Who has faith in on-line security ?
Who has faith in on-line security ?
Author
Discussion

ultimasimon

Original Poster:

9,646 posts

286 months

Thursday 30th January 2003
quotequote all
E.g. credit card payment, personal details, medical records etc.

"You are now entering a secure site"...Oh yeah mate...says who?..a friggin padlock on my taskbar? That don't fool me!

http://news.com.com/2100-1001-982131.html


Simple, up to date, computer worm: "The result: chaos.
Bank of America said 13,000 of its ATMs refused to dispense cash. In South Korea, the country's largest ISP, KT, said almost all its customers lost their connections during the attack. Chinese computer users saw sites freeze and a dramatic slowdown in download speeds, as the worm's effects hit the Internet's nameservers--the computers that translate Web addresses into numerical Internet Protocol addresses. And all this in just 376 bytes of code, meaning the entire SQL Slammer worm code is about half the length of this paragraph..."

FRIGHTENENING, half of the above paragraph in code and the most secure and safe systems that take our money (and foreigners too) keel over and die in the age that our government puts on the responsibility of protecting our nation from nuclear attack by a computer!

Absolutely brilliant that man - prove the point!! Now can we get him working FOR internet and national security and not disgruntled and AGAINST it ? !


mybrainhurts

90,809 posts

283 months

Thursday 30th January 2003
quotequote all
I have complete confidence.

Ive never lost a

mybrainhurts

90,809 posts

283 months

Thursday 30th January 2003
quotequote all
n apostrophe, let alone a

pbrettle

3,280 posts

311 months

Thursday 30th January 2003
quotequote all
What ever you do, dont get me on that bloody padlock in a web browser.... Not worth the graphics on screen... secure... never. Most websites are pretty secure, but are still vulnerable...

Mind you, biggest fraud and security risk comes with the interface between the chair and the keyboard!

Cheers,

Paul

pawsmcgraw

957 posts

286 months

Thursday 30th January 2003
quotequote all
by the number of times i've had my card crooked i'd say no faith what so ever....but i still use it,just means the bank and the supplier has to fork out 50/50 when it goes pear shaped again,and again..past caring

funkihamsta

1,261 posts

291 months

Thursday 30th January 2003
quotequote all
Hmm. Its not the transmission of the number that bothers me. It is the storing of details in a fashion connected to the net, as if they are somehow doing you a massive favour by saving you the effort of typing it in each time you buy. Instead some thieving eastern blocker can hack it straight from the retailer. Cybermugging, lose all your dosh from the comfort of your own chair!

miniman

29,813 posts

290 months

Thursday 30th January 2003
quotequote all
But doesn't everyone have a "internet fraud free guarantee" with the card they use on the net?

Use a credit card instead of a debit card - if there's any fraud, it's not your money that's gone straight away and you have time to haggle with the bank over whose problem it is...

PetrolTed

34,468 posts

331 months

Thursday 30th January 2003
quotequote all
At which point I'd like to point out that PistonHeads uses WorldPay for its online shop and assure potential customers that it provides one of the best online transaction mechanisms that we could find.

grahambell

2,720 posts

303 months

Thursday 30th January 2003
quotequote all

PetrolTed said: At which point I'd like to point out that PistonHeads uses WorldPay for its online shop and assure potential customers that it provides one of the best online transaction mechanisms that we could find.




I'd also like to point out that - contrary to the usual media hysteria - the majority of credit card fraud is NOT Internet related.

After all, why go to all the trouble of trying to break a server's security to get peoples' credit card details when you can easily get loads by rummaging for till recepits etc. in shops' bins. Or by getting a job that entails taking credit card details from people either in person or over the phone.

But how often do you hear the media going on about that?

Psychobert

6,318 posts

284 months

Thursday 30th January 2003
quotequote all
After a recent experience, I'll use a credit card, but never a debit card again on the net.

Signed up to an ISP a year ago, monthly contract and they wanted a debit card to start it off. After 6 months Imoved house and cancelled the ISP. Except it took them 3 months to acknowledge it. Then, a couple of months later, having cancelled the Direct Debit, they took 3 months in arrears from my debit card. Phoned them, emailed them, finally very stong letter and they refunded some of it, then took that back and the next month from the debit card. Only way I could stop them was to cancel the card and get a new one. Once they have your debit card number, my bank tells me there is nothign you can do to stop them taking money out. Fairly soon I shall use the debit card for cash and thats it.

Nevin

2,999 posts

289 months

Thursday 30th January 2003
quotequote all
If you cancel the direct debit and inform the bank in writing then any time the bank allows a payment to be withdrawn from your account under the auspices of thsi direct debit they are acting in breach of mandate and contract, and will probably be liable to reimburse you the money withdrawn.

I don't want to be the one to test this in court though.

agent006

12,058 posts

292 months

Thursday 30th January 2003
quotequote all
My take on it is that we used to just read the number down the phone to someone. And now it's encrypted in four zillion bit unbreakable enigmacode, so it's got to be a tiny bit more secure. At least you can't be overheard saying the number, as i was when booking last years Goodwood festival tickets.

davidd

6,712 posts

312 months

Thursday 30th January 2003
quotequote all
A lot of the time your credit card is more secure online than it is in the hands of a grubby assistant in a garage or shop.

There are many steps that can be taken to ensure online transactions are as secure as possible, it is something we have done many times now and as long as certain thnigs are done then the risks are minimised.

I would say however for any online transaction make sure that it is at least SSL encrypted and keep a copy of all your documentation. Any retailer worth their salt will make sure you are not stitched.

On a wider scale the Internet is not a particluarly safe place as was demonstrated last week, however most attacks like this would be stopped if suppliers made 100% secure operating systems and sys admins managed to get everything patched in time. The fact is however that most Operating Systems are not secure so they need lots of patches, the work mounts up (it should never be as simple as applying a patch when you are running critical systems as patches have to be tested which can take weeks), the system gets compromised. At least with the worm you knew it had been attacked.

Sorry for the lecture...

D.

Psychobert

6,318 posts

284 months

Thursday 30th January 2003
quotequote all

Nevin said: If you cancel the direct debit and inform the bank in writing then any time the bank allows a payment to be withdrawn from your account under the auspices of thsi direct debit they are acting in breach of mandate and contract, and will probably be liable to reimburse you the money withdrawn.

I don't want to be the one to test this in court though.


Sorry, might not have made myself clear.. I'd cancelled the direct debit, but the ISP still had my debit card number and details on file so they simply used that to take the money when the direct debit had not been paid by the bank. Even though I informed the bank in writing that the contract had been cancelled and they were not to pay if asked to, they couldn't stop money being taken from a debit card. I rarely use debit cards now as at least there is some protection with a credit card..