Reply to post: Re: Luhn Check to Retrieve card details

TalkTalk downplays extent of breach damage, gives extra details

Anonymous Coward
Anonymous Coward

Re: Luhn Check to Retrieve card details

That wouldn't really work in reality. If you had the first 6 and last 4 digits and then filled out the middle six with all possible combinations you'd create 1 million possibilities, with 100,000 passing the luhn/mod10 check. You've got no idea which ones are valid until you try to authorise them with an acquiring bank. You could generate all possible 10^16 credit card combinations and do the same, but you'd never get any authorised against an acquirer for a transaction with no further authentication data (CVV/Expiry/Name/Address, etc).

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Biting the hand that feeds IT © 1998–2019