Live data from Hacker News

For your security, please email your credit card and driver’s license

troyhunt.com

21–30 of 70 posts

Re: For your security, please email your credit card and driver’s license

#21
post #4

What is with content that can't be seen unless you enable social media plugins? In this case, I'm not sure its intentional (looks related to how Disqus is embedded), but this is one of several such cases in the last couple weeks.

I see everything OK with NoScript enabled and blocking everything except google.com, googleapis.com, and blogger.com.

Re: For your security, please email your credit card and driver’s license

#23

Doesn't Mt Gox require copy of your ID to 'verify' you?

It's to verify that you're a real person --the same real person as attached to the bank account -- and that you're in the US (or whatever country). There are tax and liability considerations when you're moving money

Re: For your security, please email your credit card and driver’s license

#24
post #19

It's scary that this kind of thing ever comes up, you would think this kind of thing is blindingly obvious. Having said said, I seem to recall even Paypal asking me to send them copies of the my passport/ID and various other info when there was an issue on my account. I can't recall whether it was by email or uploaded through their site though... Question: Before writing these articles* does Troy Hunt go through a re…

Having recently changed my password with PayPal, I somehow doubt they are serious about security. They enforce a maximum length limit, disallow spaces and other "non-printable" characters (!), etc.

Re: For your security, please email your credit card and driver’s license

#25

HostGator pulled this exact crap with me. I said forget it and moved onto a different host for a client. I am just SHOCKED as it was "policy" for them to have a copy of drivers license/passport and a credit card on file!!!!

Hostgator did the same to me too! I also moved onto a different host. Here's the email they sent me when I asked for more info:

Hello, Thank you for your response.

We would like to provide you with an explanation of why we request verification.

If there are any billing discrepancies, missing information, or if the order is selected randomly for fraud prevention, the account is suspended until the verification is complete and an email is sent to the customer asking them to verify the account that they signed up for. We do not obtain anything for marketing purposes and are simply trying to confirm billing details or halt fraudulent accounts. It is our goal to make verification as easy and painless as possible and appreciate your patience.

If you review the Section 1 of our Terms of Service, you will see that we do state that we will continue with the set up of your account after we have received payment and we and/or our payment partner(s) have screened the order(s) in question in case of fraud. Additionally, we do require valid contact information and may terminate an account if none is given, but we prefer to request this information from you up front.

You can review our Terms of Service here: http://www.hostgator.com/tos/tos.php

Here is some more information regarding our Privacy Policy:

http://www.hostgator.com/privacy.shtml

We apologize for any inconveniences that may result from this process. This extra verification is done for your security and to ensure that orders are not duplicitous. The web hosting industry, unfortunately, has a high rate of fraudulent orders, and this sort of verification helps us drastically reduce fraud and ensure our customers remain secure.

If you are unable to verify your account with us or do not wish to proceed with the activation of your account, then no further action needs to be taken on your part. We have only authorized the charges and have never fully received the payment. We do not fully receive the payments until an account has been activated. Since we were unable to verify your account we will not proceed with activating the account.

The initial payment made to us will be reversed with in 48 hours. If you paid with PayPal, the purchase will be refunded automatically at this time. Though, if you paid with a credit card, the authorization reversal will post to your account typically 5-7 business days after that. Depending on the establishment you bank with would determine on how fast you receive the funds. Once we release the payments your bank holds the funds until they are able to fully process the transaction and show the amount that you paid in your account.

If you have any questions, comments, or concerns, please do not hesitate to contact us.

Best regards, [Name redacted] Senior Verifications and Fraud Prevention Agent

Re: For your security, please email your credit card and driver’s license

#26

Ctrip.com, a Chinese travel site, does this for purchases with a non-Chinese card. I spent a lot of time on the phone explaining why requesting that customers email such information was inexcusable. I've encountered similar problems with badges for site visits at some companies and national labs (which have strict guidelines on PII, including numerous "training courses", but poor implementation and admin staff often…

Namecheap did this to me a while back. For some reason I must have appeared fraudulent, although I can't imagine why.

They (IIRC) asked for a photo of an ID card with the name of the person on the credit card and a photo of something tying that name to the address provided.

Our drivers licenses have our addresses on them. Sent in a photo of a driver's license with all the other information obscured... So it was just the government's identifying marks, the name, address, and photo. The license number, height, weight, barcode, etc were all obscured. In retrospect, a nice big watermark that said "FOR NAMECHEAP ONLY" would have maybe been a good addition.

It was sufficient for them.

I saw no issues with it as far as a security measure. It wouldn't take much to find my name, picture, or address just digging around online - never mind with access to my email.

Re: For your security, please email your credit card and driver’s license

#27
post #4

What is with content that can't be seen unless you enable social media plugins? In this case, I'm not sure its intentional (looks related to how Disqus is embedded), but this is one of several such cases in the last couple weeks.

Disabling JavaScript lets me read the site without enabling the social stuff. I noticed that the content seems to be there, but then gets removed, presumably by JavaScript.

(Ghostery+Chrome here)

Re: For your security, please email your credit card and driver’s license

#28
post #5

So say a restaurant wants me to give them my card details to make a reservation but I'm in a crowded place (like on a train). I offer to email the details and they accept. I know it's bad but I would rather email my details then say it loudly over the phone and have everyone hear it. Now did they break PCI? Or not because I was the one who offered to send my details. How does one send their credit card details secure…

> I can (and will) contest them and get a new card, so really the bank is taking on risk. No, they company you are purchasing from is taking the risk (hence why they are asking for the additional info). The company that you purchase from is almost always the one who covers the loss in cases of a chargeback caused by CC fraud, not the bank/CC company.

I'm confused. If I give my card to company A, but somehow along the line someone gets the details and uses it buy something at company B. And there was no way to link it to company A. How is company A having any risk whatsover?

I believe it's company B, the one who accepted a fraudulent order the one at risk. The company I have no relationship whatsover. My only risk is to check if I have charges I didn't make.

Re: For your security, please email your credit card and driver’s license

#29
post #14
post #5

So say a restaurant wants me to give them my card details to make a reservation but I'm in a crowded place (like on a train). I offer to email the details and they accept. I know it's bad but I would rather email my details then say it loudly over the phone and have everyone hear it. Now did they break PCI? Or not because I was the one who offered to send my details. How does one send their credit card details secure…

Call them before you get onto crowded trains.

The crowded train was an example (but a real life one). It's also demonstrating that they called me (and so I'm unable to pick the place).

Re: For your security, please email your credit card and driver’s license

#30
post #16
post #5

So say a restaurant wants me to give them my card details to make a reservation but I'm in a crowded place (like on a train). I offer to email the details and they accept. I know it's bad but I would rather email my details then say it loudly over the phone and have everyone hear it. Now did they break PCI? Or not because I was the one who offered to send my details. How does one send their credit card details secure…

The credit card is designed for the use case of reading it out over the phone. Part of the reason they aren't free is that credit card usage includes insurance fees against fraud and such. By design, the credit card is designed to be used in an only "mostly secure" manner. This goes back to the fact that security is not about building impenetrable walls around the thing being secured, and if there's the slightest bre…

If it can be read over the phone, or written on the outside of mail order catalogs. Why is it not ok to send it via email?

Reading it over the phone people around you can hear it, and say you have children who then go on to use it, are you going to call that fraud (and potentially have something brought against your children)?

Post reply on HN