Slashdot Mirror


This Gizmo Knows Your Amex Card Number Before You've Received It (csoonline.com)

itwbennett writes: A small device built by legendary hacker Samy Kamkar can predict what new American Express card numbers will be and trick point-of-sale devices into accepting cards without a security microchip. Because American Express appears to have used a weak algorithm to generate new card numbers, the device, called MagSpoof, can predict what a new American Express card number will be based on a canceled card's number. The new expiration date can also be predicted based on when the replacement card was requested.

2 of 68 comments (clear)

  1. Re:Not too hard by wonkey_monkey · · Score: 5, Insightful

    This isn't exactly an amazing product.

    I think that's rather the point of the story.

    --
    systemd is Roko's Basilisk.
  2. Re:Can I predict mine though? by Anonymous Coward · · Score: 5, Insightful

    Think out the implications of this. You have an Amex card, and your information gets comprised when a retailer's system is hacked. The standard response is for the credit card card companies to cancel your existing card and issue you a new one with a different account number.

    Issuing you a new card is pointless if the new account number can be predicted by anyone who has the old one. The new expiration date is also predictable based on when the card was replaced, which should be pretty easy to guess in the case of mass replacements due to a hack.