Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Many banks don’t properly validate the CVV and expiry date, or only apply fuzzy matching to “improve the customer experience”.

Classic example of this is Tesco bank where they only checked that the expiry date was in the future, not if it actually matched the card.

They also made a number of other insane mistakes, and FCA report does a good job of explaining them [1]

[1] https://www.fca.org.uk/publication/final-notices/tesco-perso...



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: