Huh, couple years ago Santander in the UK changed their web layout. No big deal, except that my password wouldn't work anymore - I rang them up, and they said "did you have any special characters in your password? If yes, then they have been removed because the new system does not support special characters. Please use the same password as before, but without special characters". 1) This is one of the largest banks i…
Stupid security things
51–60 of 161 posts
Re: Stupid security things
#52Earlier quoted context omitted.
Do you mean your grandmother's dog?
Precisely. That actually was a typo. Amazingly, a typo that has earned me a -3 downvote so far... People seem really freakishly touchy about word choice around here lately. Honestly, that's likely to make me care less about their delicate sensibilities.
Re: Stupid security things
#53Earlier quoted context omitted.
What do they require then? I've never in my entire life used my credit/debit card without typing in the PIN number(except for contactless payments, of course). I'm in the UK. I think they can be used with a signature too? Maybe? I've never heard of anyone actually signing a bill instead of using the pin, and besides, I don't even sign my cards.
I was made to sign my card for the first time ever recently in order to complete an exchange that required a refund and repurchase... Parent comments are talking about online purchases, for which your PIN is not needed.
Now I've done some reading, and it seems my country (in Latin America) is following US standards. It seems US-issued credit cards only require signatures, even when used abroad, and only recently (as far as I can google it) are they slowly starting to switch to either PIN or chip-based cards. Newly issued cards where I live have chips (this is a relatively recent development), which I'm not sure exactly how are supposed to be safer than magnetic strip cards, and also don't require PINs.
Re: Stupid security things
#54Earlier quoted context omitted.
Precisely. That actually was a typo. Amazingly, a typo that has earned me a -3 downvote so far... People seem really freakishly touchy about word choice around here lately. Honestly, that's likely to make me care less about their delicate sensibilities.
I think it's unlikely you're being downvoted for the typo - far more likely for the jokey comment which doesn't really add value to the thread.
Re: Stupid security things
#55The number of webmasters who wanted me to set up ssl to 'secure' their site, while the backend emailed cc info in the clear to the orders dept is larger than I have digits, even the extra adolecent joke ones.
Re: Stupid security things
#56Earlier quoted context omitted.
What do they require then? I've never in my entire life used my credit/debit card without typing in the PIN number(except for contactless payments, of course). I'm in the UK. I think they can be used with a signature too? Maybe? I've never heard of anyone actually signing a bill instead of using the pin, and besides, I don't even sign my cards.
Yes, they require a signature. I'm not saying this is a safe practice, just that I've never seen a store where they asked me for a pin code for major credit cards such as Visa, Amex and (I'm pretty sure, but I don't have one) MasterCard. And I'm talking not only my own country, but also the US and several countries in Europe. When I was in the UK some years ago, they didn't ask me for my pin code when I used my Visa…
Re: Stupid security things
#57This is pretty horrifying. But almost as bad: websites that insist on over-elaborate security measures for trivial stuff. Take a bow, HM Revenue & Customs: > You’ve got a new message from HMRC > Dear Fred > You have a new message from HMRC about Self Assessment. > To view it, sign in to your HMRC online account. For security reasons, we have not included a link with this email. > Why you got this email > You chose to…
Re: Stupid security things
#58@troyhunt: Have you seen the latest leak by Atlassian? I got an email on 4th April, 2017 that reads as follows: Hello, This weekend, our Security Intelligence Team detected an incident affecting HipChat.com that may have resulted in unauthorized access to user account information (including name, email address and hashed password). Atlassian ID is used to manage access to your HipChat.com account and other Atlassian…
Re: Stupid security things
#59> and I know for a fact 90% of the sites I personally sign up to online also follow that same process. This is a totally legit response. After all if something goes wrong they must have followed "best practices". No reasonable person would expect them to do more. And it's true (if you only consider the needs of the business). This is a solid strategy for getting lawsuits dismissed. I've seen it in physical security t…
Apart from the fact that it is totally untrue?
Re: Stupid security things
#60That "What is the name of your grandmother's dog?" security question made me lol @ work. This really makes me want to write a "Stupid security questions generator" website.
Why is that funny or bad? If your grandmother is living and has a single dog, as 'security questions' go that would strike me as being pretty good.