Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

From what HTP said on IRC, the credit card numbers were decrypted within the application context, which would be consistent with what you said. But during the IRC conversation, HTP willingly gave out the last four digits of people's CC#s, but ignored any request for digits before that, which would be more consistent with what Linode is stating.

It's all a very confusing world where nobody has a definite answer. Just 2 cents, don't act like I'm sharing a fact or anything



There's no inconsistency. Linode said "Credit card numbers in our database are stored in encrypted format... Along with the encrypted credit card, the last four digits are stored in clear text..."


Last 4 is all you need to wreak some serious havoc though. Service cancellations and whatnot...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: