Live data from Hacker News

For your security, please email your credit card and driver’s license

troyhunt.com

41–50 of 70 posts

Re: For your security, please email your credit card and driver’s license

#41
post #35

HostGator pulled this exact crap with me. I said forget it and moved onto a different host for a client. I am just SHOCKED as it was "policy" for them to have a copy of drivers license/passport and a credit card on file!!!!

Hetzner required passport and some other stuff. I caved.

They don't for customers with a German bank account.

Re: For your security, please email your credit card and driver’s license

#42
post #35

HostGator pulled this exact crap with me. I said forget it and moved onto a different host for a client. I am just SHOCKED as it was "policy" for them to have a copy of drivers license/passport and a credit card on file!!!!

Hetzner required passport and some other stuff. I caved.

Nost hosting companies require a drivers license or similar, very few don't anymore.

Softlayer and Hetzner are the two that I remember needing this, both seemed fine with my expired one I scanned ages (2008 or something) ago - I couldn't be bothered scanning my new one.

But really, it might stop some people but it's easy enough to fake it if you really wanted to do something bad.

Re: For your security, please email your credit card and driver’s license

#43
post #28

Earlier quoted context omitted.

> I can (and will) contest them and get a new card, so really the bank is taking on risk. No, they company you are purchasing from is taking the risk (hence why they are asking for the additional info). The company that you purchase from is almost always the one who covers the loss in cases of a chargeback caused by CC fraud, not the bank/CC company.

I'm confused. If I give my card to company A, but somehow along the line someone gets the details and uses it buy something at company B. And there was no way to link it to company A. How is company A having any risk whatsover? I believe it's company B, the one who accepted a fraudulent order the one at risk. The company I have no relationship whatsover. My only risk is to check if I have charges I didn't make.

company A to you is company B to someone else. The point is that the risk is not to the bank but to merchants.

For any given transaction the company does not know if they're "company A" and you're a genuine customer, or if they're "company B" being defrauded out of product with stolen details, so all merchants are taking on risk.

Re: For your security, please email your credit card and driver’s license

#44
post #37
post #33

Earlier quoted context omitted.

I face that all the time as a user of NoScript+Ghostery+Adblock. I have to go through a process of whitelisting trial and error with new websites I come across everyday. I wish there were a whitelist I could subscribe to that would only enable only those domains that are critical to loading content & comments for websites I visit.

Run Disconnect instead of Ghostery. Ghostery had a big fad following a while ago, but it's not actually good for you. Disconnect is much better. (and stop running NoScript (nobody is designing sites to work for you), just run with Click to Plugin enabled, Disconnect, and ABP) I've seen a lot of these "I can't see the article until I disable my 40 extensions" complaints recently, but they all work fine with my combina…

Oddly, I can see it just fine with JavaScript disabled. I do not use NoScript (I use Opera 12 and whitelist sites to allow JS or not via per site settings[1]). I also have Disqus added to my hosts file (but disabling JS will have the same effect). I would guess perhaps NoScript decides to partially allow some scripts and not others, making for chaos? That just seems like a mess waiting to happen that no developer can 100% predict. No JS or all JS is much easier, but half blocking is not so much when there's dependencies.

However, I realize when sites fail (re-enable JS) and adjust accordingly as anyone that does such things should if they're blocking content (though I'm used to adjusting since I've been using a browser with a minority user base for years). Alternatively, view it via Google cache search (and add strip=1 to the end to remove all images and JS) and run it through readability. While I would prefer all sites to not assume, that's not going to happen and comes down to if I care enough to work around to see the site content or just move along and deem it not worth it.

[1] http://help.opera.com/Windows/12.10/en/sitepreferences.html

Re: For your security, please email your credit card and driver’s license

#45
post #30

Earlier quoted context omitted.

If it can be read over the phone, or written on the outside of mail order catalogs. Why is it not ok to send it via email? Reading it over the phone people around you can hear it, and say you have children who then go on to use it, are you going to call that fraud (and potentially have something brought against your children)?

Because the physical distance your voice can be heard is a much, much smaller pool of people, and it is safe to assume that it generally excludes credit card fraudsters. edit to add : This is also why it is suggested that you wait until you are off the subway to make a purchase over the phone, for example. Who knows who's listening. Email is available world-wide. Email is not generally secure, and the message is not…

"It is not very difficult for a determined attacker to harvest your email and scan it for common structured data like credit card details."

In particular, let me highlight that scan part. The attacker in question is probably not attacking you personally... the hacker is simply spreading a dragnet as wide as possible and running a simple RE over the whole thing. The odds that a hacker is attacking "your" email is low, the odds that your email is part of some dragnet somewhere is non-trivial, in a world of bot nets and rampant compromises.

Re: For your security, please email your credit card and driver’s license

#46
post #33
post #4

What is with content that can't be seen unless you enable social media plugins? In this case, I'm not sure its intentional (looks related to how Disqus is embedded), but this is one of several such cases in the last couple weeks.

I face that all the time as a user of NoScript+Ghostery+Adblock. I have to go through a process of whitelisting trial and error with new websites I come across everyday. I wish there were a whitelist I could subscribe to that would only enable only those domains that are critical to loading content & comments for websites I visit.

I can see that article fine with Ghostery + Adblock. I wonder what URL is causing the problem?

Re: For your security, please email your credit card and driver’s license

#47
post #4

What is with content that can't be seen unless you enable social media plugins? In this case, I'm not sure its intentional (looks related to how Disqus is embedded), but this is one of several such cases in the last couple weeks.

I can see it. Does that mean I have some "social media plugin" enabled? I don't even know what that is, but I don't like the sound of it.

It means you don't have a social media blocker plugin installed. Ghostery is one example of such a plugin. With Ghostery enabled, the article content on this particular page is invisible. (That's not how it's supposed to work, and I suspect it's due to a mistake on the website's end.)

Re: For your security, please email your credit card and driver’s license

#48
post #37

Earlier quoted context omitted.

Run Disconnect instead of Ghostery. Ghostery had a big fad following a while ago, but it's not actually good for you. Disconnect is much better. (and stop running NoScript (nobody is designing sites to work for you), just run with Click to Plugin enabled, Disconnect, and ABP) I've seen a lot of these "I can't see the article until I disable my 40 extensions" complaints recently, but they all work fine with my combina…

Oddly, I can see it just fine with JavaScript disabled. I do not use NoScript (I use Opera 12 and whitelist sites to allow JS or not via per site settings[1]). I also have Disqus added to my hosts file (but disabling JS will have the same effect). I would guess perhaps NoScript decides to partially allow some scripts and not others, making for chaos? That just seems like a mess waiting to happen that no developer can…

I only use Noscript, and I can view the content.

I primarily use NoScript because it does a really good job of blocking modern popups.

Re: For your security, please email your credit card and driver’s license

#49
post #37
post #33

Earlier quoted context omitted.

I face that all the time as a user of NoScript+Ghostery+Adblock. I have to go through a process of whitelisting trial and error with new websites I come across everyday. I wish there were a whitelist I could subscribe to that would only enable only those domains that are critical to loading content & comments for websites I visit.

Run Disconnect instead of Ghostery. Ghostery had a big fad following a while ago, but it's not actually good for you. Disconnect is much better. (and stop running NoScript (nobody is designing sites to work for you), just run with Click to Plugin enabled, Disconnect, and ABP) I've seen a lot of these "I can't see the article until I disable my 40 extensions" complaints recently, but they all work fine with my combina…

>it's not actually good for you.

Can you elaborate? As in it decreases your privacy because it makes your browser uniquely-identifiable? Or something else...

Re: For your security, please email your credit card and driver’s license

#50
post #5

So say a restaurant wants me to give them my card details to make a reservation but I'm in a crowded place (like on a train). I offer to email the details and they accept. I know it's bad but I would rather email my details then say it loudly over the phone and have everyone hear it. Now did they break PCI? Or not because I was the one who offered to send my details. How does one send their credit card details secure…

Why do people care so much about guarding their personal credit card details?

In the US, at least, there is zero liability to the cardholder for fraudulent purchases made without the cardholder's signature, by law. Reporting fraud is fairly easy, and getting a new card after your details have been stolen is free and takes just a few minutes on the phone. You're without your card for a few days while it works its way through the postal system, but that's why you have multiple credit cards.

Companies need to care about this a great deal because they're potentially liable for a lot in case of problems. But individuals have no real reason to care about the secrecy their own card details. Yet, people are constantly worried about it anyway. Why?

Post reply on HN