TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

OnePlus got pwned, exposed up to 40,000 users to credit card fraud

19 pointsby anaxag0rasover 7 years ago

2 comments

joshmnover 7 years ago
Credit card fraud expert here:<p>This happens way more often than you think, particularly with sites that aren&#x27;t known to you and me. It&#x27;s entirely trivial to do, very effective, and maintenance next to nothing — but you already know that. As companies continue to choose Stripe&#x2F;Braintree&#x2F;etc and maintaining PCI compliance with their payment processor, keyloggers are being deployed less and less.<p>What is needed is a browser extension that checks all requests which contain a param&#x2F;form data that is 16-digits long and starts with 4&#x2F;5&#x2F;6 or 15-digits long and starts with 3. Is such a thing fool-proof? No, it&#x27;s not. But it&#x27;d be a starting point. Maybe add a listener to any inputs that contain such a val to see if anything&#x27;s hooking into it. Need to whitelist it for ancient processors? Okay, prompt the user.
xatttover 7 years ago
I wonder if this number correlated to how many OnePlus customers there have been in total.