TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

OnePlus got pwned, exposed up to 40,000 users to credit card fraud

19 点作者 anaxag0ras超过 7 年前

2 条评论

joshmn超过 7 年前
Credit card fraud expert here:<p>This happens way more often than you think, particularly with sites that aren&#x27;t known to you and me. It&#x27;s entirely trivial to do, very effective, and maintenance next to nothing — but you already know that. As companies continue to choose Stripe&#x2F;Braintree&#x2F;etc and maintaining PCI compliance with their payment processor, keyloggers are being deployed less and less.<p>What is needed is a browser extension that checks all requests which contain a param&#x2F;form data that is 16-digits long and starts with 4&#x2F;5&#x2F;6 or 15-digits long and starts with 3. Is such a thing fool-proof? No, it&#x27;s not. But it&#x27;d be a starting point. Maybe add a listener to any inputs that contain such a val to see if anything&#x27;s hooking into it. Need to whitelist it for ancient processors? Okay, prompt the user.
xattt超过 7 年前
I wonder if this number correlated to how many OnePlus customers there have been in total.