Live data from Hacker News

Ask HN: Liability due to lack of SSL

news.ycombinator.com

1–10 of 33 posts

Ask HN: Liability due to lack of SSL

#1
I have family member who sells stuff online. As part of his checkout experience he asks for CC info as well as SSN info on a HTTP website. I am trying to explain to him why this is bad, but he doesn't really care. What can I say to him factually that might help him make the investment in SSL (and not storing PII in SQL db) for that matter.

Re: Ask HN: Liability due to lack of SSL

#3
Beside the point, but why in the world is he collecting SSN numbers? That in itself is more concerning to me than not having SSL. But that's just me. I have had my identity stolen and know first hand how difficult, to almost impossible, it is to clean up.

With that said, I do know that many states have strict laws regarding the collection/use of SSN numbers via websites and/or for the sale of goods.

As for the credit card info, I believe most processors have in their terms that SSL is required for live transactions. I was also going to point to PCI compliance, but I am not sure how aggressive they are at going after the "little guy". Although with credit card theft in the US being a hot topic right now, I am sure anyone that is non-compliant will be a target for violations.

EDIT: To add link, starting at Page 12 talks about various state laws regarding SSN collection: http://www.gao.gov/new.items/d051016t.pdf

Re: Ask HN: Liability due to lack of SSL

#4
Unless he is a government, insurance, credit card, bank, real estate organization he should not be asking for a SSN online or storing it unless they are for his employees or the transactions being conducted requires notification to the IRS or the transaction is subject to the customer identification program rules. Either way PII like this should be securely stored offline.

For Credit Card information it has to all be transmitted and stored in an securely in accordance to the credit card merchant agreement he has agreed too.

The HTTP protocol is not secure, when your family member is hacked or audited they may be liable for many civil and criminal charges.

Have them read all the information for PCI DSS compliance - https://www.pcisecuritystandards.org/merchants/

You have done your part by advising him about the risks, privacy concerns and how bad it really is. Either way it is ultimately a risk he is accepting for himself and the business which he will have to deal with the consequences when something bad occurs in the future.

If he needs proof of how bad the decisions he has made can be, point him to many of the recent credit card and government organization breaches.

Re: Ask HN: Liability due to lack of SSL

#5

Beside the point, but why in the world is he collecting SSN numbers? That in itself is more concerning to me than not having SSL. But that's just me. I have had my identity stolen and know first hand how difficult, to almost impossible, it is to clean up. With that said, I do know that many states have strict laws regarding the collection/use of SSN numbers via websites and/or for the sale of goods. As for the credit…

Can someone explain how identity theft is even possible in the US? I hear a lot about it, but I can't understand how broken a system must be that makes it possible for someone to steal your identity just by having one identifier.

Re: Ask HN: Liability due to lack of SSL

#6
post #5

Beside the point, but why in the world is he collecting SSN numbers? That in itself is more concerning to me than not having SSL. But that's just me. I have had my identity stolen and know first hand how difficult, to almost impossible, it is to clean up. With that said, I do know that many states have strict laws regarding the collection/use of SSN numbers via websites and/or for the sale of goods. As for the credit…

Can someone explain how identity theft is even possible in the US? I hear a lot about it, but I can't understand how broken a system must be that makes it possible for someone to steal your identity just by having one identifier.

Hypothetical situation: what do you do if you lose all of your ID (e.g. house fire)? You have to start somewhere, and your SSN is a good choice.

You can't do it solely based on one single number, but in this case a data breach would include name, address, credit card number, SSN, and probably security questions. You can turn around and use that information to play the part of a person to another organization, and then go from there. Combine that data with social engineering, and you can get a lot of information about someone and then use it in further attacks.

That's not to say the US's system isn't broken; lots of companies ask for (and require!) the SSN even though they shouldn't. The problem is that it's not just one identifier that holds the key to your life, but that the SSN is an extremely strong identifier which is assumed to be secret.

Re: Ask HN: Liability due to lack of SSL

#7
post #5

Beside the point, but why in the world is he collecting SSN numbers? That in itself is more concerning to me than not having SSL. But that's just me. I have had my identity stolen and know first hand how difficult, to almost impossible, it is to clean up. With that said, I do know that many states have strict laws regarding the collection/use of SSN numbers via websites and/or for the sale of goods. As for the credit…

Can someone explain how identity theft is even possible in the US? I hear a lot about it, but I can't understand how broken a system must be that makes it possible for someone to steal your identity just by having one identifier.

That's the problem, it really is that easy. All it takes is someone to know you SSN and, depending on what they are trying to do, a little bit of information about you.

SSN numbers were originally only supposed to be used as a government identifier for social security, however, they have evolved into a unique identifier for all US citizens. They are used in every facet of the banking/credit industry here and are relied upon in determining financial decisions. For example, it is completely possible to simply know someone's SSN and date of birth to obtain a credit card. Although many banks/credit card companies are asking for increasing amounts of information to confirm it is really the person applying.

Re: Ask HN: Liability due to lack of SSL

#8
There is also the case for a potential increase in his conversion rates as a result of adding SSL.

Online shoppers I've observed in usability sessions often scour sites looking for evidence of security measures (e.g., green EV certs in the browser, various icons in the footer). This is especially true when you're asking for something like SSN info...

If appealing to the desire for security of user info doesn't work (unfortunately), appeal to his desire for more customers...

Re: Ask HN: Liability due to lack of SSL

#9
Seriously? Do cc vendors allow any random home hacker to create collection forms for credit cards. If I were visa I would at minimum have a checklist that must be fulfilled otherwise the store get their license withdrawn.

Re: Ask HN: Liability due to lack of SSL

#10
post #5

Beside the point, but why in the world is he collecting SSN numbers? That in itself is more concerning to me than not having SSL. But that's just me. I have had my identity stolen and know first hand how difficult, to almost impossible, it is to clean up. With that said, I do know that many states have strict laws regarding the collection/use of SSN numbers via websites and/or for the sale of goods. As for the credit…

Can someone explain how identity theft is even possible in the US? I hear a lot about it, but I can't understand how broken a system must be that makes it possible for someone to steal your identity just by having one identifier.

US banks lack any care about security in this area and rely on being able to eat the costs of fraud. This is clearly obvious even from logging into their sites. Many sites require weak passwords, have no two factor authentication, mix secure and insecure items, etc. They also are not very scrupulous when approving loan and credit card applications (for small amounts) and will do so even when the application has obviously been shredded and taped back together, for example, a clear sign of someone having grabbed it out of the garbage.

Regardless, between the greed and the complete lack of interest in security in this area leads customers extremely vulnerable as the only things that are required to open a credit card in another person's name are usually a name, address, date of birth, and social security number, all of which are essentially public to anyone who is even the least bit dedicated to committing fraud. This current situation benefits banks so much, the few costs they do actually have to pay for insurance and after the fact pale in comparison.

Post reply on HN