Live data from Hacker News

For your security, please email your credit card and driver’s license

troyhunt.com

11–20 of 70 posts

Re: For your security, please email your credit card and driver’s license

#11
Ctrip.com, a Chinese travel site, does this for purchases with a non-Chinese card. I spent a lot of time on the phone explaining why requesting that customers email such information was inexcusable. I've encountered similar problems with badges for site visits at some companies and national labs (which have strict guidelines on PII, including numerous "training courses", but poor implementation and admin staff often overlook the requirements).

Re: For your security, please email your credit card and driver’s license

#12
post #4

What is with content that can't be seen unless you enable social media plugins? In this case, I'm not sure its intentional (looks related to how Disqus is embedded), but this is one of several such cases in the last couple weeks.

"me too", I had to use the URL in another browser to read the story. Ghostery + Adblock + Chrome

Re: For your security, please email your credit card and driver’s license

#13
post #4

What is with content that can't be seen unless you enable social media plugins? In this case, I'm not sure its intentional (looks related to how Disqus is embedded), but this is one of several such cases in the last couple weeks.

I see it fine with JS disabled in Firefox 23.

Re: For your security, please email your credit card and driver’s license

#14
post #5

So say a restaurant wants me to give them my card details to make a reservation but I'm in a crowded place (like on a train). I offer to email the details and they accept. I know it's bad but I would rather email my details then say it loudly over the phone and have everyone hear it. Now did they break PCI? Or not because I was the one who offered to send my details. How does one send their credit card details secure…

Call them before you get onto crowded trains.

Re: For your security, please email your credit card and driver’s license

#15
post #5

So say a restaurant wants me to give them my card details to make a reservation but I'm in a crowded place (like on a train). I offer to email the details and they accept. I know it's bad but I would rather email my details then say it loudly over the phone and have everyone hear it. Now did they break PCI? Or not because I was the one who offered to send my details. How does one send their credit card details secure…

> I can (and will) contest them and get a new card, so really the bank is taking on risk.

No, they company you are purchasing from is taking the risk (hence why they are asking for the additional info). The company that you purchase from is almost always the one who covers the loss in cases of a chargeback caused by CC fraud, not the bank/CC company.

Re: For your security, please email your credit card and driver’s license

#16
post #5

So say a restaurant wants me to give them my card details to make a reservation but I'm in a crowded place (like on a train). I offer to email the details and they accept. I know it's bad but I would rather email my details then say it loudly over the phone and have everyone hear it. Now did they break PCI? Or not because I was the one who offered to send my details. How does one send their credit card details secure…

The credit card is designed for the use case of reading it out over the phone. Part of the reason they aren't free is that credit card usage includes insurance fees against fraud and such. By design, the credit card is designed to be used in an only "mostly secure" manner.

This goes back to the fact that security is not about building impenetrable walls around the thing being secured, and if there's the slightest breach the security is "failed". It's about raising the costs of penetrating the security above the value of penetration. When computers aren't involved [1], it's "hard enough" to gather enough cards to make fraud worthwhile, and even harder to get away with it. (Not impossible... just "hard enough".)

[1]: One of my favorite personal sayings: "To err is human. To fuck up a million times per second, you need a computer." Fraudulently obtaining ten cards by working as a waiter and stealing them over the course of a day is one thing, stealing 25 million in ten seconds from a computer is quite another.

Re: For your security, please email your credit card and driver’s license

#17
post #4

What is with content that can't be seen unless you enable social media plugins? In this case, I'm not sure its intentional (looks related to how Disqus is embedded), but this is one of several such cases in the last couple weeks.

I have Ghostery on (with all filters up-to-date and enabled), and also didn't see the content.

I had to click the "play once" discus button to get the _content_ (not the discussion) to appear.

Re: For your security, please email your credit card and driver’s license

#19
It's scary that this kind of thing ever comes up, you would think this kind of thing is blindingly obvious. Having said said, I seem to recall even Paypal asking me to send them copies of the my passport/ID and various other info when there was an issue on my account. I can't recall whether it was by email or uploaded through their site though...

Question: Before writing these articles* does Troy Hunt go through a responsible disclosure with the businesses in question, much like you would if you found a security flaw in Microsoft/Facebook/Google/etc?

* (not this one so much, but some of the other articles he has written - eg. http://www.troyhunt.com/2013/09/web-security-dark-matter-dev...)

Post reply on HN