5 ms·
Because they can't harvest your information if you don't sign up for stuff.
by pxndx 8y ago
Because they can't harvest your information if you don't sign up for stuff.
- VBprogrammer 8y agoNever attribute to malice that which is adequately explained by stupidity. I would be completely unsurprised to find that other than having the data in some poorly secured database it isn't used for anything useful.
- toufiqbarhamov 8y agoNever forget the corollary! “...But don’t dismiss malice.” Dismissing reasonable concerns about a nearly universal practice is best done through reasoned argument, not aphorism.
- EnFinlay 8y agoTo be pedantic, that's till harvesting your data, it's just not selling it. Does that make it malicious and stupid?
- darkpuma 8y agoYou should be aware that many malicious people feign incompetence when caught.
- VBprogrammer 8y agoI'm really surprised this was down voted so much. I really don't think it's all that controversial. Like so many websites require registration when you are almost guaranteed never to return.
- brewdad 8y agoI feel really bad for bobsmith@aol.com. He probably had to abandon that address years ago.
- ouid 8y agonever attribute to stupidity that which is adequately explained by profit motive.
- Forbo 8y agoCouldn't a card number be tokenized in some way so as to allow for tracking?
- Znafon 8y agoI dont think so, this would probably go against PCI DSS.
- leesalminen 8y agoI've seen several deterministic tokenizers for payment cards.
- Znafon 8y agoWhere there done by the payment processor like Artemis2 or in house? I'm asking because I saw a lot of in-house tokenizer with hashes or deterministic encryption that could get reversed in a few seconds by brute force since the space to cover is so small.
- unethical_ban 8y agoThe whole point of tokenizing is to get rid of PCI problems on CC analysis and testing, as I understand it.
- Znafon 8y agoIs there credit card tokenization services from which you can get a token identifying permanently a card without the possibility to make a payment?
- nothrabannosir 8y agoYes, most PSPs do this. E.g. Stripe calls it a fingerprint. It's only valid for your merchant ID (i.e. if we both signed up for Stripe and swiped the same card, we'd get different fingerprints). https://stripe.com/docs/api/tokens/create_card https://stripe.com/docs/api/tokens/create_card (notice the request has no charge, but the response contains a fingerprint). To state the obvious: it's not determinstic outside of Stripe, and there's no way to revert it, or even iterate over all CC numbers and brute force the space. You'd need Stripe's secret, e.g. assuming they use HMAC.