Live data from Hacker News

The Passport Payment (2000)

web.archive.org

31–40 of 55 posts

Re: The Passport Payment (2000)

#32
post #17

I'm confused, how did he pay for someone else's domain? Was there no authentication?

Back then, control was authenticated as necessary for the proper functioning, but even today I see no reason why renewal should have to be gated behind login walls. Actually, I'd even prefer it not to be, because you might, in a pinch, be prevented from paying for them yourself electronically, having to call in a favor and promise to pay back as soon as you see that friend. Or you just prefer to pay someone cash for…

> even today I see no reason why renewal should have to be gated behind login walls.

This actually reminds me on a somewhat interesting social engineering "vulnerability" a little while back[0].

1. The hacker would call into Amazon and say that the website was acting up and they needed to add a card to the victim's account. It wouldn't take much effort because why would it?

2. The hacker'd call right back and say that "their" email had been compromised and they needed to change it/add a new one and reset the password. You supply the card you just gave (and name/billing address, but those aren't too hard to find)

3. Use that to hop on to the account and grab the last 4 digits of the victim's real card.

You now have the victim's billing address and last 4 of a credit card. A surprising amount of authentication power.

I think the lesson here is if it can be privileged information, it is. Even if it's privileged for someone else.

[0]: https://www.wired.com/2012/08/apple-amazon-mat-honan-hacking...

Re: The Passport Payment (2000)

#34
post #17

Earlier quoted context omitted.

Back then, control was authenticated as necessary for the proper functioning, but even today I see no reason why renewal should have to be gated behind login walls. Actually, I'd even prefer it not to be, because you might, in a pinch, be prevented from paying for them yourself electronically, having to call in a favor and promise to pay back as soon as you see that friend. Or you just prefer to pay someone cash for…

> even today I see no reason why renewal should have to be gated behind login walls. This actually reminds me on a somewhat interesting social engineering "vulnerability" a little while back[0]. 1. The hacker would call into Amazon and say that the website was acting up and they needed to add a card to the victim's account. It wouldn't take much effort because why would it? 2. The hacker'd call right back and say tha…

Ok, yeah, I see. Though, in that case, it's both a failure on his side, as well as an utter failure on apple's side.

Also, arguably, a plus for Google's stance on this: no answers to questions, no access. Sue us.

Re: The Passport Payment (2000)

#35
post #17

Earlier quoted context omitted.

Back then, control was authenticated as necessary for the proper functioning, but even today I see no reason why renewal should have to be gated behind login walls. Actually, I'd even prefer it not to be, because you might, in a pinch, be prevented from paying for them yourself electronically, having to call in a favor and promise to pay back as soon as you see that friend. Or you just prefer to pay someone cash for…

> even today I see no reason why renewal should have to be gated behind login walls. This actually reminds me on a somewhat interesting social engineering "vulnerability" a little while back[0]. 1. The hacker would call into Amazon and say that the website was acting up and they needed to add a card to the victim's account. It wouldn't take much effort because why would it? 2. The hacker'd call right back and say tha…

That's a useless hack at the time. You could generate your own credit card numbers back then using a formula. The name/expiry date or address were not used for verification.

So ordering from a fake credit card was easy. Finding the drop shipping location was the hard part.

Re: The Passport Payment (2000)

#36
post #22
post #16

perhaps the most surprising to me is the apparent willingness to enter credit card info online in 1999. I wasn't around for this period but wasn't the conventional wisdom back then that this was insecure? hence PayPal?

Well we had https ("check for the lock icon") back then, you could pay for plenty of things with credit cards online. Of course there was some fear of it among the general public. PayPal by no means invented online payments they just popularised it.

>PayPal by no means invented online payments they just popularised it.

I'm not sure it's even so much that PayPal "popularized" online payments as it somewhat democratized them. When I had a small side software business in the early to mid-90s, it wasn't easy/cheap to get setup with a merchant credit card. Mostly, people mailed me checks although at some point I struck a deal with a local BBS operator/reseller for him to take payments for me when necessary.

Re: The Passport Payment (2000)

#37
post #17

I'm confused, how did he pay for someone else's domain? Was there no authentication?

Back then, control was authenticated as necessary for the proper functioning, but even today I see no reason why renewal should have to be gated behind login walls. Actually, I'd even prefer it not to be, because you might, in a pinch, be prevented from paying for them yourself electronically, having to call in a favor and promise to pay back as soon as you see that friend. Or you just prefer to pay someone cash for…

In the UK, student loan payments can be made online without authentication: if you know the right details, it just works. Which was convenient for me, because I have never managed to log into my account.

Re: The Passport Payment (2000)

#38
post #35

Earlier quoted context omitted.

> even today I see no reason why renewal should have to be gated behind login walls. This actually reminds me on a somewhat interesting social engineering "vulnerability" a little while back[0]. 1. The hacker would call into Amazon and say that the website was acting up and they needed to add a card to the victim's account. It wouldn't take much effort because why would it? 2. The hacker'd call right back and say tha…

That's a useless hack at the time. You could generate your own credit card numbers back then using a formula. The name/expiry date or address were not used for verification. So ordering from a fake credit card was easy. Finding the drop shipping location was the hard part.

Your fake credit card isn't going to have a balance.

Re: The Passport Payment (2000)

#39

Try to go passport.com nowadays. It redirects you to Bing and search "passport" as result. Handy.

I had an issue with my router which now uses myfiosgateway.com as the router config though it is hosted on the router (presumably so it can serve https?) And mark monitor showed up with a big "this is the actual internet so you don't wanna visit it" page when I was routed to the actual .com, kinda similar

Re: The Passport Payment (2000)

#40
post #25
post #17

Earlier quoted context omitted.

Back then, control was authenticated as necessary for the proper functioning, but even today I see no reason why renewal should have to be gated behind login walls. Actually, I'd even prefer it not to be, because you might, in a pinch, be prevented from paying for them yourself electronically, having to call in a favor and promise to pay back as soon as you see that friend. Or you just prefer to pay someone cash for…

yup, i use gandi for that reason. they support payment from anyone. it's especially convenient for volunteer community sites. we don't depend on the person who registered the domain and forgot to give access to others.

Very good to know. I use Gandi too, didn't realize I could do that.
Post reply on HN