Note that the 3-digit code verifies the number and expiration date. It is not like a randomized verification code that only exists on the card, so if someone has the card number, expiration date and knows the verification algorithm, they could simply reverse-derive the code number.
The account number, expiration date, and another value are combined and then encrypted using secret keys only the bank has. Then 3 or 4 digits are extracted from that encrypted value and are either stored on the mag stripe or in the chip, or are printed on the back.
When you attempt a transaction, the bank’s computer runs the same encryption calculation again and if the CVV the merchant provides with the transaction matches the one they just generated, the card is good. Else it’s not.
So a bad guy who had somehow gotten the account number and expiration date, but not the CVV, could not compute the CVV on their own unless they also had the bank’s secret encryption key. That key isn’t in the card, isn’t in the merchant’s terminal, isn’t anywhere except at that card issuer’s computers that authorize transactions or make new cards.
Now for sure, since the CVV is only 3 digits long, somebody could try to brute force a fraudulent transaction: just try the card number and expiration date with a CVV of 000, then 001, then 002, etc., up to 999. But decent bet the issuer would kill the card for too many attempted failed transactions long before the bad guy got lucky.
I would think that the majority of credit card fraud is the result of a data breach, but there are a lot of assholes out there trying to scam you. Hiding the number doesn’t seem necessary to me, unless you eat at restaurants a lot and the wait staff takes your card out of your sight. But even then, can’t a skimmer get your info?
I was in Vancouver, BC in 2013 and every restaurant had the little handheld readers. I am starting to see them more and more here but it is crazy how long it’s taking to proliferate here. MERCA!
Longer than that but the change across different vendors may not be universal. I got a card 18 months ago with no signature area.
I’ve had someone look at the signature on the card and compare it to the signature i wrote once in my life, and that was decades ago.
That being said, when my card was fraudulently duplicated, and the credit card company asked me questions to help their prosection of the person they thought had stolen it, the rep i spoke with said that the signature used by the thief didn’t look anything like my signature.
I have Capital One and, on their advice, generated a virtual card that I used only for online purchases. My account was compromised, but it was the virtual account that was compromised and not my “real” account with the data on the card. I had to get a whole new physical card with a whole new set of data. I haven’t recreated the virtual account for this one.
Nope. Don’t know how the first one was compromised. The second one, the replacement, got compromised too. But I received that replacement as promised in the mail. The second one got compromised before I even received it and activated it.
The reason, apparently, is something about virtual card numbers tying it all together.
I can’t quite figure that out either. I did get a virtual card and change all my online stuff thinking that the virtual card would be the same as my new card. Nope. Then the new card was compromised before I even got the card. They said it was because the new card was also tied to my virtual card that they just gave me.
So, when I did get a third card, I had to change everything back over to that and I got rid of the so called virtual card.