Slashdot Mirror


Gift Card Hacking

TheSauce writes "MSNBC has this discussion of how easy it is to hack and jack the contents of those lovely Plastic Gift Cards one sees at most Mass Merchants and Consumer Electronics stores. One retailer notes that the odds of this occuring are about at the level of being pickpocketed."

2 of 264 comments (clear)

  1. Re:Barnes and Noble. by Grimmtooth · · Score: 5, Informative
    The account number was on the magstrip of the card, was printed on the card, but was _also_ printed on the gift receipt that came with the card.


    Which is EXACTLY why several states, California foremost among them, have begun to implement consumer protection laws that require that the receipt NOT display the account number and/or the expiry date (depending on the state). I believe in the case of California, it goes into effect on Jan 1 2002.

    My company's ready. I wonder how many other POS vendors aren't? :-)

    At any rate, it is the store's responsibility to comply, by using compliant POS software. Since it is easier to implement across the board than on a state by state basis, I presume that if a vendor has fixed it for CA, they will be prepared for the other states, too.

    Outside the US is not something I'm familiar with.
    --
    /* .sigs are irrelevant */
  2. I hate nationally syndicated stupidity by Grimmtooth · · Score: 4, Informative
    By way of boda fides, I work for a POS (point of sale) vendor that just happens to support the processing of said gift / stored value cards. As a result I have had to become very familiar with the mechanics of the whole thing.

    So, a few comments:

    • Despite what MSNBC would tell you, Debit cards are not protected from theft by a lack of visible account number. Rather they are protected by encrypted PIN.
    • Despite what MSNBC would tell you, you can buy card writing equipment without going to the black market. They are perfectly legal. They just cost BIG bucks, and that's why most people don't have one :-)
    • The theft method described to lift account numbers is no different than what is done with credit cards, except in the case of the latter you have to work harder to get a valid account number. Anyone with a card writer WOULD know how to do that, trust me.
    • Credit cards are a far greater risk because they are unrestricted in where they may be used, unlike gift cards.
    • Be aware that most gift card processors allow for the process of 'cashing out' the card. Provided the store allows, there's no reason that there would be unclaimed cash left on the card. Of course, those merchants that do NOT allow cash-out are the ones to be concerned with.


    Slow news day, plain and simple.
    --
    /* .sigs are irrelevant */