American Express fails miserably at basic security
timetobleed.com
timetobleed.com
From Bruce Scheier's blog[1]:
"But once you understand that the problem is fraudulent transactions, you quickly realize that authenticating the transaction, not the person, is the way to proceed.
"Again, think about credit cards. Store clerks barely verify signatures when people use cards. People can use credit cards to buy things by mail, phone or Internet, where no one verifies the signature or even that you have possession of the card.
"Even worse, no credit card company mandates secure storage requirements for credit cards. They don't demand that cardholders secure their wallets in any particular way. Credit card companies simply don't worry about verifying the cardholder or putting requirements on what he does. They concentrate on verifying the transaction."
The only reason this isn't a big deal is that it remains incredibly easy for attackers to get CC#'s without capturing packets off the wire.
(OK, I sympathize: buying a thousand bucks of stuff in four transactions from central Japan at 2 in the morning is not exactly typical behavior for a Bank of America customer.)
I have pre-paid phone, buy small items from Google checkout, and travel frequently. Barclay's knows this, but still keeps calling to confirm my (quite regular, very normal) transactions and blocking my cards.
That had me laughing, you really clearly have not dealt with large numbers of $10 to $50 transactions.
Card companies don't care at all about such charges, if you have a valid card number, expiry in the future and a cvv that matches the charge will be accepted.
VBV and its sister programs has been designed to combat this and passes most of the responsibility back to the consumer or their bank in five-way handshake between the consumer, the merchant, the IPSP, the bank and the issuer.
I seriously doubt that Schneier would consider this information disclosure OK based on this loose interpretation of his blog post.
I googled "waiter stealing credit card numbers" and here's an example from today's news of some folks who got caught:
http://www.wjla.com/news/stories/0510/739156.html
On the other hand if you have a radio scanner and are picking up numbers going over the air from tow truck companies there's no traceable link between you and anything in the database.
Then I stopped using checks.
The CC number is almost never secure.
(I also had a Paypal debit card canceled for authorized charges. Needless to say, I just buy everything with the Amex. Good customer service, good interest rate, cash back.)
If that wasn't bad enough, look at how services like Mint have to interface with these institutions? When will something like OAuth come into play at banks?
I'd love to charter a bank on the premise of superior online service.
It's the only explanation I can come up with.
I can't speak for most financial systems (I only am familiar with one, but it's a big one), but I know plain text passwords happen. Lets call the system IET.
IET doesn't encrypt the passwords used for internet banking. To obscure the passwords, they're stored in the DB using EBCDIC. No joke.
Sure, in theory, encryption of data at rest doesn't matter if the system is secure; however, with a security posture like this, the data is bound to leak.
In this case, I found out about the unencrypted passwords because they were in the files going to the "print & statement" vendor: there is a default letter in the system that says "Hey your password changed to foo99!". Despite suppressing this letter, the data was still transmitted to the vendor: it is simply ignored.
Edit: mkull is probably right in the vast majority of cases
The merchant is the easy way out, they're not going to cancel their connection with the card issuer because that's their bottom line. Sticking the charge to the customer is harder because the customer will cancel.
Follow the path of the least resistance: stick it to the merchant.
Now if they did the right thing, they'd fix their acceptance rules and a bunch of security issues and eat the remainder of the charges.
Fat chance of that happening any day soon.
If they ate the charges, they are afraid that a lot of merchants would deliberately ring up fraudulent purchases for the guaranteed profit.
Those two facts force them to the current system. And the fact that merchants are not allowed to charge customers different rates for different cards gets rid of incentives for merchants to charge customers for the poor security practice that the credit cards have.
But think about it for a second, those charges were inflicted on good merchants, the affiliates are not the merchants, they're in the same boat that you are in, except they lost their goods, the affiliate pay-out and a chargeback fine on top of that.
The bona-fide merchants have to make decisions about charges being fraudulent or not in the absence of this information.
If they guess wrong they end up paying or lose a sale.
Malafide merchants don't care one bit, they'll be up and running under a new identity next week, so they never get stuck with these charges, the simply fold and play it again, and in that case the card issuers do eat the chargebacks.
A bona-fide merchant is a sitting duck, and trust me, this comes to a lot of money on an annual basis. Consumer fraud exists and it is a serious problem.
Find insecurity in competitors service, make loud blog noises, drop payload.
It's just an attack on a competitor and a veiled ad.
As for the butthurt, and this comment: http://news.ycombinator.com/reply?id=1379577 I think you're missing the tone of the conversation around you and it makes you stand out in a negative way.
Amex's lack of security is no less interesting if it's discovered by a competitor. It's a pretty serious mistake by an organization you would expect to be more careful and knowledgeable about these things.
This comment is complementing American Express.
Really identity thievery is an issue b/c of the banks + loan companies. They're perfectly willing to roll accounts with very little scrutiny and I don't understand why there are not class action lawsuits etc. to nail the lender not the jacked identity. Search on the "credit freeze" if you want the real solution.
Name + billing address + four last digits should be enough? Or eight last. Or four last + CVC. Asking for everything that's required for a purchase is beyond dumb. To me, it's like giving out your password while talking to customer representatives, that's also something you don't do.