11 ms·
American Express fails miserably at basic security
- someone_here 16y agoUnfortunately, most of today's "security" with regards to credit cards are merely there to deter the easy grabs. Any determined person could easily get anyone's details through a number of means.
- amdev 16y agoSure, but why not grab low hanging fruit?
- mtsmith85 16y agoWhile I don't know enough to refute the main fact, my gut feeling is that while that may be true, any company doing this time of work on the web needs to at least take care of the base amount of security (using HTTPS where applicable, not storing plain text passwords, etc.)
- jeff18 16y agoJust out of curiosity, what is the actual penalty to American Express for saying their page is secure while transmitting credit card numbers in plaintext?
- deleted 16y ago[deleted]
- eli 16y agoIf someone steals my card number, they're the ones on the hook. Edit: mkull is probably right in the vast majority of cases
- mkull 16y agowrong.. if someone steals the card number, the merchant who accepts the fraudulent transaction is on the hook. Not AMEX
- xenophanes 16y agoThat sounds awful. Credit card fraud is mostly paid for by merchants??
- jacquesm 16y agoThe card issuer has two parties they can stick the charge to, one is the merchant, the other their customer. The merchant is the easy way out, they're not going to cancel their connection with the card issuer because that's their bottom line. Sticking the charge to the customer is harder because the customer will cancel. Follow the path of the least resistance: stick it to the merchant. Now if they did the right thing, they'd fix their acceptance rules and a bunch of security issues and eat the remainder of the charges. Fat chance of that happening any day soon.
- btilly 16y agoIn the USA, by law, they are not allowed to stick it to the customer for more than $50. If they ate the charges, they are afraid that a lot of merchants would deliberately ring up fraudulent purchases for the guaranteed profit. Those two facts force them to the current system. And the fact that merchants are not allowed to charge customers different rates for different cards gets rid of incentives for merchants to charge customers for the poor security practice that the credit cards have.
- tptacek 16y agoThere clearly are merchants who do that today. Last time we have a card stolen, we got tons of random bullshit merchandise in the mail (weird cosmetics and such), presumably for the affiliate money.
- InclinedPlane 16y agoAmerican Express also limits password for their online banking functions to less than 8 purely alphanumeric characters (no spaces, no special characters). If this alone wasn't bad enough, this almost certainly means that somewhere deep in the bowels of AmEx's software stack there's an ancient system where the password field is in plain-text.
- bradgessler 16y agoAMEX isn't the only one with arcane password restrictions. Most banks limit the characters to an alphanumeric subset of ASCII with a few characters like _, and -. It makes no sense. If that wasn't bad enough, look at how services like Mint have to interface with these institutions? When will something like OAuth come into play at banks? I'd love to charter a bank on the premise of superior online service.
- gry 16y agoI wonder about this, same for my bank. My theory is alphanumeric plus one, maybe two symbols means there is a lower probability of some sort of SQL injection. Perhaps a greater risk for exposing one account, but lower risk for exposing many. It's the only explanation I can come up with.
- natrius 16y agoIt's a good explanation, but it can only be valid if they store passwords in plain text. No financial institution would do that, right?
- jlangenauer 16y agoI'd dare say that if a financial institution ever had a situation where an attacker could see any part of their database, they'd have far bigger problems to deal with.
- oasisbob 16y agoAhahahahaha! Yeah, right. I can't speak for most financial systems (I only am familiar with one, but it's a big one), but I know plain text passwords happen. Lets call the system IET. IET doesn't encrypt the passwords used for internet banking. To obscure the passwords, they're stored in the DB using EBCDIC. No joke. Sure, in theory, encryption of data at rest doesn't matter if the system is secure; however, with a security posture like this, the data is bound to leak. In this case, I found out about the unencrypted passwords because they were in the files going to the "print & statement" vendor: there is a default letter in the system that says "Hey your password changed to foo99!". Despite suppressing this letter, the data was still transmitted to the vendor: it is simply ignored.
- pkulak 16y agoThat's pretty terrible, but I'd say it's still more secure than most of the ways I transfer my credit card number. Twice I've needed a tow truck, and both times would you like to know how they charged my card? By picking up their radio and reading off all my info to the main office. All I'd need is a scanner to get dozens of valid credit card numbers a day.
- mynameishere 16y agoI once gave my card to a waiter.
- hugh3 16y agoA waiter stealing credit card numbers has a good chance of being caught eventually. I assume the credit card companies do some basic data mining on their stolen card database, and if card numbers start getting stolen shortly after dining at a particular establishment then they'll track this down. I googled "waiter stealing credit card numbers" and here's an example from today's news of some folks who got caught: http://www.wjla.com/news/stories/0510/739156.html http://www.wjla.com/news/stories/0510/739156.html On the other hand if you have a radio scanner and are picking up numbers going over the air from tow truck companies there's no traceable link between you and anything in the database.
- mseebach 16y agoNo, but there'd be a link to tow-truck companies in your area, and perhaps their not-exactly-PCI-compliant handling of credit-card numbers would be exposed.
- spohlenz 16y agoWho says it would be in your area though? You could travel the country and probably find hundreds of instances of this sort of thing happening.
- gbhn 16y ago
- jacquesm 16y agoThat's just an ad for 'homerun'. Find insecurity in competitors service, make loud blog noises, drop payload.
- ice799 16y agowhat's wrong with that? i removed that part from the conclusion to help fix your butthurt.
- jacquesm 16y agoWhat's wrong with it is that it is about as relevant as Microsoft analyzing security problems in OS/X and posting them on their website or Apple evaluating Windows. It's just an attack on a competitor and a veiled ad. As for the butthurt, and this comment: http://news.ycombinator.com/reply?id=1379577 http://news.ycombinator.com/reply?id=1379577 I think you're missing the tone of the conversation around you and it makes you stand out in a negative way.
- recampbell 16y agoReally, just an ad? Amex's lack of security is no less interesting if it's discovered by a competitor. It's a pretty serious mistake by an organization you would expect to be more careful and knowledgeable about these things.
- JoachimSchipper 16y agoTrue, but read the comments. The organization reporting this is little better. ("Encrypted on the client" - which means they would be horribly exposed to man-in-the-middle attacks...)
- deleted 16y ago[deleted]
- codahale 16y agoBy that token, all security advisories are just advertisements for the security researchers' services.
- kaddar 16y ago"This page is secure"? This comment is complementing American Express.
- jrockway 16y agoMaybe. But their fraud detection is pretty good. I've seen some unauthorized charges before, and Amex has called me before I had any idea. I've also had unauthorized charges show up on a Citi card -- their customer support didn't care and refused to help me. I just paid the $60 (for some scam software, apparently) and canceled the card. So Citi may protect their numbers better, but Amex actually helps you when someone gets your number. (I also had a Paypal debit card canceled for authorized charges. Needless to say, I just buy everything with the Amex. Good customer service, good interest rate, cash back.)
- treblig 16y agoI would be inclined to take this more seriously if there wasn't an enormous distorted AMEX logo at the top of the post.
- ice799 16y agoi don't do graphics bro sorry
- edj 16y agoThis sounds scarier than it really is. Why? Because credit card companies focus on identifying fraudulent transactions rather than verifying your id. From Bruce Scheier's blog[1]: "But once you understand that the problem is fraudulent transactions, you quickly realize that authenticating the transaction, not the person, is the way to proceed. "Again, think about credit cards. Store clerks barely verify signatures when people use cards. People can use credit cards to buy things by mail, phone or Internet, where no one verifies the signature or even that you have possession of the card. "Even worse, no credit card company mandates secure storage requirements for credit cards. They don't demand that cardholders secure their wallets in any particular way. Credit card companies simply don't worry about verifying the cardholder or putting requirements on what he does. They concentrate on verifying the transaction." [1]:http://www.schneier.com/essay-153.html http://www.schneier.com/essay-153.html
- dminor 16y agoAnd also they offload most of the risk onto merchants for accepting fraudulent transactions, so merchants have to be extra vigilant.
- tptacek 16y agoStrong disagree. In reality, and especially for small-ish transactions, card companies are terrible at detecting fraud and customers are terrible at noticing it. Criminals can make second-order money off innocuous transactions through affiliate scams. The only reason this isn't a big deal is that it remains incredibly easy for attackers to get CC#'s without capturing packets off the wire.
- tptacek 16y agoIt wouldn't matter at all if the handler was https. If the form is delivered over HTTP, a man in the middle can make it go wherever they want.
- DeusExMachina 16y agoReading the discussion about credit cards number security reminded me of this, that is worse than having some money stolen: http://news.ycombinator.com/item?id=1129797 http://news.ycombinator.com/item?id=1129797
- henrikschroder 16y agoWhy would you even need the entire credit card number to sign up for a service likes this? That's what boggles my mind the most. Amex really only need enough data to identify one of their cardholderes in such a way that noone can sign up for someone else. Name + billing address + four last digits should be enough? Or eight last. Or four last + CVC. Asking for everything that's required for a purchase is beyond dumb. To me, it's like giving out your password while talking to customer representatives, that's also something you don't do.
- ams6110 16y agoThe F-bombs really don't add anything to an otherwise decent write-up. Use some more creative vocabulary.
- ice799 16y agosorry bro i write the way i talk. also: "shit, piss, fuck, cunt, cocksucker, motherfucker, and tits."
- hans 16y agoI canceled Identity Protect service at AMX after it routinely lagged (sometimes months) in notifying me of credit changes to my fico or whatever. It is sad to see people pay $14/month for that service which, best case scenario, notifies you after somebody jacked your card and has long since moved away to a foreign country. Then I canceled my card too! Really identity thievery is an issue b/c of the banks + loan companies. They're perfectly willing to roll accounts with very little scrutiny and I don't understand why there are not class action lawsuits etc. to nail the lender not the jacked identity. Search on the "credit freeze" if you want the real solution.
- dalore 16y agoIn the old mail order days my dad used to write the cc number on the order form, in plain text!
- kadhinn 16y agoEye Opener..it's hard to believe but then you have proved it. Merchants need to take this up with banks.
- c00p3r 16y agoThe issue is as old as the internet itself - do not use your primary card. Open a special one for electronic use only with separate account instead.