jack: (Default)
[personal profile] jack
AAAAAAAAAAAAAUGH!

How can the banking industry know less about security than me?

A while ago, "Verified by Visa" became compulsory when buying things online. In order to buy anything, you have to know your verified by visa password.

Except, SURPRISE! You don't have to. You can either know your verified by visa password "passcode", OR know your card details, postcode and date of birth.

Seriously, that's strictly less secure than asking for card details, postcode, and date of birth only. I don't think I could devise a system less secure than that if I tried. For instance, it still provides absolutely zero protection against someone you know "borrowing" your credit card: shouldn't that be something passwords protect against?

I mean, I understand -- they don't want to be inundated with phone calls from people saying "I tried to buy something and I couldn't, what's wrong". But after all the brouhaha about verified by visa I thought maybe you needed to speak to someone in person, or at least need the right dongle to reset it. But no, I was insufficiently cynical. Again.

There's probably some other good reason I should know about but don't? I hope?

I do not think that if people were asked to predict my major flaw they would guess "insufficiently cynical about human stupidity". But apparently, I am. Can I rebrand it as "optimism" or "faith in mankind"..? :)

Date: 2012-10-28 01:03 pm (UTC)
kaberett: Trans symbol with Swiss Army knife tools at other positions around the central circle. (Default)
From: [personal profile] kaberett
There are some cases in which it is Worse Even Than That, but I am not willing to go into details of my personal experience in public ;)