4 ms·
Someone asked me to pay a bill using docusign and entering my credit card information into one of those free text boxes They couldn't understand why I refused t
by gloverkcn 9y ago
Someone asked me to pay a bill using docusign and entering my credit card information into one of those free text boxes They couldn't understand why I refused to do it.
- cottsak 9y agoApparently it's as safe as entering credit card details into another online merchants form who is PCI compliant. https://support.docusign.com/en/answers/00004343 https://support.docusign.com/en/answers/00004343
- tyingq 9y agoIt doesn't really spell out, though, how they differentiate CC info and avoid storing it with the rest of the data in the pdf form. There's just some hand wavy language about "Bank-grade Security". I suspect this means they store the CC data, which would be significantly different from how must online merchants operate.
- Drisc0 9y agoAs someone who has worked on a similar product, I would imagine they only store a token given to them by their payment gateway. The actual CC information is held by the PCI compliant payment gateway, while Docusign can use the token to charge a card without storing compromising information.
- tyingq 9y agoWould be good if that were spelled out though. From the outside, you click a link and see a pre-filled PDF, as both the end user and the person that sent the form. There's no obvious magic that it's auto-detecting cc like data and storing it differently than the other fields in the pdf.
- chatmasta 9y agoWith credit cards, you personally do not have much to worry about, since your card issuer holds the ultimate liability for any fraud that occurs. Just be careful to use a credit card (attached to a reversible ledger) and not a debit card (attached to a less-reversible cash account).
- FooBarWidget 9y agoAre you sure? I don't know how credit card companies in the US behave, but here in the Netherlands I called up mastercard to ask them whether I am liable for any fraud that occurs if I do something like this (or send credit card info over email, like so many hotels want). The credit card company tells me, yes I am liable for any fraud that occurs, because email and unecrypted text boxes on websites are known to be insecure, and so it can be argued that it's my own fault if credit card fraud occurs.
- cottsak 9y agoIn AUS it's much like chatmasta says: if its a CC linked a true "credit" account the issuer has the value entirely underwritten. If you can reasonably prove that someone stole it for example, then you'll get your money [credit] back. If it's linked to a savings account and it's a Visa/MC debit card, for example, then it's a different story. The funds are not insured and so if you loose it it's on you.
- teraflop 9y agoEven if the credit card company decides to hold you liable, you're still better off, because they have to follow court procedures and get a judgment against you before they can actually take your money. With a debit card, the money is just gone and the burden is generally on you to find some way of recovering it from whoever stole it.
- user5994461 9y ago>>> With a debit card, the money is just gone and the burden is generally on you to find some way of recovering it from whoever stole it. Not true. Not in Europe.