4 ms·
It's also very possible to abuse a local, bricks and mortar key duplication service. To abuse the online service, you need a valid credit card not in your name
by mapgrep 13y ago
It's also very possible to abuse a local, bricks and mortar key duplication service.
To abuse the online service, you need a valid credit card not in your name or traceable to you, a valid anonymous dropbox to ship to, a clean shot of the key, and an anonymous or well concealed IP address.
To abuse the local service, you need the key, some cash, and about 20 minutes.
Neither is immune to abuse.
- georgemcbay 13y agoAs the consumer, it is way easier to be abused by the online service. First let's assume those running the service are perfectly honest. Now let's assume they practice security about as well as the average small online retailer. Now let's assume a hacker breaks into their system and downloads a full dump of their database. Now that hacker has many (hundreds? thousands?) of key photos matched directly to addresses and likely tons of other PII. D'oh.
- derleth 13y ago> Now let's assume a hacker breaks into their system and downloads a full dump of their database. Now that hacker has many (hundreds? thousands?) of key photos matched directly to addresses and likely tons of other PII. In theory, they could encrypt the data with a public key before it ever hits the database (or any other permanent storage) and ensure the matching private key is never stored on the same computer.
- georgemcbay 13y agoIn theory there are lots of ways they could secure the data, my point was that in the non-theory real world most online companies fall way short of good practices for data security. This is why barely a day can go by these days without some some story popping up on HN about "Company XYZ was hacked, customer data exposed".
- greedo 13y agoAccording to the website, they redact your shipping address a day after the duplicated key ships. So no need for a dead drop. Plus, you could use a VISA prepaid card.
- mapgrep 13y agoRight, my point is that neither service is ironclad secure. (By the way, loading and activating a prepaid Visa anonymously is more tricky than you'd think post Patriot Act - I'd venture criminals would more likely just grab a stolen CC). Interesting about the redaction. Presumably that's to guard your home if the picture is ever compromised?
- MichaelGG 13y agoDo you have more details about prepaid VISAs and Patriot Act? As of a bit ago, you could just walk into any store and buy one with cash.
- Karunamon 13y agoNot sure if the PA is what caused this, but the last time I tried to set up a prepaid card a couple years ago, (one of those off-the-shelf drugstore ones), the actual card could only have $100 put on it until I filled out a form online that required all kinds of PII, including the requisite SSN. The prepaid card only worked in person too, never online. (I assume they did this by having a bogus or placeholder name attached in their database, which would fail any basic verification checks done by an online seller, but work just fine at a local retailer.