TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Square's public card transaction search – is it safe?

3 pointsby dc352almost 8 years ago
I have played with our SSL cert check tool https:&#x2F;&#x2F;keychest.net , testing SSL certs of various web servers.<p>When I did it for &quot;squareup.com&quot;, I got a few additional domains present in the cert, including &quot;gosq.com&quot;, which turns out to be a public service, a &quot;card transaction search&quot;.<p>You enter your last 4 card digits, an expiry date, a transaction date and a transaction value, and it will show you a receipt.<p>It appears to be a legitimate service - available from support pages. It just feels really wrong. The &quot;search space&quot; seems to me pretty small to get loads of random hits. (Even though there&#x27;s a limit in the number of tries.)

no comments

no comments