3 ms·
You should not use any card that does not give you a 100% guarantee that you will not be held responsible for erroneous charges. It really doesn't matter the r
by reeses 13y ago
You should not use any card that does not give you a 100% guarantee that you will not be held responsible for erroneous charges. It really doesn't matter the retailer – they almost all suck. The older the company or the faster its growth, the more you should worry. Push that worry onto Amex or your bank.
PCI is surprisingly easy (and anyone can look it up at https://www.pcisecuritystandards.org/security_standards/documents.php?agreements=pcidss&association=pcidss https://www.pcisecuritystandards.org/security_standards/docu...). It's basically all about "data at rest," covering what can be stored, how it must be stored, and how it should be stored. If a merchant can't meet the requirements, then they are required to demonstrate "compensating controls" which can literally be "we have a project in place to fix this before the audit a year from now."
"Data at rest" involves (in this case) credit card information stored on "disk" (SSD, etc.) for more than a short period of time. This generally excludes virtual memory, some queueing software, etc. If it touches the disk for ten seconds but is then wiped, you're compliant.
Then there are a list of "musts". You must have firewalls protecting the internal network (and review the rulesets), documentation on any connectivity to cardholder data, dataflow diagrams, only allow essential traffic in the card info environment, wall off wireless access, have an IPS, change all vendor defaults on any devices that could possibly screw you, minimize server responsibility (so don't run your smtp relay on the machine that also encrypts your card info), rotate encryption keys every x days, don't store CID/CVV/track 2/full mag-tape data from the card, scan your systems for changes/compromise/unauthorized access, maintain nonreputable audit trails, etc.
PCI is ratcheting down the requirements so that there is less room for interpretation. Previously, just using Oracle's obfuscation toolkit would be enough. This would protect you (more or less) if someone had access to your block device in raw mode or your data files in what-the-hell-is-your-dba-thinking mode, but an Edward Snowden could log in and SELECT all of your card info.
- maxerickson 13y agoBut why should a credit card user care about any of that (other than the easy disputing of erroneous charges)?
- reeses 13y agoBecause the world sucks. Many times, your cc provider will detect suspicious activity and freeze your account, but one of the common patterns of card theft is a validation phase followed by a "hammer it until it cries" phase. It's quite possible to have a few small charges show up on your account that you might miss because your overall bill seems fine. Usually, once the card is proven good, you'll get the lovely bill for a first-class flight to Qatar. I agree that a cc user should not have to care about any of this, but people responsible for protecting your money are not so responsible.
- maxerickson 13y agoBut there isn't any need to invoke PCI or details about it in order to say "Card info gets leaked so watch your statements". (And most people are fairly aware of the fact that card numbers are sensitive information; the newish thing here is a large retailer failing so spectacularly)
- reeses 13y agoRemember when people were afraid to enter their credit cards online, so they would call a customer service rep and read it to that person over the phone? The key piece to keep in mind is that the info on that little piece of plastic is never "safe". If I were warning my mother, I'd just follow your hypothetical above. Of course, if the outcomes of these data breaches start including other identity theft, such as the "$50,000 twitter name"[1] hijack, more realistic phishing attacks, etc., then things are going to get interesting. [1] Which is of course silly since the TOS specify that they are not to be sold.
- jccooper 13y agoRemember? It's still happening. We get this question constantly.
- raverbashing 13y ago"(other than the easy disputing of erroneous charges)" They are not easy nor simple AND you can't use your credit card while they mail you a new one So yeah, as someone who have had their CC misused, it's a pain in the behind