Live data from Hacker News

For your security, please email your credit card and driver’s license

troyhunt.com

51–60 of 70 posts

Re: For your security, please email your credit card and driver’s license

#51
post #37
post #33

Earlier quoted context omitted.

I face that all the time as a user of NoScript+Ghostery+Adblock. I have to go through a process of whitelisting trial and error with new websites I come across everyday. I wish there were a whitelist I could subscribe to that would only enable only those domains that are critical to loading content & comments for websites I visit.

Run Disconnect instead of Ghostery. Ghostery had a big fad following a while ago, but it's not actually good for you. Disconnect is much better. (and stop running NoScript (nobody is designing sites to work for you), just run with Click to Plugin enabled, Disconnect, and ABP) I've seen a lot of these "I can't see the article until I disable my 40 extensions" complaints recently, but they all work fine with my combina…

Thanks. I will try Disconnect. [Edited: I'm curious to know why you say Ghostery isn't good for users, and why Disconnect is better?]

To clarify, I wasn't complaining specifically about this article but in general while browsing the web.

Click to Plugin seems to be a Safari plugin, while I am a Firefox/Chrome user. As for ditching NotScript altogether, I'm not sure I'm ready for that yet, especially when I see sites that seem to be loading scripts from an dozen or two domains in addition to their own!

My paranoia comes with a (discomfort) cost attached, I know.

Re: For your security, please email your credit card and driver’s license

#52
post #37

Earlier quoted context omitted.

Run Disconnect instead of Ghostery. Ghostery had a big fad following a while ago, but it's not actually good for you. Disconnect is much better. (and stop running NoScript (nobody is designing sites to work for you), just run with Click to Plugin enabled, Disconnect, and ABP) I've seen a lot of these "I can't see the article until I disable my 40 extensions" complaints recently, but they all work fine with my combina…

Oddly, I can see it just fine with JavaScript disabled. I do not use NoScript (I use Opera 12 and whitelist sites to allow JS or not via per site settings[1]). I also have Disqus added to my hosts file (but disabling JS will have the same effect). I would guess perhaps NoScript decides to partially allow some scripts and not others, making for chaos? That just seems like a mess waiting to happen that no developer can…

> I use Opera 12 and whitelist sites to allow JS or not via per site settings

May I ask how to arrive at what 3rd party domains need to be whitelisted for a site to load properly?

Re: For your security, please email your credit card and driver’s license

#53
post #40

Earlier quoted context omitted.

Having recently changed my password with PayPal, I somehow doubt they are serious about security. They enforce a maximum length limit, disallow spaces and other "non-printable" characters (!), etc.

The amount of sites that disallow "special characters" is annoying me, esp when they "encourage" tough passwords... it would also be nice, before sending me a password reminder, if you reminded me of your rules of your password policy - that is often enough to trigger me to remember my password!

correct horse battery staple

Re: For your security, please email your credit card and driver’s license

#54
I've had this type of request for certain online things before. I've always assumed it was for the company's security, not mine. While it might be unreasonable for a purchase, if you want secure shell or something on a hosted server, I can see where verifying you are who you say you are would be valuable. I certainly wouldn't hand out shells to random people on my own servers.

Of course, you might use a different method than email to deliver the required documents a little more securely.

Re: For your security, please email your credit card and driver’s license

#55
post #37
post #33

Earlier quoted context omitted.

I face that all the time as a user of NoScript+Ghostery+Adblock. I have to go through a process of whitelisting trial and error with new websites I come across everyday. I wish there were a whitelist I could subscribe to that would only enable only those domains that are critical to loading content & comments for websites I visit.

Run Disconnect instead of Ghostery. Ghostery had a big fad following a while ago, but it's not actually good for you. Disconnect is much better. (and stop running NoScript (nobody is designing sites to work for you), just run with Click to Plugin enabled, Disconnect, and ABP) I've seen a lot of these "I can't see the article until I disable my 40 extensions" complaints recently, but they all work fine with my combina…

but it's not actually good for you

[citation needed]

Re: For your security, please email your credit card and driver’s license

#56
post #51
post #37

Earlier quoted context omitted.

Run Disconnect instead of Ghostery. Ghostery had a big fad following a while ago, but it's not actually good for you. Disconnect is much better. (and stop running NoScript (nobody is designing sites to work for you), just run with Click to Plugin enabled, Disconnect, and ABP) I've seen a lot of these "I can't see the article until I disable my 40 extensions" complaints recently, but they all work fine with my combina…

Thanks. I will try Disconnect. [Edited: I'm curious to know why you say Ghostery isn't good for users, and why Disconnect is better?] To clarify, I wasn't complaining specifically about this article but in general while browsing the web. Click to Plugin seems to be a Safari plugin, while I am a Firefox/Chrome user. As for ditching NotScript altogether, I'm not sure I'm ready for that yet, especially when I see sites…

Ghostery might not be as bad as the headlines suggest, but their tracking seems to be opt-out rather than opt-in:

https://news.ycombinator.com/item?id=5897682

http://lifehacker.com/ad-blocking-extension-ghostery-actuall...

http://venturebeat.com/2012/07/31/ghostery-a-web-tracking-bl...

A few months ago, Disconnect's founder (byoogle) spoke about why Disconnect is better:

https://news.ycombinator.com/item?id=5898165

Disclaimer: I used Ghostery for a long time and liked it, but now use Disconnect.

Re: For your security, please email your credit card and driver’s license

#57
Paypal asked me for the same data 6 years ago to unblock my account. (I was not a merchant, just doing a purchase on my card)

I told them to fuck off but haven't been able to open a new account since they manage to keep linking such to my old blocked one. They pretend it's for my security as well to protect against fraudulent acts.

It's none of your business. In Denmark the bank will protect us against fraudulent acts.

Once again, Fuck off.

Re: For your security, please email your credit card and driver’s license

#58
post #51

Earlier quoted context omitted.

Thanks. I will try Disconnect. [Edited: I'm curious to know why you say Ghostery isn't good for users, and why Disconnect is better?] To clarify, I wasn't complaining specifically about this article but in general while browsing the web. Click to Plugin seems to be a Safari plugin, while I am a Firefox/Chrome user. As for ditching NotScript altogether, I'm not sure I'm ready for that yet, especially when I see sites…

Ghostery might not be as bad as the headlines suggest, but their tracking seems to be opt-out rather than opt-in: https://news.ycombinator.com/item?id=5897682 http://lifehacker.com/ad-blocking-extension-ghostery-actuall... http://venturebeat.com/2012/07/31/ghostery-a-web-tracking-bl... A few months ago, Disconnect's founder (byoogle) spoke about why Disconnect is better: https://news.ycombinator.com/item?id=5898165 D…

Ghostery's anonymized data sharing is opt-in.

Source: current, updated Ghostery user.

Re: For your security, please email your credit card and driver’s license

#59
post #2

"Fines will be levied in all cases where merchants are the subject of a security breach and upon investigation are found to be non-compliant. The average fines levied for a small merchant total around £15,000 which is payable on top of any forensic investigation and remediation costs." This is mitigated quite a bit by the extreme difficulty to report PCI-DSS violation before they lead to outright fraud.

I believe there is a PCI requirement that a company's system must be evaluated once every three months by a PCI approved vendor to ensure that data is being kept secure. To me, it seems kind of contradictory because if a company is being approved by said vendors, then how could they be found non-compliant in a breach? Maybe the quarterly vendor assessment isn't mandatory. digs through documents EDIT: This quarterly s…

Nor a properly documented procedure seems to exist for random people (me) to report blatant PCI-DSS violation they stumbled upon.

PCI-DSS is barely better than security theater, with so litte effort spent on finding violations...

Re: For your security, please email your credit card and driver’s license

#60

Earlier quoted context omitted.

Oddly, I can see it just fine with JavaScript disabled. I do not use NoScript (I use Opera 12 and whitelist sites to allow JS or not via per site settings[1]). I also have Disqus added to my hosts file (but disabling JS will have the same effect). I would guess perhaps NoScript decides to partially allow some scripts and not others, making for chaos? That just seems like a mess waiting to happen that no developer can…

I only use Noscript, and I can view the content. I primarily use NoScript because it does a really good job of blocking modern popups.

I use NoScript because essentially every browser exploit in the last decade has had javascript as a necessary component. Running the minimum amount of javascript protects against even zero-day attacks.

I say web developers who put their convenience ahead of my security are bastards.

Post reply on HN