TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: Booking.com sends raw CC data to Hotels. Is it legal?

33 pointsby _hv99over 7 years ago
A friend of mine has a hotel and hostel and is partner with booking.com. He received 100s of CC raw data each day.<p>There is no protection whatsoever. Booking doesn&#x27;t manage payments on their own, they send the data clean-text directly to the hotel owner to process them using their own POS.<p>Is it legal? this is Masive.

4 comments

its_trivialover 7 years ago
they send raw credit card numbers, they dont send YOUR credit card number. They create a disposable credit card number, which they send down to the hotel, linked to your credit card. Its like a token in the form of a different credit card number. The hotel doesnt know the difference and the disposable credit card number has a fixed limit which is what you paid for your room. After that it is discarded, I dont know what happens to it afterwards. Edit: I work for a large hospitality software company, those numbers go thru us before they get to the hotel.
评论 #16110162 未加载
评论 #16104008 未加载
评论 #16107146 未加载
评论 #16103650 未加载
评论 #16114996 未加载
评论 #16103624 未加载
siquickover 7 years ago
You should edit the context of this question based upon the answer from its_trivial : <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=16103175" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=16103175</a>
boysabr3over 7 years ago
I think you have the answer already and IANAL but just to add on, in most countries this a matter of PCI compliance that is enforced by the card networks. In most countries it&#x27;s not a criminal offence to be PCI non-compliant (but you could be liable for civil suits and fines by the card schemes).<p>I imagine there&#x27;s a clause in the PCI compliance rules that allows raw card numbers to be sent less securely if they are virtual + single use card numbers or maybe if the liability of fraud on those card numbers doesn&#x27;t fall on the &quot;original&quot; card holders.
dammover 7 years ago
If you want to know it&#x27;s legal ask a lawyer.<p>Am I shocked? no... reminds me of ACH and the file format they use.