# Lowe's "security" for credit card usage.

**URL:** https://boards.straightdope.com/t/lowes-security-for-credit-card-usage/577962
**Category:** In My Humble Opinion
**Created:** [April 11, 2011, 3:45pm UTC](https://boards.straightdope.com/t/lowes-security-for-credit-card-usage/577962 "2011-04-11T15:45:31Z")
**Posts on this page:** 13
**Page:** 1

<div class="post-metadata">

### Author: ![crypto](https://avatars.discourse-cdn.com/v4/letter/c/b3f665/32.png) [@crypto](https://boards.straightdope.com/u/crypto)
#### Post date: [April 11, 2011, 3:45pm UTC](https://boards.straightdope.com/t/lowes-security-for-credit-card-usage/577962/1 "2011-04-11T15:45:31Z")

</div>

I have been wondering about this for awhile, but perhaps there is someone out here that works for Lowes, or can explain the logic behind this…

I check out at Lowes and use my credit card. For some inexplicable reason, they ask me for the last 4 digits of my credit card. What good does that do (besides annoy me, by making me pull my wallet back out to get my credit card again)?

This is the dumbest security measure of all time. If I’ve stolen a credit card, I would physically have to have it to use it. So, I can look at the card and put it back, just like someone would if they were the legitimate owner of the card. WTF?

A better thing to ask me is what my zip code is. At least with that, if I don’t know it, I am not going to able to wing it. Without knowing the billing address, I won’t be able to guess the zip unless I’m incredibly lucky, or know the person I stole the card from.  
Not fool-proof by any stretch, but it’s better than the last four digits of the card.

Anyone know why Lowes asks for this info? (I’m not sure of any other store that asks for the cards digits)?

---

<div class="post-metadata">

### Author: ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)
#### Post date: [April 11, 2011, 4:15pm UTC](https://boards.straightdope.com/t/lowes-security-for-credit-card-usage/577962/2 "2011-04-11T16:15:20Z")

</div>

It is (or was) a pretty standard scam to alter the mag stripe of a legit card to have a different stolen account number on the mag stripe. Having the clerk check that the last 4 embossed numbers match the last 4 from the mag stripe pretty well defeats that scam.

It’s also is a way for the store to ensure the clerk actually handles & looks at the card. That way the clerk can detect things like plain white card stock cards, unsigned cards, known fake bank cards, etc. By demanding the clerk actualy key the numbers, they pretty well force the clerk to actually do this step, not just blow it off.

With any retail “security” procedure, rememember there are 3 actors: the customer, the clerk, and corporate management. As customer often you’re just watching a security transaction between the other two parties.

Ref the two recent threads about “no receipt? your purchase is free.” and “I hate receipt checkers at the exit.” Both of those procedures are about management trying to prevent theft by clerks, not theft by you.

---

<div class="post-metadata">

### Author: ![Gus\_Gusterson](https://avatars.discourse-cdn.com/v4/letter/g/85f322/32.png) [@Gus\_Gusterson](https://boards.straightdope.com/u/Gus_Gusterson)
#### Post date: [April 11, 2011, 4:17pm UTC](https://boards.straightdope.com/t/lowes-security-for-credit-card-usage/577962/3 "2011-04-11T16:17:41Z")

</div>

They’re doing it wrong. They are supposed to ask for the card and enter the last four digits themselves to confirm that the numbers embossed on the card match the numbers that were read from the magnetic strip on the card. This protects against cards that have been reprogrammed with stolen numbers (so that the numbers embossed on the card don’t match what the magnetic strip says). Lowe’s obviously instituted this policy and then gave no training on it.

---

<div class="post-metadata">

### Author: ![Lasciel](https://avatars.discourse-cdn.com/v4/letter/l/e79b87/32.png) [@Lasciel](https://boards.straightdope.com/u/Lasciel)
#### Post date: [April 11, 2011, 4:21pm UTC](https://boards.straightdope.com/t/lowes-security-for-credit-card-usage/577962/4 "2011-04-11T16:21:39Z")

</div>

> [@LSLGuy](#):
>
> It is (or was) a pretty standard scam to alter the mag stripe of a legit card to have a different stolen account number on the mag stripe. Having the clerk check that the last 4 embossed numbers match the last 4 from the mag stripe pretty well defeats that scam.
> 
> _ **It’s also is a way for the store to ensure the clerk actually handles & looks at the card. That way the clerk can detect things like plain white card stock cards, unsigned cards, known fake bank cards, etc. By demanding the clerk actualy key the numbers, they pretty well force the clerk to actually do this step, not just blow it off.** _
> 
> snip

Not true. Both Lowes, HD, and Target clerks ASK THE CUSTOMER what the last 4 digits are. That accomplishes shit-all for security.

I cannot remember the last time a clerk TOUCHED or even asked to LOOK at my credit card. I could be swiping a strip of cardboard through their little scanner whatsis for all they know. All the asking for the last 4 digits accomplishes is to make sure the scam artist knows what their overlaid mag-number is, and rattle that sucker off. Hell, if they wanted to be really sneaky about it, have them dig the card out of their wallet, pretend to look at the last 4 digits, and THEN tell the cashier the fake numbers.

I’m sure it was intended to make it harder for scams, but the cashiers are circumventing it quite nicely in the interests of doing less work.

---

<div class="post-metadata">

### Author: ![Dewey\_Finn](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dewey_finn/32/4222_2.png) [@Dewey\_Finn](https://boards.straightdope.com/u/Dewey_Finn)
#### Post date: [April 11, 2011, 4:33pm UTC](https://boards.straightdope.com/t/lowes-security-for-credit-card-usage/577962/5 "2011-04-11T16:33:58Z")

</div>

A few times, I’ve had the clerk ask to see my credit card. I think most recently at Best Buy. It’s annoying when I’m using one of the swipe-it-yourself machines, I’ve already swiped the card and put it back in my wallet. If you’re going to ask for the card, you might as well swipe it yourself.

---

<div class="post-metadata">

### Author: ![Zsofia](https://avatars.discourse-cdn.com/v4/letter/z/7bcc69/32.png) [@Zsofia](https://boards.straightdope.com/u/Zsofia)
#### Post date: [April 11, 2011, 5:54pm UTC](https://boards.straightdope.com/t/lowes-security-for-credit-card-usage/577962/6 "2011-04-11T17:54:40Z")

</div>

The funniest part is where you do self checkout at Lowes and the MACHINE asks for your last four digits. Not even a person!

---

<div class="post-metadata">

### Author: ![crypto](https://avatars.discourse-cdn.com/v4/letter/c/b3f665/32.png) [@crypto](https://boards.straightdope.com/u/crypto)
#### Post date: [April 12, 2011, 2:38am UTC](https://boards.straightdope.com/t/lowes-security-for-credit-card-usage/577962/7 "2011-04-12T02:38:49Z")

</div>

I’m actually glad I asked the question. I had no idea that it is a security measure that, if performed correctly, actually makes some sense. But like \*\*Lasciel \*\*and others, I can’t remember when anyone actually \*asked \*for my card. The last time someone did, it was at Christmas, and they looked for the signature match. Also a stupid security feature (if I stole it and signed it, my signature will look the same), but at least they made an effort.

> [@Zsofia](#):
>
> The funniest part is where you do self checkout at Lowes and the MACHINE asks for your last four digits. Not even a person!

Based on the theory of how this security measure is supposed to work, this is laughable! I’d like to see Lowes get sued from Visa for promoting theft.

Also, I just want to add my ignorance to the altering the strip in the first place. How on earth is that done? It must be easy, but damned if I know how to do it. Can I buy something legally to read my card’s magnetic strip? Aren’t the strips even the least bit encoded? How on earth do criminals figure out how to do this?

---

<div class="post-metadata">

### Author: ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)
#### Post date: [April 12, 2011, 3:13pm UTC](https://boards.straightdope.com/t/lowes-security-for-credit-card-usage/577962/8 "2011-04-12T15:13:53Z")

</div>

The stripes are not encoded or secret at all. Simplifying just a bit, the stripe contains the same name and account number as are embossed into the plastic. And it’s in plain text in plain old ASCII: “John A Smith 4001 1234 5678 9012”

Anyone can buy machines which read or write those stripes. After all, those same cards are used for hotel keys, company ID badges, and a jillion other uses. The layout of the data itself confirms to a publicly published standard. Otherwise, how would all the companies which make the equipemt or cash register software know how to process the data?

All this design dates from the 1960s when life was simpler. And it can’t be changed since there’s so much installed equipment which reads only the dumb old standard.

The push to RFID or other “smart-card” standards is partly a way to inject more hack-reistance into the cards. But since most fraud now is conducted online where the physical card isn’t even used, that effort is a bit of closing the barn door on a mostly-gone horse. Soon enough our credit "card"s will just be an app on our smartphone which talks to an app on the credit card terminal / cash register.

---

<div class="post-metadata">

### Author: ![crypto](https://avatars.discourse-cdn.com/v4/letter/c/b3f665/32.png) [@crypto](https://boards.straightdope.com/u/crypto)
#### Post date: [April 13, 2011, 9:01am UTC](https://boards.straightdope.com/t/lowes-security-for-credit-card-usage/577962/9 "2011-04-13T09:01:47Z")

</div>

> [@LSLGuy](#):
>
> The stripes are not encoded or secret at all. Simplifying just a bit, the stripe contains the same name and account number as are embossed into the plastic. And it’s in plain text in plain old ASCII: “John A Smith 4001 1234 5678 9012”

Wow. I had no idea it was this basic. I’m not sure why it never occurred to me, as you are quite right in that to encode the data would require a massive effort to make sure the other device could read it and interpret it correctly. Perhaps I thought that even a basic encoding would have been done at the beginning. Even if it was a public standard, it’s a layer of security that might keep a segment of thieves from considering this type of crime. Kind of like putting an unlocked club onto your steering wheel.

---

<div class="post-metadata">

### Author: ![Skald\_the\_Rhymer](https://avatars.discourse-cdn.com/v4/letter/s/ecccb3/32.png) [@Skald\_the\_Rhymer](https://boards.straightdope.com/u/Skald_the_Rhymer)
#### Post date: [April 13, 2011, 2:50pm UTC](https://boards.straightdope.com/t/lowes-security-for-credit-card-usage/577962/10 "2011-04-13T14:50:35Z")

</div>

> [@Gus\_Gusterson](#):
>
> They’re doing it wrong. They are supposed to ask for the card and enter the last four digits themselves to confirm that the numbers embossed on the card match the numbers that were read from the magnetic strip on the card. This protects against cards that have been reprogrammed with stolen numbers (so that the numbers embossed on the card don’t match what the magnetic strip says). Lowe’s obviously instituted this policy and then gave no training on it.

Or the employee in question ignored the training. I used to be a retail store trainer, and people often seemed to forget extremely simple things ten minutes after going through a training class and signing off on the procedure. Not just the low-wage clerks in Men’s Underwear either; some of our appliances commission salesfolk made respectable middle-class incomes but couldn’t be arsed to recall how to process credit cards to avoid chargebacks that would cost them their commission.

---

<div class="post-metadata">

### Author: ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)
#### Post date: [April 14, 2011, 11:28am UTC](https://boards.straightdope.com/t/lowes-security-for-credit-card-usage/577962/11 "2011-04-14T11:28:20Z")

</div>

At my two closest Lowes the clerks always ask to handle the card. And then they read & key the last 4 themselves.

So for Lowes specifically, not all amployees at all stores do it wrong. So I bet the corporate policy is written correctly and the problem falls to lazy local store management and/or poor local training.

I do agree it’s funny when the self-checkout machine asks me to key my own numbers. Although that will still trap some small percentage of would-be crooks.

---

<div class="post-metadata">

### Author: ![Wallenstein](https://avatars.discourse-cdn.com/v4/letter/w/b5a626/32.png) [@Wallenstein](https://boards.straightdope.com/u/Wallenstein)
#### Post date: [April 14, 2011, 12:59pm UTC](https://boards.straightdope.com/t/lowes-security-for-credit-card-usage/577962/12 "2011-04-14T12:59:34Z")

</div>

The drive behind chip & pin is to remove the need for staff to handle cards. Lots of card fraud is caused by employees “skimming” cards while pretending to swipe for a sale.

When I go shopping (in the UK) the staff never, ever need to handle my card except on the very rare occasions they need to enter the details manually.

---

<div class="post-metadata">

### Author: ![Folacin](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/folacin/32/3195_2.png) [@Folacin](https://boards.straightdope.com/u/Folacin)
#### Post date: [April 14, 2011, 1:38pm UTC](https://boards.straightdope.com/t/lowes-security-for-credit-card-usage/577962/13 "2011-04-14T13:38:58Z")

</div>

> [@LSLGuy](#):
>
> I do agree it’s funny when the self-checkout machine asks me to key my own numbers. Although that will still trap some small percentage of would-be crooks.

Possibly more than a small percentage - I’d guess that a lot of hacked cards are sold/distributed to small-time thieves, who possibly don’t know the encoded number (or, if they were told it, are no more likely to remember it than the Lowe’s clerk is to remember the proper procedure for handling cards).
