All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Credit Card Data Vulnerable to Derivation Attacks Despite PCI DSS Compliance

By

kodbraker

1mo ago· 8 min readenInsight

Summary

The article discusses how credit card data can be stolen or derived even from PCI DSS compliant ecommerce websites. The author shares a personal experience of having their card compromised despite the merchant following industry security standards. It explains the vulnerabilities in how credit card numbers are stored and displayed, and how brute force-like attacks can derive valid card numbers from partial data visible on UIs and receipts.

Key quotes

· 3 pulled
These days, storing and showing what's visible on UI's and receipts are highly standardized and regulated by the industry standards such as PCI DSS.
And even when you save your card on an ecommerce website, which strictly follows the PCI DSS, your card can still be stolen - or derived. As it happened to me.
PCI DSS is the widely known and implemented industry standard for defining bare-minimum security measures that should be taken when handling sensitive banking data such as credit cards.
Snippet from the RSS feed
These days, storing and showing what's visible on UI's and receipts are highly standardized and regulated by the industry standards such as PCI DSS. And even when you save your card on an ecommerce website, which strictly follows the PCI DSS, your card c

You might also wanna read