the nonprofit World Privacy Forum, agrees. “Convenience is the greatest enemy of privacy, and this is a perfect example of that,” Dixon says. “The banks have made it too easy to access this sensitive information. There needs to be increased security procedures.”

Testing the flaw
In running various vulnerability tests with his own cards and those of several volunteers, Dworsky found it was simple to gain access to the targeted account in almost every case.

“I was shocked. I was absolutely shocked that using a relatively simple technique, someone could find out about someone else’s credit card history.”

Using the same technique and with his permission, I was able to get into the database for Dworsky’s Chase and Bank of America credit card accounts. The automated system gave me his credit lines and how much credit was still available on the card, the amount of the last bill and when it was paid, plus information about dozens of recent transactions: the date, the amount and what was purchased.

The security protocol is stricter at Capital One, Citi and American Express. They all require the entire card number to be entered every time, no matter where the call is placed from.

Dworsky would like to see Chase and BofA do the same thing. “It’s so easy to close this loophole,” he says. “They just need to require anyone who calls their information line to put in the full 16-digit credit card number.”

So, am I safe?
OK, so I hack into the bank’s automated system and find out that your last payment was $500 on Aug. 12 and that you have available credit of $21,500. Maybe I learn that you made a $65 purchase at Home Depot on Aug. 3, and a $75 purchase at Target the next day.

This isn’t enough information to allow a crook to order a new credit card or get a cash advance. But an identity thief can use the information to build credibility with potential victims.

Here’s how it works: Armed with the details from your account, the thief phones you, this time using caller ID spoofing to make it look like he’s calling from your bank.

He tells you he’s from the bank’s security department, and says they’ve noticed some suspicious activity on your account. To prove he’s with the bank, the crook recites the information gleaned from the phone system about your credit card account. That could cause you to drop your guard, and give him enough additional account information to rip you off.

Other dangers
Identity theft isn’t the only threat here. This same technique could also allow unauthorized people to collect information about your charitable or political donations, religious or other organizations you belong to, even charges you’ve made for medical problems.

My two cents
ID spoofing has changed the security landscape. A phone number is no longer a reliable means of authentication. If you have a credit card with either of these two banks and you believe security trumps convenience, as I do, I encourage you to contact them and let them know how you feel. Tell them you want this loophole closed.

News source

More Posts

  • Getting out of debt – Can credit card consolidation be of any help?

    Getting out of debt – Can credit card consolidation be of any help?


    If you are too deep into debt, can credit card consolidation help you to get out of it? The answer to this is yes, but, you will also be required to make sure that you are going to change you have been spending money, and using your credit cards. Credit cards make shopping easy, as you need not carr...
  • Get 2 Free Nights At Any Fairmont Hotel and Earn Status Faster

    Get 2 Free Nights At Any Fairmont Hotel and Earn Status Faster


    Chase and Fairmont Hotels & Resorts just announced the first ever Fairmont credit card, the Fairmont Visa Signature Card. Not only does the brand new card help cardmembers earn status faster, but it also comes with a nice sign up bonus: you’ll receive two complimentary night stays complete with ...
  • The Chase Ink Bold Business Credit Card – earn up to 50k bonus points

    The Chase Ink Bold Business Credit Card – earn up to 50k bonus points


    Earn up to 50,000 bonus points with The Chase Ink Bold Business Credit Card. After you make your first purchase, you will qualify for 25,000 bonus points. If you make purchases totaling $10,000 or more within 3 months of account opening, you will receive an additional 25,000 bonus points for a total...
  • Marriott Rewards Credit Card

    Marriott Rewards Credit Card


    If you prefer to stay at Marriott hotels when you’re on the road, you should check out the  Credit Card. You need excellent credit to qualify for this card. As soon as you get approved, you get two free night e-certificates. You know what else I really like about this card? After your first use, you...
  • 2 FREE Roundtrip Flights from Southwest Airlines Rapid Rewards Plus Card

    2 FREE Roundtrip Flights from Southwest Airlines Rapid Rewards Plus Card


    Chase and Southwest have once again brought back this popular offer – when you apply for a new Southwest Airlines Rapid Rewards Plus Card, you’ll earn 50,000 bonus points after just your first purchase. Those points are worth $833 towards Wanna Get Away fares, meaning you should be able to redeem th...
  • Lenders making the more attractive credit card offers

    Lenders making the more attractive credit card offers


    In recent months, many consumers have probably found their mailbox full of credit card offers regardless of their previous borrowing history, and the value of those offers has likely been on the rise again, particularly if they have a strong credit score. Lenders have been casting a wider net in ...
  • The CFPB Changed Course on Lowering Fees

    The CFPB Changed Course on Lowering Fees


    Last week, the Consumer Financial Protection Bureau (CFPB) backed off a plan to reduce costly up-front fees on credit cards. It’s amazing how the early headlines last week gave the impression that the CFPB was weak for changing course. The CFPB was, in fact, left with little wiggle room due to a fed...
  • Credit card convenience fees

    Credit card convenience fees


    Paying with a credit card often yields rewards. But in certain situations those benefits come at a cost, not just through interest, but in the form of convenience fees. Convenience fees it`s credit card processing companies ordinarily forbid charging a surcharge for accepting cards, but, under li...
  • 100,000 Avios points Bonus is Back from Chase British Airways Visa Signature Card

    100,000 Avios points Bonus is Back from Chase British Airways Visa Signature Card


    The first travel card to introduce the 100,000 Avios point bonus has brought it back. The Chase British Airways Visa Signature card you will get 50,000 bonus Avios after your first use of the card. And 25,000 bonus Avios after you make $10,000 in purchases within the first year of account opening. P...
  • Barclaycard Ring MasterCard: The First Social Credit Card

    Barclaycard Ring MasterCard: The First Social Credit Card


    Barclaycard recently announced the introduction of the Barclaycard Ring MasterCard, what it calls "the first social credit card to be designed and built through the power of community crowdsourcing." The new card will offer a low 8% interest rate, low fees, simple terms and the opportunity for cardh...