Credit-card experts explain the extent of Obama’s deception


Blog For Free!


Archives
Home
2009 November
2009 October
2009 September
2009 August
2009 July
2009 June
2009 May
2009 April
2009 March
2009 February
2009 January
2008 December
2008 November
2008 October
2008 September
2008 August
2008 July
2008 June
2008 May
2008 April
2008 March
2008 February
2008 January
2007 December
2007 November
2007 October
2007 September
2007 July
2007 June
2007 May
2007 April
2007 March
2007 February
2007 January
2006 December
2006 November
2006 October
2006 September
2006 August
2006 July
2006 June
2006 May
2006 April
2006 March
2006 February
2006 January
2005 December
2005 November
2005 October
2005 August
2005 July
2005 June
2005 May
2005 April
2005 March
2005 January
2004 December
2004 November
2004 October
2004 September
2004 August
2004 July

My Links
The Racist History of the Democratic Party
Global Warming: A Chilling Perspective
Internet Haganah
Watts Up With That?
Jihad Watch
Ponder the Maunder
The Dissident Frogman
Barking-Moonbat EWS
Just Barking Mad!
The Malaria Clock
Project Valour-IT
Islam: Turning everything it touches to Shi'ite since 632 AD...
10 Myths of Islam

tBlog
My Profile
Send tMail
My tFriends
My Images


Sponsored
Blog



Get 

Firefox!

Tell me when this blog is updated

what is this?


Click to Read


hacker emblem

/plg.swf?go=46VLG3802B085L3" />
Credit-card experts explain the extent of Obama’s deception
10.29.08 (1:04 pm)   [edit]

After writing twice about the deliberate decision by the Barack Obama campaign to avoid validation checks on credit-card contributions, I’ve heard from a number of people in the credit-card industry on how this works.  Two explanations in particular explain the depth of deliberation and deception involved in disregarding address and security-code verification.  The first explains that Team Obama probably didn’t just opt out of using these verification processes, but more likely rewrote the code on their site to bypass them, emphases mine:

I have over 30 years of experience in investigating Credit Card Fraud and I can tell you, which you may or may not know, that the merchant acquirer that is conducting the collection of credit / debit card for the Obama campaign are responsible for the actions to be taken regarding the Address Verification System responses.  The value of the AVS system is that the issuer of the card being used provides back to the merchant acquirer a response based upon the information provided during the authorization process.  This response indicates to the merchant acquirer if the card information was validated as to ownership of the account.  It is the merchant acquirer that determines what to do when the authorization response is received.  In most cases the transaction that comes back with any negative meaning is denied.  However, if the merchant acquirer has adjusted their system to accept any response as acceptable the transaction would be completed.

The value of the AVS system is to deny Card Not Present transactions (CNP) which are suspicious.  This protects the merchant against charge backs for bad transactions.  What is interesting to me is that the merchant acquirer has knowingly violated a basic CNP fraud prevention technique to accommodate a merchant (Obama Campaign).  I think that both the Associations (VISA & MasterCard) would be highly interested in looking at the merchant acquirer that was processing these transactions.  The value of ignoring the AVS responses is that multiple invalid transactions may be made without fear of being rejected by the authorization systems.  This means that the real owner of the credit card account is willing to allow multiple transactions to be made on the account using different names and addresses that under normal conditions would be denied.  The merchant acquirer has a complete listing of all transactions done and it would be very interesting to see how many transactions were conducted on the same account number using different names.  I would think that this would be a Federal violation under the current campaign funding laws.

Another fraud-prevention veteran notes that Team Obama has at the least provided a testing ground for thieves looking to validate responses:

You may have mentioned this elsewhere, but disabling the security allows would be credit card thieves to “ping” numbers till they get a hit.  The number of “pings” should have raised flags at Visa and MasterCard, don’t you think?

I wonder if they warned the Obama campaign, or worse, ignored it.

In other words, a crook could simply type in random numbers until he found one sequence that worked in some fashion.  That could give a thief a starting point for committing credit-card fraud.  If all they had to do was type nonsense values for names and addresses, such as Doodad Pro, they could quickly determine which numbers were valid — and they could probably program bots to do that kind of work.

Thanks to Team Obama, millions of people now have to wonder whether they’ve been victimized by credit thieves.  Some of us wonder if the thieves aren’t really working at Team Obama in the first place.

Hot Air

0 Comments
 
Your Name:


Your Comment:


Locations of visitors to this page





 Use OpenOffice.org

My computer geek score is greater than 100% of all people in the world! How do you compare? Click here to find out!

I am nerdier than 99% of all people. Are you a nerd? Click here to take the Nerd Test, get geeky images and jokes, and write on the nerd forum!




Get this widget!