5 ms·
Yeah, the prologue to this was an example about credit card fraud. It seems like by far the weakest link is the poor security around credit card numbers.
by ectoplasm 11y ago
Yeah, the prologue to this was an example about credit card fraud. It seems like by far the weakest link is the poor security around credit card numbers.
- bgilroy26 11y agoChip and pin is a highly regarded approach to securing CC #s. Maybe to secure web logins, everyone should pony up for one of those rsa [the company] SecureID dongles that generates identifiers http://stackoverflow.com/questions/8340495/how-does-rsa-tokens-work http://stackoverflow.com/questions/8340495/how-does-rsa-toke...
- acqq 11y agoCredit card fraud detection is actually the "good working system." The author complains that he has to enter the new one on all the sites he uses. Well duh, the reason he got the new cc number is that only the vendors he really needs get the new one. And he complains that the sites don't know that "it's he" so he has to write down the passwords to which I answered that the alternatives are central authorities and they appear to be the worse solution than the problem. Is there anybody here who'd like that Google or Facebook or Microsoft or Verisign or the government opens all the sites he visits? The named entities would be happy, it seems.
- jandrese 11y agoI remember when Microsoft first suggested single signon for the Internet (Passport) and everybody on Slashdot had their pitchforks out and started writing long screeds against giving a single company so much aggregate data about their browsing habits.
- acqq 11y agoYes, I remember that I was almost scared as I imagined how wrong it can go. I remember being on some MS organized conference then, even the attendees there, you know, at that time every new technology from MS was cheered by default, were highly skeptical. The guy on the stage wanted to "sell" it, he even did something like "who trusts MS" and raised the hand, an almost nobody followed him. Then he said "I trust them, because, why would they not be straight?" Really.
- ectoplasm 11y agoI don't want a central authority, but CC fraud is still $6 billion annually. Why not build a chip reader into devices? http://www.statisticbrain.com/credit-card-fraud-statistics/ http://www.statisticbrain.com/credit-card-fraud-statistics/
- dublinben 11y agoIt's an awfully quaint notion that you should be able to take money from someone's account (credit/debit/checking/etc.) just by knowing the account numbers. This unauthenticated, default-trusting system needs to be entirely replaced.