Hacker News new | ask | show | jobs
by helper 4568 days ago
Why would you think that Target OCRs CVV2? They already have CVV1 (used for card in hand) read off the magstrap, so what would they want with CVV2? It would also be an insane violation of PCI rules.
1 comments

As far as I know, big companies can negotiate with the individual networks to do whatever they want with your credit card information, including storing the data in a non-PCI-compliant manner.