Not as apologetic as one might expect.
Not as apologetic as one might expect.
The question is, why would banks put your credit card number on the description of transactions in the first place? I've never seen that done before.
I think they're perhaps not as apologetic as you'd like because the premise (Blippy publishes credit card numbers) is incorrect. They made a mistake in a beta period which they fixed.
This is actually pretty common. It happens on my statements, and while I think that my bank could do something better (last 4 digits would be enough), there is at least a reason. For my joint checking account with multiple debit cards, it helps figure out who bought what. Since each purchase has the exact card number, we can figure out who went to Starbucks 3 times in one day...
Personally, I am not sure why any digits need to be on sales receipts. Or why I even need a receipt.
Also you have the CSV on the back of the card and expiry date. You also have the "Verified by Visa" stuff where you have to enter your password for any online purchase, also you'll usually have to enter the card holders full address.
I agree though, receipts are mainly useless wastes of paper these days, and the less paper with personal details on the better.
Given the massive library of photos available on Flickr, it'd be unlikely that there aren't some credit cards on there - perhaps a credit card left on the coffee table in the background that can be enhanced... Maybe even a credit card in someones very thin see through shorts :/ Wonder how long it'd take to find some examples.
I'm no security expert by any means but still I'm sure that it must be possible to design a lot safer system. Of course you can never defeat human stupidity / irresponsibility / malevolence but it should be a lot harder to commit card fraud.
It's true. A friend of mine moved to Canada from the UK with tickets bought on her card, changed her credit card's billing address to Vancouver, and called the card issuer to let them know she would be moving.
Immediately after she made her first purchase in Canada, they put a hold on her card. She had to call back to get the hold released, but it was put back on as soon as she made another purchase. This continued until she got a new (Canadian) card.
It's too bad the banks in the UK don't scrutinize themselves.
The one time this happened to me, Amex called me to tell me they thought there was a problem. I looked, noticed that there was, and I had a new card / account number the next day. Very convenient, and only an 8 hour or so window where I couldn't use my card.
Someone was careless with my card data, but it didn't matter -- it didn't cost me any time or money. So I guess that's why I don't get too upset about stories like the original article.
Some times people mess up. But there's a difference between "oh oops in the beta period we didn't realize that banks put credit card numbers in descriptions :/ and we didn't realize Google would index that. 4 people were affected and we're sorting it"
and
"We routinely share credit card numbers!!!"
Personally I'd give them a break about it. They're probably feeling pretty crappy about it all already without people blowing things out of all proportion. (This is one of the worst things about the internet IMHO - blowing tiny things up into mammoth proportions through rumor, misunderstanding and incorrect assumptions. And always assuming everyone is evil).
* They got some data
* The data has a "description" field
* They naively displayed that description field
* They then found to our horror that sometimes this
description field contains CC numbers :/
I don't think you can really blame them too much for that.It would be another story if they were actually storing CC numbers and 'accidentally' published them, but that doesn't seem to be what happened.
if(/\d{4}((\s|-)?\d{4}){3}/){
# don't print it
}n.b. not trying to be a smart-ass, just saying it can't be that hard.
And I agree, that a root cause analysis should be done. E.g. asking the 5 why's (as Eric Ries advocates), for behind every technical problem, there's a human problem.
It seems like a ridiculous idea, and while it makes sense in some corner cases, I'm not surprised that they missed something that was only a problem for four users ever.
Perhaps what we should be doing here is asking why Google kept a cache of months-old HTML instead of updating their cache instead?
To that I would say, one should be very very very paranoid about what you print, given that you know that you're printing things from people's credit card bill statement.
Blippy shouldn't have output'd the cc numbers, whether or not Google caches it or not is a secondary to this. Note that Google's cache wasn't explicitly out to get Blippy, they just happened to cache whatever Blippy was emitting.
...to a point.
What other 'bad information' might be in that description? Social Security # for a USA customer? Social Insurance # for a Canadian customer? Pretty soon you'll have a laundry list of 'bad numbers' that you have to try and filter out.
If as they say, all they released were 4 credit card numbers, I understand why they act like this isn't a big deal.
Their system works and has worked the entire time for 99.98 percent of all people. Those few people who did get their numbers published, well, send them a ham or something. At worst, if the cards are used, the user will have a couple days of saying "Chargeback X chargeback Y". This isn't even about a bug currently in their software, but a small one from a long time ago from a credit card processor arguably doing something incorrectly (or at least, quite strangely).
Yes, only someone with the temerity and tenacity to ... click "View Source".