首页> 外文会议>Information Security for South Africa Conference >An investigation into credit card information disclosure through Point of Sale purchases
【24h】

An investigation into credit card information disclosure through Point of Sale purchases

机译:通过销售点购买对信用卡信息披露进行的调查

获取原文

摘要

The use of debit and credit cards has become indispensable to consumers worldwide. This cashless method of payment offers flexibility and convenience. It eliminates the safety risk of carrying large cash amounts in person and cards can be cancelled as soon as it is lost or stolen. One of the most popular methods of non-cash transactions is through a Point of Sale (POS) terminal. A POS is a quick and convenient method for a customer to pay a business, but may lead to the disclosure of sensitive information without the knowledge of the customer. By investigating the information printed on the customer and merchant transaction receipts at various POS devices in South Africa, it is shown that information provided on the POS transaction receipts can put the consumer at risk as the credit card number, expiry date and name of the card holder may be printed on these transaction receipts. This paper investigates various POS devices used by South African businesses and the relevant information printed on the merchant and customer transaction receipts after a transaction. It is shown that the information contained in the transaction receipts from certain POS terminals is sufficient to perform successful online purchases at multiple online shopping sites. We also show that when the CVV number on the back of the credit card can be obtained while the transaction is in progress, even more online shopping sites can be successfully used without the authorisation or knowledge of the credit card owner.
机译:借记卡和信用卡的使用已成为全球消费者不可或缺的工具。这种无现金付款方式提供了灵活性和便利性。它消除了亲自携带大笔现金的安全风险,并且一旦丢失或被盗卡就可以取消。最受欢迎的非现金交易方法之一是通过销售点(POS)终端。 POS是客户付款业务的一种快速便捷的方法,但是可能会导致在客户不知情的情况下泄露敏感信息。通过调查在南非的各种POS设备上印在客户和商家交易收据上的信息,可以看出,在POS交易收据上提供的信息可能会使消费者面临风险,例如信用卡号,有效期和卡名。持有人可以打印在这些交易收据上。本文调查了南非企业使用的各种POS设备以及交易后印在商人和客户交易收据上的相关信息。可以看出,包含在来自某些POS终端的交易收据中的信息足以在多个在线购物站点执行成功的在线购买。我们还表明,当在交易进行过程中获得信用卡背面的CVV号时,即使没有信用卡所有者的授权或知识,也可以成功使用更多的在线购物网站。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号