Live data from Hacker News

The Passport Payment (2000)

web.archive.org

41–50 of 55 posts

Re: The Passport Payment (2000)

#41
post #16

perhaps the most surprising to me is the apparent willingness to enter credit card info online in 1999. I wasn't around for this period but wasn't the conventional wisdom back then that this was insecure? hence PayPal?

Average non-technical people used well-known companies, but that included eBay and Amazon. Presumably Network Solutions was trusted by this customer of theirs.

I could be wrong, but I think in 1999 Amazon was still only selling books. Certainly they did not sell the variety of goods they have now.

There were thousands of online shops at the time, selling everything that Amazon sells today, and it was common to purchase from them using CC or PayPal.

Re: The Passport Payment (2000)

#42
post #38
post #35

Earlier quoted context omitted.

That's a useless hack at the time. You could generate your own credit card numbers back then using a formula. The name/expiry date or address were not used for verification. So ordering from a fake credit card was easy. Finding the drop shipping location was the hard part.

Your fake credit card isn't going to have a balance.

It was and still is trivial to get stolen credit card info that do have balances or credit available.

Re: The Passport Payment (2000)

#43
post #19
post #16

perhaps the most surprising to me is the apparent willingness to enter credit card info online in 1999. I wasn't around for this period but wasn't the conventional wisdom back then that this was insecure? hence PayPal?

No, not at all? SSL had been around for 6 years already, credit card transactions were quite common, especially with known, reputable hosts (Network Solutions can be safely be assumed to have qualified at the time)

Unfortunately, not all websites used https or enforced it on pages that should have had it. It was very common to see payment forms submitted over http. That is why browsers evolved to the point where Chrome now won’t submit certain types of html form fields over non-https.

Re: The Passport Payment (2000)

#44
post #19

Earlier quoted context omitted.

No, not at all? SSL had been around for 6 years already, credit card transactions were quite common, especially with known, reputable hosts (Network Solutions can be safely be assumed to have qualified at the time)

Unfortunately, not all websites used https or enforced it on pages that should have had it. It was very common to see payment forms submitted over http. That is why browsers evolved to the point where Chrome now won’t submit certain types of html form fields over non-https.

I'm aware of it - even talked some people out of attempting ecommerce without SSL about 20 years ago (not all successfully).

But the linked article specifically mentions an HTTPS link.

Re: The Passport Payment (2000)

#45
post #20
post #16

perhaps the most surprising to me is the apparent willingness to enter credit card info online in 1999. I wasn't around for this period but wasn't the conventional wisdom back then that this was insecure? hence PayPal?

Back then, I remember Internic let you register a domain and you had 30 days to pay up, because people would commonly put a cheque in the post ("mail a check.")

[deleted]

Re: The Passport Payment (2000)

#46
post #38
post #35

Earlier quoted context omitted.

That's a useless hack at the time. You could generate your own credit card numbers back then using a formula. The name/expiry date or address were not used for verification. So ordering from a fake credit card was easy. Finding the drop shipping location was the hard part.

Your fake credit card isn't going to have a balance.

It didn't matter because in order to check someone had to call and wait an hour so no one did in mail order purchases/shopping networks because you had an address to send the police to.

Re: The Passport Payment (2000)

#47
post #9

Could you imagine doing this today? You'd probably get lawyers making you sign agreements saying your payment of the domain renewal is not a ownership interest in the domain and threatening to take you to court for renewing their domain.

And - of course - the same lawyers would bill MSFT $5,000

Re: The Passport Payment (2000)

#48
post #16

perhaps the most surprising to me is the apparent willingness to enter credit card info online in 1999. I wasn't around for this period but wasn't the conventional wisdom back then that this was insecure? hence PayPal?

Memory's hazy (it might have been a year or two before 1999) but I remember in the UK buying a domain from Network Solutions with a credit card but then I had to fax a signed document to their US office to actually authenticate ownership. This wasn't an automated anti-fraud thing like you might see today, it was just standard procedure for on-line orders (or at least non-US ones).

But, yeah, paying on-line with credit cards was absolutely a thing in 1999.

Re: The Passport Payment (2000)

#49
post #8

Earlier quoted context omitted.

It used to be that nameserver changes with TLDs were measured in days, not minutes. Even today some TLDs continue to operate this way.

What are reasonable timeframe expectations for nameserver changes now?

The .com zone file is updated every few minutes. Caching behaviours will vary significantly. Frequently a significant fraction of traffic can be using new nameservers within minutes, with a long tail of traffic with older information.

Each TLD does their own thing. For example, last time I checked, .ca only seemed to be serving a new zone file every few hours. How long new nameservers take will depend on your luck in terms of where you are in their refresh cycle.

Re: The Passport Payment (2000)

#50
post #16

perhaps the most surprising to me is the apparent willingness to enter credit card info online in 1999. I wasn't around for this period but wasn't the conventional wisdom back then that this was insecure? hence PayPal?

It was fairly common. Paypal was around in 1999 (only just). More remarkably it was common to mail a personal check or money order for things on ebay and for the most part, it worked.
Post reply on HN