|
|
Log in / Subscribe / Register

Security quotes of the week

Security quotes of the week

Posted Oct 13, 2016 9:21 UTC (Thu) by epa (subscriber, #39769)
Parent article: Security quotes of the week

Isn't relying on users not to enter their credit-card number almost as doomed as relying on them not to plug in USB devices or to view documents attached to email messages?

The number is printed in big writing on the front of every card. Surely any system that requires keeping it a secret needs a rethink.


to post comments

Security quotes of the week

Posted Oct 13, 2016 10:30 UTC (Thu) by eru (subscriber, #2753) [Link]

The number is printed in big writing on the front of every card. Surely any system that requires keeping it a secret needs a rethink.

But the number isn't online (until the user enters it manually). These days, crooks are not interested in information that isn't downloadable, it is just too much trouble to obtain.

Security quotes of the week

Posted Oct 13, 2016 11:02 UTC (Thu) by farnz (subscriber, #17727) [Link]

A system that relies on users not entering their credit card number unless they intend to spend money is not doomed - people are trained that they shouldn't give you access to their cards unless they want you to spend money.

What dooms card-based age verification systems (beyond the practicalities of the card networks not wanting to get involved) is that to make them work, you have to train people to give access to their cards without any intention of spending money. Once you've established that giving out your card number is a requirement for access, not just payment, you've trained people to be phished.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds