8 ms·
Why would a company ever ever ever accept 6 digits of a credit card number as a way to authenticate an identity?? Credit card numbers are not secure. Therefor
by chavesn 13y ago
Why would a company ever ever ever accept 6 digits of a credit card number as a way to authenticate an identity??
Credit card numbers are not secure. Therefore, they should not ever be accepted as authentication. Especially only 6 digits of it! This is by far the most shocking part of this story. As if I needed another reason to despise GoDaddy.
[Edited to add] I would sure love to see a scarlet letter list of companies which allow such practices, so I can never use them.
- ivanbrussik 13y agoI actually think it was 4.
- eridius 13y agoGoDaddy requires 6 digits, but the agent let the attacker guess 2 of them (repeatedly, until he got it right). That's truly awful.
- fredsted 13y agoI thought everyone knew not to use GoDaddy after the SOPA incident. Hopefully this will convince more people to move their domains to a domain registrar that cares about its customers.
- Osiris 13y agoSOPA was from one person (in-house counsel) and was not and is not the sentiment of c-level management or any employees I've ever talked to.
- yajoe 13y agototally off-topic, but because of the SOPA nonsense I've slowly moved my 40-or-so domains to namecheap during 2013 when their renewals came up. I was otherwise ambivalent about which DNS service/registrar to use before that incident... but thank you for helping the guy get his twitter account back and fixing up the internal controls.
- squigs25 13y agoSometimes you're forced to use godaddy. I wanted a domain that had been registered with godaddy, so I needed to backorder it through them, and register it through them.
- hkmurakami 13y agoThe attacked got the last 4 from Paypal and Godaddy asked him to guess two more digits.
- aaronbasssett 13y agoGuess from a fairly limited set as well, it wasn't all numbers 00-99. http://en.wikipedia.org/wiki/List_of_Issuer_Identification_Numbers http://en.wikipedia.org/wiki/List_of_Issuer_Identification_N...
- mikegreen 13y agoSomething isn't right. They ask for the 2 digits before the last 4, and then let him guess the first two. I'm really interested to see godaddy's response to this...I'm sure paypal records their interactions, I would imagine godaddy does as well. Hell, I called Avis about something 2 months later with a dispute and they pulled the recording to make sure I wasn't BS'ing them.
- Osiris 13y agoWhen a customer calls into the GoDaddy call center, they are supposed to provide a 4 digit pin in order to gain access to their account. I don't work in that department, but I'll forward the page to the CEO and make sure it gets read and addressed.
- Osiris 13y agoUPDATE: GoDaddy's CEO let me know that they contacted the affected party, the internal security team, and Twitter security. I'd hope they are also looking at policy/training changes for customer support, but that wasn't mentioned.
- SimHacker 13y agoWhile you're at it, tell him to stop shooting elephants, donating money to Mitt Romney, decorating your web site with scantily clad women, and acting like a sexist pig. Edit: I see you got a new CEO since I and so many other customers left in disgust about your company's support of SOPA and all those other issues. I'm sure you still have binders full of scantily clad women to decorate your booths at trade shows. Your company is permanently tainted, one of the worst examples of what's wrong with the computer industry, and I'm never coming back.
- Osiris 13y agoI get it. I came on 2 years ago after Bob had already left. GoDaddy has also officially stopped doing "GoDaddy Girls", which is a relief. Those old commercials were awful.
- blazzar 13y agoThe reason for the 6 digits is probably linked to PCI DSS compliance where agents are allowed to view the first 2 and last 4 of stored card numbers.
- gaius 13y agoThe first digit of a credit card number identifies the type of company the issuer is, e.g. 1 is an airline, 3 is a travel agency, 4 and 5 are credit card companies, 7 is an oil company. The final digit is a checksum. Two things about this baffle me: 1) that websites feel the need to have a dropdown to identify what sort of card you have instead of just figuring it out and 2) why they need to ping it off the issuer's servers to detect you've entered an invalid number e.g. a typo.
- anthonys 13y agoI agree- there's no need to get people to choose the type of card however for 2), that's not always the case. Pretty much all cards can be validated with the Luhn algorithm in js. See http://stackoverflow.com/questions/20725761/validate-credit-card-number-using-luhn-algorithm http://stackoverflow.com/questions/20725761/validate-credit-...
- delinka 13y agoThe card number can be validated, that doesn't make it a valid card. You still have to ask the issuing bank whether the card is an active account, whether it has the funds for the purchase, etc
- gaius 13y agoYes - things such as two transposed digits can easily and should be trapped on the client side.
- aaronem 13y agoBack when I was doing payment code, I built several sites which didn't prompt for the card type, since (a) the first digit identifies the association [1] and (b) the processor doesn't usually care anyway, i.e., you don't need to submit a card type value along with the rest of the transaction data. Most of the clients for whom I built these sites complained about the lack of a dropdown, and were not terribly receptive to my explanations on points (a) and (b) above; their line of thinking on the matter was that people expect to see a card type dropdown, and will complain in its absence. I rather doubt that's true, but I have also never considered it really my place to argue too strenuously against a client who refuses to let me save them money, so more often not I ended up adding the dropdown anyway. [1] 3 = AmEx; 4 = Visa; 5 = Mastercard; 6 = Discover.
- blueskin_ 13y agowell, http://plaintextoffenders.com http://plaintextoffenders.com exists - someone should make creditcardoffenders.com .
- qznc 13y agoNow there needs to be a browser plugin, which warns you when you are about to create an account on such a website.
- cpach 13y agoThat's an awesome idea!
- kmfrk 13y agoThe problem with services like that is that they aren't likely to be updated, if the company improve their measures. You'd have to check in regularly to confirm this is still the way they do things.
- cpach 13y agoThat’s definitely a potential issue. Would be cool if the users’ incentives could be set up in a way that prevent the information from getting outdated.
- Achshar 13y agoKind of off topic but that site also shows sites that email users their password when they create the account. That does not necessarily mean they store it plain text. Though the kind of devs that would send the password in email are likely to store it in plain text, but it's not necessary.
- Steuard 13y agoIf you send the password in email, that's at least one instance where it was readable in clear text to everyone on the network between you and the server (and probably things like packet sniffers on the local network, right?). It's not as bad as storing it in the clear, but it removes some of the value of (e.g.) hosting a login page via SSL.
- mathattack 13y agoCredit card #s and social security #s are not secure. But what should companies use instead? We're a long way from everyone having fingerprint scanners, and I'm sure there will be a way to break that too. Isn't the solution more around recovering from when the break-ins inevitably happen?
- if_by_whisky 13y agoFingerprint scanners sound worse than credit cards to me... Why would you want a password that you can't ever change and leave copies of everywhere you go?
- mcone 13y agoBecause fingerprints should be used as usernames, not passwords. http://blog.dustinkirkland.com/2013/10/fingerprints-are-user-names-not.html http://blog.dustinkirkland.com/2013/10/fingerprints-are-user...
- ecocentrik 13y agoThat's probably not a great idea for anything other than very secure systems where users aren't concerned with privacy, flexibility of identity or anonymity.
- aestra 13y agoDoes Go Daddy require recurring payments or can you pay for a couple years up front? If so you could have generated a one time card number OR had been issued a new card since you paid you you might not even know your card number. How would this even work for everyone? https://www.namecheap.com/ https://www.namecheap.com/ accepts bitcoin as payment to avoid this situation.
- adventured 13y agoYou can pay up to 20 years in advance on a domain with GoDaddy if I recall.