එහෙමත් එකක් තියෙනවදඇයි මේ ත්රෙඩ් එක එලකිරි එකේ මුල පෙන්නන්නෙ නැත්තෙ?![]()
එහෙමත් එකක් තියෙනවදඇයි මේ ත්රෙඩ් එක එලකිරි එකේ මුල පෙන්නන්නෙ නැත්තෙ?![]()
thread 4 k yata pennane. 3 fast yanawa mekata wadaඇයි මේ ත්රෙඩ් එක එලකිරි එකේ මුල පෙන්නන්නෙ නැත්තෙ?![]()
නෑ බං මට මොන වදිියකින්වත් එලකිරි හෝම්පේජ් එකේ මේ ත්රෙඩ් එක පේන්නෙ නෑ. මම Find කරලත් බැලුවthread 4 k yata pennane. 3 fast yanawa mekata wada
නෑ බං මට මොන වදිියකින්වත් එලකිරි හෝම්පේජ් එකේ මේ ත්රෙඩ් එක පේන්නෙ නෑ. මම Find කරලත් බැලුව
Uwa ignore karanna epa ban. some good content he posted just like this

It is like this, if you are using CCs now you need to put the cvv number and then if everything is right you have the OTP (even browsers will only save name, cc# and expiry). So the chances of doing shit with stolen CC numbers are quite low unless the figure out some complex scheme. So no need to be too paranoid but would be a good opportunity to penalize fucker like this who are more interested in profits than safety of the data they collect.So the merchant's customer's Cards are compromise. so what if hackers publish the Data Dump and people already have got the card numbers try to Use the cards? in that case don't you think that customer should empty the Related account ?
Let me correct some point. when you connect to a Direct-Debit Payment Network you don't need an OTP CVV of customer every time. . All things happen under the hood. (When you pay using google Pay you just need a thumb print and you wont get any OTP) customer never ask for CVV or anything. they just need to given there thumb print and transaction done. So to handle this Marchant side must keep some track(AUTH Keys for DDP networks and Another data set.). basically customer gave mandate to handle transaction for them. good side this is very easy for customer.It is like this, if you are using CCs now you need to put the cvv number and then if everything is right you have the OTP (even browsers will only save name, cc# and expiry). So the chances of doing shit with stolen CC numbers are quite low unless the figure out some complex scheme. So no need to be too paranoid but would be a good opportunity to penalize fucker like this who are more interested in profits than safety of the data they collect.
What pissed me off is the arrogance and the lack of transparency (only revealed this because they got their pants pulled down in public)
මේක මචන් ඉතින් ගොඩක් ඇප්වල කරනවනෙ ලංකාවෙ
- ඉන්පසු "බැංකු ගිණුම connect කරන්න" button එක ඔබා, ඔබේ බැංකුව, හැඳුනුම්පත් අංකය සහ ගිණුම් අංකය ලබාදෙන්න.
- එවිට ඔබේ බැංකුවෙන් ඔබට SMS හරහා ලැබෙන OTP අංකය (JustPay code එක) හෙළPay වෙත ඇතුළත් කරන්න.
මට මේ ගැන ලොකු දැනුමක් නෑ. මට කියපන් එහෙම ඩේටා ඉස්සුව කියල උන්ට cvv නැතුව payment එකක් කරන්න පුලුවන්ද? එහෙම පුලුවන් වෙන්නෙ මොන ඩේටා හින්ද්ද? මොකද දැන් වෙන කෙනෙක්ට cvv නැතුව payment එකක් කරන්න බෑනෙ. ඔය payhere වගේ network එකකට උනත් මුලින් authorize කරල දෙන්න එපැයි. Payhere එකෙන් කියන්නෙ cc numbers උනත් partial ගිහින් තියෙන්නෙ කියල. අනික password breach එකක් නැති නිසා පාස්වර්ඩ් මාරු කරන්න උවමනාවක් නෑ නේද?Let me correct some point. when you connect to a Direct-Debit Payment Network you don't need an OTP CVV of customer every time. . All things happen under the hood. (When you pay using google Pay you just need a thumb print and you wont get any OTP) customer never ask for CVV or anything. they just need to given there thumb print and transaction done. So to handle this Marchant side must keep some track(AUTH Keys for DDP networks and Another data set.). basically customer gave mandate to handle transaction for them. good side this is very easy for customer.
Now this system is hacked and that party got all the customer and secure data (we don't know the extend of the hack but we should think of the maximum for sake of the customers). now it's very easy to Commit a Direct Debit - pulls because attacker already have customer data and all the Auth he needs.
And yes this is not easy for a programmer but a professional can easily do this. that's why people hack these kind of systems.
All i am saying is that don't take any chance.
)හරි උබට පොඩි පැහැදිලි කිරීමක් කරන්නම්මේක මචන් ඉතින් ගොඩක් ඇප්වල කරනවනෙ ලංකාවෙ
මට මේ ගැන ලොකු දැනුමක් නෑ. මට කියපන් එහෙම ඩේටා ඉස්සුව කියල උන්ට cvv නැතුව payment එකක් කරන්න පුලුවන්ද? එහෙම පුලුවන් වෙන්නෙ මොන ඩේටා හින්ද්ද? මොකද දැන් වෙන කෙනෙක්ට cvv නැතුව payment එකක් කරන්න බෑනෙ. ඔය payhere වගේ network එකකට උනත් මුලින් authorize කරල දෙන්න එපැයි. Payhere එකෙන් කියන්නෙ cc numbers උනත් partial ගිහින් තියෙන්නෙ කියල. අනික password breach එකක් නැති නිසා පාස්වර්ඩ් මාරු කරන්න උවමනාවක් නෑ නේද?
(Dialog app එකේ එහෙමනන් fingerprint එකවත් ඕනෙ නෑ නිකන්ම payment එක වෙනව ටච් කරපු ගමන්)
------ Post added on May 3, 2022 at 1:53 PM
හෙළPay වෙත බැංකු ගිණුමක් connect කරන්නේ කොහොමද?
හෙළPay වෙත බැංකු ගිණුමක් connect කිරීම ඉතාම සරලයි. ඒ සඳහා,
හෙළකුරු App එක තුළ ඇති හෙළPay icon එක ඔබා, එහි ඉහලින් දිස්වන + සලකුණ ඔබන්න.
ඉන්පසු "බැංකු ගිණුම connect කරන්න" button එක ඔබා, ඔබේ බැංකුව, හැඳුනුම්පත් අංකය සහ ගිණුම් අංකය ලබාදෙන්න.
එවිට ඔබේ බැංකුවෙන් ඔබට SMS හරහා ලැබෙන OTP අංකය (JustPay code එක) හෙළPay වෙත ඇතුළත් කරන්න.
මෙසේ කළ පසු ඔබේ බැංකු ගිණුම හෙළPay වෙත connect වී, ඒ ගැන ඔබට දැනුම්දීමක් ලැබෙනු ඇත.
There is a way to gain access to iCloud account with partial card details. This issue must not be neglected. The owner should be held accountable for playing with innocent life’s.It is like this, if you are using CCs now you need to put the cvv number and then if everything is right you have the OTP (even browsers will only save name, cc# and expiry). So the chances of doing shit with stolen CC numbers are quite low unless the figure out some complex scheme. So no need to be too paranoid but would be a good opportunity to penalize fucker like this who are more interested in profits than safety of the data they collect.
What pissed me off is the arrogance and the lack of transparency (only revealed this because they got their pants pulled down in public)
To be honest I am not an expert on this shit, nor have I used debit cards or payhere. So not sure how it works. But I also think that there should be regulations on what is stored and how things are handled without just doing whatever you like to make the coding part easy.හරි උබට පොඩි පැහැදිලි කිරීමක් කරන්නම්
මේක බලපන්
මේකට තමා ඩිරෙක්ට් ඩෙබිට් ට්රාන්සක්ෂන් කියන්නේ. උබ මර්චන්ට්, උබේ කස්ටමර් ගේ කාඩ් විස්තර අරගෙන උබ එක බෑන්ක් එකට දීලා කටම්ර් වෙනුවෙන් උබ පේ කරනවා කියල බෑන්ක් එක ඔකේ කරගෙන තියෙන්නේ. හැබැයි කටම්ර් ගේ ඔකේ එක ලැබුනාම. එකට තමා ෆින්ගර් ප්රින්ට් එක දෙන්නේ. එක හෙලකුරු සයිඩ් එකට ඔකේ එකක් විතරයි. හැක් කල එකා ලග ඕක සිමුලටේ කරන්න පුළුවන් ඔක්කොම තියෙනවා.
My personal opinion is that Banks should not allow the method Direct Debit. it allow you to access customers account with less secure steps. i think VISA Europe taking steps to step down these transactions. i don't know about the Asia Pacific gateways. but it should happen soon.To be honest I am not an expert on this shit, nor have I used debit cards or payhere. So not sure how it works. But I also think that there should be regulations on what is stored and how things are handled without just doing whatever you like to make the coding part easy.
I think banks too are in hot water for working with these guys without proper auditing.
එතකොට මචන් මේ breach එකත් එක්ක banks වලින් හෝ payhere සයිඩ් එකෙන් එහෙම simulate කරන්න බැරිවෙන්න මොකක් හරි step එකක් ගන්නෙ නැද්ද? (අලුත් key එකක් use කරනව හරි මොකක් හරි... I don't know whatever it is)හරි උබට පොඩි පැහැදිලි කිරීමක් කරන්නම්
මේක බලපන්
මේකට තමා ඩිරෙක්ට් ඩෙබිට් ට්රාන්සක්ෂන් කියන්නේ. උබ මර්චන්ට්, උබේ කස්ටමර් ගේ කාඩ් විස්තර අරගෙන උබ එක බෑන්ක් එකට දීලා කටම්ර් වෙනුවෙන් උබ පේ කරනවා කියල බෑන්ක් එක ඔකේ කරගෙන තියෙන්නේ. හැබැයි කටම්ර් ගේ ඔකේ එක ලැබුනාම. එකට තමා ෆින්ගර් ප්රින්ට් එක දෙන්නේ. එක හෙලකුරු සයිඩ් එකට ඔකේ එකක් විතරයි. හැක් කල එකා ලග ඕක සිමුලටේ කරන්න පුළුවන් ඔක්කොම තියෙනවා.