Signing up for on-line services is a good use for "virtual account numbers". This is a feature offered on some Citibank and Discover credit cards (maybe others) that allows you to generate a separate credit card number that's billed to your original account. The nice thing about them is that once a virtual account number has been billed by a vendor, it does not accept any charges in the future except from the same ve…
I wish other banks offered that functionality. I am not a fan of Citibank.
If you didn't cancel the credit card you used for linode.com, now is the time
61–70 of 138 posts
Re: If you didn't cancel the credit card you used for linode.com, now is the time
#62Tangentially: Why do merchants really need to store CC numbers? From the consumers' standpoint, there would be no difference if, during the first transaction, the merchant is issued some alterate key with which to charge the account. Each merchant would be issued their own key, so there would be no risk of a security breach spreading outside of the merchant.
Depending on your payment provider, you will be however locked in and can't change anymore.
Re: If you didn't cancel the credit card you used for linode.com, now is the time
#63Earlier quoted context omitted.
The fact that Linode stored the public and private keys in the same directory is strong evidence that they do not have any competence in security. Their reluctance to disclose the compromise of their customer's passwords and financial data is evidence that they are not trustworthy. So on one hand we have someone who is careful enough about their finances to use disposable prepaid cards for renting a VPS. On the other…
"stored the public and private keys in the same directory" People keep harping on that, but as phrased that's not a problem. Wherever you have your private key, there's no reason not to also have your public key. The issue is if the private key was living somewhere inappropriate. Consider that "public and private keys in the same directory" is exactly what happens when you run ssh-keygen on any of the typical setups;…
Re: If you didn't cancel the credit card you used for linode.com, now is the time
#64Earlier quoted context omitted.
Why is using prepaid cards for online purchases fishy? - Prepaid cards impose an upper limit on what can be spent, so that if the card details leak out you are protected against losing more money than is on the card. They can't plunder your entire bank account. - Some people don't like the idea of having debt. By using a credit card you immediately have a debt whether you like it or not.
By using a credit card you immediately have a debt whether you like it or not. Credit cards are only debt if you treat them like debt. I use the shit out of mine, but pay the full balance pretty much every month. There's a lot of convenience, I'm fully protected from fraudulent activity, and I have a stupid amount of points/miles/whatever for free (or at least cheap) travel, to boot — I flew to .au a couple years ago…
Re: If you didn't cancel the credit card you used for linode.com, now is the time
#65Thanks, I was thankfully canceled my card. Is there anyone else here that has had their card compromised?
Re: If you didn't cancel the credit card you used for linode.com, now is the time
#66Earlier quoted context omitted.
"stored the public and private keys in the same directory" People keep harping on that, but as phrased that's not a problem. Wherever you have your private key, there's no reason not to also have your public key. The issue is if the private key was living somewhere inappropriate. Consider that "public and private keys in the same directory" is exactly what happens when you run ssh-keygen on any of the typical setups;…
You must be kidding. This is encryption 101. The private key is supposed to be moved to a secure location after key generation.
Re: If you didn't cancel the credit card you used for linode.com, now is the time
#67I haven't seen anything yet, and I tend to keep pretty close watch on it.
Re: If you didn't cancel the credit card you used for linode.com, now is the time
#68Tangentially: Why do merchants really need to store CC numbers? From the consumers' standpoint, there would be no difference if, during the first transaction, the merchant is issued some alterate key with which to charge the account. Each merchant would be issued their own key, so there would be no risk of a security breach spreading outside of the merchant.
One of the things you pay payment providers for is for taking on the risk of the higher levels of PCI compliance.
Re: If you didn't cancel the credit card you used for linode.com, now is the time
#69Earlier quoted context omitted.
By using a credit card you immediately have a debt whether you like it or not. Credit cards are only debt if you treat them like debt. I use the shit out of mine, but pay the full balance pretty much every month. There's a lot of convenience, I'm fully protected from fraudulent activity, and I have a stupid amount of points/miles/whatever for free (or at least cheap) travel, to boot — I flew to .au a couple years ago…
Your balance is irrelevant - your available credit line is debt, as at any moment you can be liable for up to that amount.
Re: If you didn't cancel the credit card you used for linode.com, now is the time
#70Earlier quoted context omitted.
By using a credit card you immediately have a debt whether you like it or not. Credit cards are only debt if you treat them like debt. I use the shit out of mine, but pay the full balance pretty much every month. There's a lot of convenience, I'm fully protected from fraudulent activity, and I have a stupid amount of points/miles/whatever for free (or at least cheap) travel, to boot — I flew to .au a couple years ago…
Your balance is irrelevant - your available credit line is debt, as at any moment you can be liable for up to that amount.