Why Aren't Credit Card Companies Using A Google Defense Mechanism?
from the interesting-ideas dept
Bennett Haselton has written up an interesting article at Slashdot, highlighting just how easy it is to find large collections of credit card information using Google. The method is pretty straightforward -- and has been written about extensively in the past. What's interesting, though, is that Haselton wonders why the credit card companies haven't done anything about it. Obviously, they can't prevent card info from being leaked or available online -- but they absolutely can continue to scan for such information and issue new cards to those whose info was compromised. Of course, the reason they don't do this is that the "cost" probably seems high, and the cost of not doing anything isn't particularly high. However, Haselton also notes that this is the type of thing that others could easily help fix as well -- and if the credit card companies could build up more of a community, it's likely that volunteers probably would have written scripts that would find these cards and alert the victims years ago, when this issue was first discovered. While it's fun for some people to bash companies that bring together a community of supporters and volunteers, it's not hard to see cases such as this one where having a community who can be a lot more efficient at solving big problems can be a good thing.Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community.
Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis.
While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.
–The Techdirt Team
Reader Comments
Subscribe: RSS
View by: Time | Thread
[ link to this | view in chronology ]
Excuse me, but...
[ link to this | view in chronology ]
finding credit-card numbers..
[ link to this | view in chronology ]
[ link to this | view in chronology ]
Re:
The credit card companies are under no obligation whatsoever to pro-actively take care of the problem themselves.
As long as it is cheaper for them to do nothing (and just eat the loss resulting from the information being out on the web) as annoying that may be for anybody whose cc information is out on the web, it's their right to do nothing. Why would/should the CC be obligated to take care of a problem they had nothing to do with creating? It's not their fault other companies are careless enough to let CC information leak onto the web (TJ Maxx comes to mind...hmmmm coincidence?)
If/when it becomes more costly to do nothing, they will take care of the problem. But they'd have the right to whine it's not fair they have to spend $$ on taking care of a problem they had no part in creating
and btw, the McD analogy is so fundamentally flawed I'm not even going to bother
[ link to this | view in chronology ]
Why don't the credit card companies do anything?
I have a close friend who was a victim of identity theft. The thief/thieves used his personal information to open new credit cards under his name and ring up charges as fast as he could shut the cards down. Because he had reported his cards as stolen and the credit card companies were aware of what was going on, the companies would obligingly take off the charges. But they kept raising his interest rate every time it happened. So on one hand, they were acknowledging that it wasn't his fault, while on the other hand, they were gouging him for it. His credit rating and interest rate got so bad that no store will accept his credit card and he has to use cash for everything.
The worst part? The guy worked for the Attorney General's Identity Theft department at the time. And what he learned there was that there was absolutely nothing he could do about his situation, because the credit card companies do whatever they want.
[ link to this | view in chronology ]
Identification and Authorization
Using an account identifer as an authorization token is just idiotic.
How many of you use your username as your password? Please (virtually) raise your (virtual) hands. We have a FAQ on security basics for you.
In-person transactions in 3-space usually require the actual card. That is, the account number is used for account identification. Meanwhile, something owned (the card itself) together with something characteristic (a signature) is sufficient for authorization.
But for distance transactions, the authorization component is stripped off. That's just stupid.
In a ubiquitiously networked world, a remote transaction should involve the customer communicating with the card issuer and securely authorizing the specific transaction.
There's no reason that this shouldn't be a relatively seamless part of a transaction with a merchant. The merchant, the customer and the several banks involved are all capable of communicating with each other in real time over the network.
Of course, this architecture wouldn't work for telephone or mail-order purchases. But as on-line purchasing increases in importance, those older methods become less important. Thus, it should be possible to place additional burdens on those older styles of remote transaction without burdening most customers and most merchants excessively.
The flat fact is that account identifiers cannot realistically be kept secret. The identifier has to be disclosed to too many parties. Otoh, transaction authorization tokens should be shared with the minimum number of parties. A customer shouldn't be disclosing their transaction authorization token(s) to anyone but their own bank.
[ link to this | view in chronology ]
Credit Cards Australia
comparison web site, Credit world.
[ link to this | view in chronology ]
It's true
[ link to this | view in chronology ]
Safe shopping online with credit cards
Shopping online safely with credit cards is such a serious issue. It really defies logic that they don't do anything about it.
[ link to this | view in chronology ]
Thanks
[ link to this | view in chronology ]
Shopping Online
[ link to this | view in chronology ]