The lion's share of the credit card situation can be laid with the credit card companies themselves. Transactions are not authenticated beyond perhaps a cursory glance at a signature. If every transaction needed to be authenticated so that the person requesting the transaction was indeed the cardholder, the value of the card number would be diminished. Since transactions are unauthenticated for the most part, the number has value.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/newsbriefs/481/1884#1884