Live data from Hacker News

For your security, please email your credit card and driver’s license

troyhunt.com

61–70 of 70 posts

Re: For your security, please email your credit card and driver’s license

#61
Related story: After updating to iOS 7, Google Authenticator lost my AWS 2-factor token. The reset process requires me to hand over my drivers license, proof of address, and a notarized affidavit confirming my identity.

As cleartext email attachments.

So anyone who gets into my GMail Sent Items folder has enough to take out loans in my name, get into all my hosting accounts, etc. I requested a GPG public key but the rep didn't have one and wouldn't create one. Wouldn't even let me send an encrypted archive and share the password over the phone. It had to be email attachments or a link. I went with Dropbox so I can at least shut off the link later, but anyone in a position to observe that email could have already downloaded my identity documents.

I appreciate Amazon's resistance to social engineering there, but refusal to use email encryption in the single most sensitive kind of email I will probably ever send is just awful. Companies that require cleartext transmission of proof of identity need to be held responsible for the identity theft that inevitably occurs as a result.

Re: For your security, please email your credit card and driver’s license

#62
I'm surprised the article missed the single biggest problem with requesting copies of "identity documents" - the company you send them to has no way to verify them!

In his example they wanted copies of utility bills and a driver's license either domestic or foreign. Clearly they have no way of verifying the authenticity of foreign driver's licenses from arbitrary countries. At the very best they might have a book that shows samples of valid licenses, but no way can they verify the data on the license.

And if they could do it that would be a pretty serious breach of privacy. The government agency that issues licenses has no business telling arbitrary people if so and so lives at a certain address - back in 1989 the actress Rebecca Schaeffer was shot point-blank at her front door by a stalker who looked up her address at the local dept of motor vehicles precipitating a major change in privacy of license records.

Basically any of these documents can be photo-shopped or even made up completely from scratch and the company requiring them would not be any wiser.

So, these policies don't improve security for anyone - legitimate customers become less secure and the company is just as susceptible to fraud.

Re: For your security, please email your credit card and driver’s license

#63
post #58

Earlier quoted context omitted.

Ghostery might not be as bad as the headlines suggest, but their tracking seems to be opt-out rather than opt-in: https://news.ycombinator.com/item?id=5897682 http://lifehacker.com/ad-blocking-extension-ghostery-actuall... http://venturebeat.com/2012/07/31/ghostery-a-web-tracking-bl... A few months ago, Disconnect's founder (byoogle) spoke about why Disconnect is better: https://news.ycombinator.com/item?id=5898165 D…

Ghostery's anonymized data sharing is opt-in . Source: current, updated Ghostery user.

Thank you. I appreciate the correction.

Re: For your security, please email your credit card and driver’s license

#64
post #52

Earlier quoted context omitted.

Oddly, I can see it just fine with JavaScript disabled. I do not use NoScript (I use Opera 12 and whitelist sites to allow JS or not via per site settings[1]). I also have Disqus added to my hosts file (but disabling JS will have the same effect). I would guess perhaps NoScript decides to partially allow some scripts and not others, making for chaos? That just seems like a mess waiting to happen that no developer can…

> I use Opera 12 and whitelist sites to allow JS or not via per site settings May I ask how to arrive at what 3rd party domains need to be whitelisted for a site to load properly?

I block everything or not (if I site has that much stuff, I probably don't want anything loading from it since it's not just third parties that could be problematic as the site probably performs like crap with local stuff too). If I don't trust a certain third party, I just add it to my hosts file as it's probably common on a lot of sites.

Finding them involves using Opera Dragonfly, Firebug in Firefox or Live HTTP headers a Firefox Addon (or whatever similar in your browser of choice). Granted that's not easy for everyone to do, but I think most on HN could do that if they wished. Though that's what works for me and I'm just sharing in response to your request :)

Re: For your security, please email your credit card and driver’s license

#65
post #23

Doesn't Mt Gox require copy of your ID to 'verify' you?

It's to verify that you're a real person --the same real person as attached to the bank account -- and that you're in the US (or whatever country). There are tax and liability considerations when you're moving money

Not to mention "Know Your Customer" and Anti-Money Laundering laws for money service businesses. Given that you can't really get "money" out of Mt.Gox at this point in time (only bitcoins), it seems like mostly a formality at this point so that next time the feds come to seize all of Mt.Gox's holdings, they can show that they've been crossing all of the t's and dotting all of the lower-case j's ever since the last time they unwillingly paid $5mil to the government.

Re: For your security, please email your credit card and driver’s license

#66
post #51

Earlier quoted context omitted.

Thanks. I will try Disconnect. [Edited: I'm curious to know why you say Ghostery isn't good for users, and why Disconnect is better?] To clarify, I wasn't complaining specifically about this article but in general while browsing the web. Click to Plugin seems to be a Safari plugin, while I am a Firefox/Chrome user. As for ditching NotScript altogether, I'm not sure I'm ready for that yet, especially when I see sites…

Ghostery might not be as bad as the headlines suggest, but their tracking seems to be opt-out rather than opt-in: https://news.ycombinator.com/item?id=5897682 http://lifehacker.com/ad-blocking-extension-ghostery-actuall... http://venturebeat.com/2012/07/31/ghostery-a-web-tracking-bl... A few months ago, Disconnect's founder (byoogle) spoke about why Disconnect is better: https://news.ycombinator.com/item?id=5898165 D…

[deleted]

Re: For your security, please email your credit card and driver’s license

#67
post #52

Earlier quoted context omitted.

> I use Opera 12 and whitelist sites to allow JS or not via per site settings May I ask how to arrive at what 3rd party domains need to be whitelisted for a site to load properly?

I block everything or not (if I site has that much stuff, I probably don't want anything loading from it since it's not just third parties that could be problematic as the site probably performs like crap with local stuff too). If I don't trust a certain third party, I just add it to my hosts file as it's probably common on a lot of sites. Finding them involves using Opera Dragonfly, Firebug in Firefox or Live HTTP h…

Too late to edit my previous post, but if you would like to see my host file list, I can paste it somewhere. Some of it is from other lists and quite a bit is things I add.

Re: For your security, please email your credit card and driver’s license

#68
post #62

I'm surprised the article missed the single biggest problem with requesting copies of "identity documents" - the company you send them to has no way to verify them! In his example they wanted copies of utility bills and a driver's license either domestic or foreign. Clearly they have no way of verifying the authenticity of foreign driver's licenses from arbitrary countries. At the very best they might have a book tha…

> I'm surprised the article missed the single biggest problem with requesting copies of "identity documents" - the company you send them to has no way to verify them!

I'm not so sure about that. Bars have machines to scan your drivers licence and verify if its real, so why can't other companies do the same thing.

As for arbitry licences...they could either not work for the US, or demand passports which can be verified against someone.

Re: For your security, please email your credit card and driver’s license

#69
post #62

I'm surprised the article missed the single biggest problem with requesting copies of "identity documents" - the company you send them to has no way to verify them! In his example they wanted copies of utility bills and a driver's license either domestic or foreign. Clearly they have no way of verifying the authenticity of foreign driver's licenses from arbitrary countries. At the very best they might have a book tha…

> I'm surprised the article missed the single biggest problem with requesting copies of "identity documents" - the company you send them to has no way to verify them! I'm not so sure about that. Bars have machines to scan your drivers licence and verify if its real, so why can't other companies do the same thing. As for arbitry licences...they could either not work for the US, or demand passports which can be verifie…

I'm not so sure about that. Bars have machines to scan your drivers licence and verify if its real, so why can't other companies do the same thing.

No, those machines don't work that way. They just check for integrity in the physical license itself hologram in the right place, etc -- something you can't do with a scanned copy of a license. They don't have a master database that they phone home and check in with to see if the data on the card is forged.

Actually, they do have a database - of the info they read off the cards. The bars use that info for two things: (1) if you are enough of a troublemaker, they put you on the list to reject next time. (2) they also sell all of their card scan info to the data brokers. That's right, places like Equifax, TRW, etc know the time and date of every time you went to a bar that scanned your ID.

Re: For your security, please email your credit card and driver’s license

#70
I had to go through a similar process when ordering a machine from an outfit called "Mac of All Trades" (http://www.macofalltrades.com/) recently (on behalf of a client). They requested my driver's license and the front and back of my business credit card.

I went back and forth with their customer support over this. I pointed out how easy it was to use free software to fake the "credentials" they were asking for; I pointed out that the business email address they used to contact me + the business phone number they used to contact me + the business website that listed both + web.archive.org were at least as useful for verification of identity; I pointed out that we order piles of stuff from tons of different vendors and they were one of only two that requested this. They stonewalled and I eventually acquiesced. (They were the only non-eBay source for a machine that this client wanted at anything resembling a decent price.)

I pointed them to SiftScience and Bruce Schneier's article on security theater. In the end it didn't seem to do any good. I was friendly with them about it at the time but have gotten grumpier about it since.

I think I'll send them a link to this article and this thread.

Post reply on HN