8 ms·
For your security, please email your credit card and driver’s license
- sharjeel 13y agoLooks like this thread is still alive: http://serverfault.com/questions/293217/our-security-auditor-is-an-idiot-how-do-i-give-him-the-information-he-wants http://serverfault.com/questions/293217/our-security-auditor...
- brohee 13y ago"Fines will be levied in all cases where merchants are the subject of a security breach and upon investigation are found to be non-compliant. The average fines levied for a small merchant total around £15,000 which is payable on top of any forensic investigation and remediation costs." This is mitigated quite a bit by the extreme difficulty to report PCI-DSS violation before they lead to outright fraud.
- JimmaDaRustla 13y agoI believe there is a PCI requirement that a company's system must be evaluated once every three months by a PCI approved vendor to ensure that data is being kept secure. To me, it seems kind of contradictory because if a company is being approved by said vendors, then how could they be found non-compliant in a breach? Maybe the quarterly vendor assessment isn't mandatory. digs through documents EDIT: This quarterly scan by an ASV and only evaluates the network in regards to external IP addresses, so it does not check anything regarding how the data is stored/transferred.
- lotsofcows 13y agoMy PCIDSS provider runs nessus once a quarter. It's found a few bugs but it's not an evaluation of anything other than my web facing server.
- brohee 13y agoNor a properly documented procedure seems to exist for random people (me) to report blatant PCI-DSS violation they stumbled upon. PCI-DSS is barely better than security theater, with so litte effort spent on finding violations...
- Terretta 13y agoWhat is with content that can't be seen unless you enable social media plugins? In this case, I'm not sure its intentional (looks related to how Disqus is embedded), but this is one of several such cases in the last couple weeks.
- maggit 13y agoDisabling JavaScript lets me read the site without enabling the social stuff. I noticed that the content seems to be there, but then gets removed, presumably by JavaScript. (Ghostery+Chrome here)
- HeXetic 13y agoI see everything OK with NoScript enabled and blocking everything except google.com, googleapis.com, and blogger.com.
- leephillips 13y agoI can see it. Does that mean I have some "social media plugin" enabled? I don't even know what that is, but I don't like the sound of it.
- jarrett 13y agoIt means you don't have a social media blocker plugin installed. Ghostery is one example of such a plugin. With Ghostery enabled, the article content on this particular page is invisible. (That's not how it's supposed to work, and I suspect it's due to a mistake on the website's end.)
- sp332 13y agoI have Ghostery and RequestPolicy on, and I can see the content fine.
- deleted 13y ago[deleted]
- patrickg 13y ago"me too", I had to use the URL in another browser to read the story. Ghostery + Adblock + Chrome
- dalore 13y agoSo say a restaurant wants me to give them my card details to make a reservation but I'm in a crowded place (like on a train). I offer to email the details and they accept. I know it's bad but I would rather email my details then say it loudly over the phone and have everyone hear it. Now did they break PCI? Or not because I was the one who offered to send my details. How does one send their credit card details securely to a brick and mortar store? Via email I know it's insecure but if unauthorized charges do appear I can (and will) contest them and get a new card, so really the bank is taking on risk.
- BillyMaize 13y agoI always go directly to the companies website to give information like this. You can't fall for the dancing bunny if you never ever respond through email.
- nodata 13y agoCall them before you get onto crowded trains.
- dalore 13y agoThe crowded train was an example (but a real life one). It's also demonstrating that they called me (and so I'm unable to pick the place).
- kapkapkap 13y ago
- jedbrown 13y agoCtrip.com, a Chinese travel site, does this for purchases with a non-Chinese card. I spent a lot of time on the phone explaining why requesting that customers email such information was inexcusable. I've encountered similar problems with badges for site visits at some companies and national labs (which have strict guidelines on PII, including numerous "training courses", but poor implementation and admin staff often overlook the requirements).
- nucleardog 13y agoNamecheap did this to me a while back. For some reason I must have appeared fraudulent, although I can't imagine why. They (IIRC) asked for a photo of an ID card with the name of the person on the credit card and a photo of something tying that name to the address provided. Our drivers licenses have our addresses on them. Sent in a photo of a driver's license with all the other information obscured... So it was just the government's identifying marks, the name, address, and photo. The license number, height, weight, barcode, etc were all obscured. In retrospect, a nice big watermark that said "FOR NAMECHEAP ONLY" would have maybe been a good addition. It was sufficient for them. I saw no issues with it as far as a security measure. It wouldn't take much to find my name, picture, or address just digging around online - never mind with access to my email.
- johnmurch 13y agoHostGator pulled this exact crap with me. I said forget it and moved onto a different host for a client. I am just SHOCKED as it was "policy" for them to have a copy of drivers license/passport and a credit card on file!!!!
- kanamekun 13y agoHostgator did the same to me too! I also moved onto a different host. Here's the email they sent me when I asked for more info: Hello, Thank you for your response. We would like to provide you with an explanation of why we request verification. If there are any billing discrepancies, missing information, or if the order is selected randomly for fraud prevention, the account is suspended until the verification is complete and an email is sent to the customer asking them to verify the account that they signed up for. We do not obtain anything for marketing purposes and are simply trying to confirm billing details or halt fraudulent accounts. It is our goal to make verification as easy and painless as possible and appreciate your patience. If you review the Section 1 of our Terms of Service, you will see that we do state that we will continue with the set up of your account after we have received payment and we and/or our payment partner(s) have screened the order(s) in question in case of fraud. Additionally, we do require valid contact information and may terminate an account if none is given, but we prefer to request this information from you up front. You can review our Terms of Service here: http://www.hostgator.com/tos/tos.php http://www.hostgator.com/tos/tos.php Here is some more information regarding our Privacy Policy: http://www.hostgator.com/privacy.shtml http://www.hostgator.com/privacy.shtml We apologize for any inconveniences that may result from this process. This extra verification is done for your security and to ensure that orders are not duplicitous. The web hosting industry, unfortunately, has a high rate of fraudulent orders, and this sort of verification helps us drastically reduce fraud and ensure our customers remain secure. If you are unable to verify your account with us or do not wish to proceed with the activation of your account, then no further action needs to be taken on your part. We have only authorized the charges and have never fully received the payment. We do not fully receive the payments until an account has been activated. Since we were unable to verify your account we will not proceed with activating the account. The initial payment made to us will be reversed with in 48 hours. If you paid with PayPal, the purchase will be refunded automatically at this time. Though, if you paid with a credit card, the authorization reversal will post to your account typically 5-7 business days after that. Depending on the establishment you bank with would determine on how fast you receive the funds. Once we release the payments your bank holds the funds until they are able to fully process the transaction and show the amount that you paid in your account. If you have any questions, comments, or concerns, please do not hesitate to contact us. Best regards, [Name redacted] Senior Verifications and Fraud Prevention Agent
- kamjam 13y agoIt's scary that this kind of thing ever comes up, you would think this kind of thing is blindingly obvious. Having said said, I seem to recall even Paypal asking me to send them copies of the my passport/ID and various other info when there was an issue on my account. I can't recall whether it was by email or uploaded through their site though... Question: Before writing these articles* does Troy Hunt go through a responsible disclosure with the businesses in question, much like you would if you found a security flaw in Microsoft/Facebook/Google/etc? * (not this one so much, but some of the other articles he has written - eg. http://www.troyhunt.com/2013/09/web-security-dark-matter-developers-and.html http://www.troyhunt.com/2013/09/web-security-dark-matter-dev...)
- danielbarla 13y agoHaving recently changed my password with PayPal, I somehow doubt they are serious about security. They enforce a maximum length limit, disallow spaces and other "non-printable" characters (!), etc.
- kamjam 13y agoThe amount of sites that disallow "special characters" is annoying me, esp when they "encourage" tough passwords... it would also be nice, before sending me a password reminder, if you reminded me of your rules of your password policy - that is often enough to trigger me to remember my password!
- joeframbach 13y agocorrect horse battery staple
- snake_plissken 13y agoDoesn't Mt Gox require copy of your ID to 'verify' you?
- aroch 13y agoIt's to verify that you're a real person --the same real person as attached to the bank account -- and that you're in the US (or whatever country). There are tax and liability considerations when you're moving money
- yebyen 13y agoNot to mention "Know Your Customer" and Anti-Money Laundering laws for money service businesses. Given that you can't really get "money" out of Mt.Gox at this point in time (only bitcoins), it seems like mostly a formality at this point so that next time the feds come to seize all of Mt.Gox's holdings, they can show that they've been crossing all of the t's and dotting all of the lower-case j's ever since the last time they unwillingly paid $5mil to the government.
- sveit 13y agoIf I saw this in my inbox, I would think it is a phishing attack. By sending a legitimate email like this, Big W is making it much easier for their customers to succumb to phishing.
- ChuckMcM 13y agoThis is what happens when you do s/fax/email/g on all of your processes.
- qdog 13y agoI've had this type of request for certain online things before. I've always assumed it was for the company's security, not mine. While it might be unreasonable for a purchase, if you want secure shell or something on a hosted server, I can see where verifying you are who you say you are would be valuable. I certainly wouldn't hand out shells to random people on my own servers. Of course, you might use a different method than email to deliver the required documents a little more securely.
- jzs 13y agoPaypal asked me for the same data 6 years ago to unblock my account. (I was not a merchant, just doing a purchase on my card) I told them to fuck off but haven't been able to open a new account since they manage to keep linking such to my old blocked one. They pretend it's for my security as well to protect against fraudulent acts. It's none of your business. In Denmark the bank will protect us against fraudulent acts. Once again, Fuck off.
- superuser2 13y agoRelated story: After updating to iOS 7, Google Authenticator lost my AWS 2-factor token. The reset process requires me to hand over my drivers license, proof of address, and a notarized affidavit confirming my identity. As cleartext email attachments. So anyone who gets into my GMail Sent Items folder has enough to take out loans in my name, get into all my hosting accounts, etc. I requested a GPG public key but the rep didn't have one and wouldn't create one. Wouldn't even let me send an encrypted archive and share the password over the phone. It had to be email attachments or a link. I went with Dropbox so I can at least shut off the link later, but anyone in a position to observe that email could have already downloaded my identity documents. I appreciate Amazon's resistance to social engineering there, but refusal to use email encryption in the single most sensitive kind of email I will probably ever send is just awful. Companies that require cleartext transmission of proof of identity need to be held responsible for the identity theft that inevitably occurs as a result.
- Amadou 13y agoI'm surprised the article missed the single biggest problem with requesting copies of "identity documents" - the company you send them to has no way to verify them! In his example they wanted copies of utility bills and a driver's license either domestic or foreign. Clearly they have no way of verifying the authenticity of foreign driver's licenses from arbitrary countries. At the very best they might have a book that shows samples of valid licenses, but no way can they verify the data on the license. And if they could do it that would be a pretty serious breach of privacy. The government agency that issues licenses has no business telling arbitrary people if so and so lives at a certain address - back in 1989 the actress Rebecca Schaeffer was shot point-blank at her front door by a stalker who looked up her address at the local dept of motor vehicles precipitating a major change in privacy of license records. Basically any of these documents can be photo-shopped or even made up completely from scratch and the company requiring them would not be any wiser. So, these policies don't improve security for anyone - legitimate customers become less secure and the company is just as susceptible to fraud.
- true_religion 13y ago> I'm surprised the article missed the single biggest problem with requesting copies of "identity documents" - the company you send them to has no way to verify them! I'm not so sure about that. Bars have machines to scan your drivers licence and verify if its real, so why can't other companies do the same thing. As for arbitry licences...they could either not work for the US, or demand passports which can be verified against someone.
- Amadou 13y agoI'm not so sure about that. Bars have machines to scan your drivers licence and verify if its real, so why can't other companies do the same thing. No, those machines don't work that way. They just check for integrity in the physical license itself hologram in the right place, etc -- something you can't do with a scanned copy of a license. They don't have a master database that they phone home and check in with to see if the data on the card is forged. Actually, they do have a database - of the info they read off the cards. The bars use that info for two things: (1) if you are enough of a troublemaker, they put you on the list to reject next time. (2) they also sell all of their card scan info to the data brokers. That's right, places like Equifax, TRW, etc know the time and date of every time you went to a bar that scanned your ID.
- thaumaturgy 13y agoI had to go through a similar process when ordering a machine from an outfit called "Mac of All Trades" (http://www.macofalltrades.com/ http://www.macofalltrades.com/) recently (on behalf of a client). They requested my driver's license and the front and back of my business credit card. I went back and forth with their customer support over this. I pointed out how easy it was to use free software to fake the "credentials" they were asking for; I pointed out that the business email address they used to contact me + the business phone number they used to contact me + the business website that listed both + web.archive.org were at least as useful for verification of identity; I pointed out that we order piles of stuff from tons of different vendors and they were one of only two that requested this. They stonewalled and I eventually acquiesced. (They were the only non-eBay source for a machine that this client wanted at anything resembling a decent price.) I pointed them to SiftScience and Bruce Schneier's article on security theater. In the end it didn't seem to do any good. I was friendly with them about it at the time but have gotten grumpier about it since. I think I'll send them a link to this article and this thread.