Gaping security issue?
Author
Discussion

Simpo Two

Original Poster:

91,816 posts

290 months

Yesterday (19:47)
quotequote all
I ordered some wine by mail order and the delivery driver wanted ID to prove I was over 18. Driving licence or passport he said. But they were filed away so I asked if a credit card would do. He said 'maybe' so I showed him the back where my name was. He pointed his phone at it, tapped it a few times then said 'OK' and off he went.

10 seconds later I realised that he could easily have taken a photo of it, and all the info needed to commit fraud is there. Same for passports and driving licences. I phoned the CC company and they said the only way to be sure is to cancel the card - so I did.

Isn't this requirement for ID (that gets a phone pointed at it) a blatant open door for all sorts of nefarious activities?

bobtail4x4

4,331 posts

134 months

Yesterday (20:13)
quotequote all
I bought a craft knife a few months back, they said they needed to ID me,

I showed them my bus pass,

Super Sonic

12,949 posts

79 months

Yesterday (20:17)
quotequote all
Do you not keep your driving licence in your wallet?

Derek Smith

49,115 posts

273 months

Yesterday (20:18)
quotequote all
Simpo Two said:
I ordered some wine by mail order and the delivery driver wanted ID to prove I was over 18. Driving licence or passport he said. But they were filed away so I asked if a credit card would do. He said 'maybe' so I showed him the back where my name was. He pointed his phone at it, tapped it a few times then said 'OK' and off he went.

10 seconds later I realised that he could easily have taken a photo of it, and all the info needed to commit fraud is there. Same for passports and driving licences. I phoned the CC company and they said the only way to be sure is to cancel the card - so I did.

Isn't this requirement for ID (that gets a phone pointed at it) a blatant open door for all sorts of nefarious activities?
If you are concerned about security of your credit card, get in touch with your supplying bank. And if not, why not? They will probably have prepared and rapid systems for this.

normalbloke

8,612 posts

244 months

Yesterday (20:18)
quotequote all
Super Sonic said:
Do you not keep your driving licence in your wallet?
They don’t accept the paper version…

sixor8

8,136 posts

293 months

Yesterday (20:20)
quotequote all
There's someone who hasn't moved address for a LONG time. smile

5lab

1,862 posts

221 months

Yesterday (20:50)
quotequote all
This is why credit card companies rely on multi factor authentication to authorize internet transactions. The only thing he could have used the data for is a telephone purchase, which have really tight auth controls and normally put the onus on the merchant to assure identity.

Basically it's extremely unlikely to be an issue.

Simpo Two

Original Poster:

91,816 posts

290 months

Yesterday (20:59)
quotequote all
Derek Smith said:
If you are concerned about security of your credit card, get in touch with your supplying bank. And if not, why not? They will probably have prepared and rapid systems for this.
Simpo Two said:
and they said the only way to be sure is to cancel the card - so I did.

Simpo Two

Original Poster:

91,816 posts

290 months

Yesterday (21:00)
quotequote all
Super Sonic said:
Do you not keep your driving licence in your wallet?
No, too easy to lose.

Simpo Two

Original Poster:

91,816 posts

290 months

Yesterday (21:02)
quotequote all
5lab said:
The only thing he could have used the data for is a telephone purchase
That was my concern, as it had the number, expiry date and CVV code.

Furbo

3,716 posts

57 months

Yesterday (21:18)
quotequote all
Simpo Two said:
I ordered some wine by mail order and the delivery driver wanted ID to prove I was over 18. Driving licence or passport he said. But they were filed away so I asked if a credit card would do. He said 'maybe' so I showed him the back where my name was. He pointed his phone at it, tapped it a few times then said 'OK' and off he went.

10 seconds later I realised that he could easily have taken a photo of it, and all the info needed to commit fraud is there. Same for passports and driving licences. I phoned the CC company and they said the only way to be sure is to cancel the card - so I did.

Isn't this requirement for ID (that gets a phone pointed at it) a blatant open door for all sorts of nefarious activities?
If he only saw one side, he doesn't have all your card details. You've no doubt done "cardholder not present" transactions before, so you've given your full details to randoms. You typically aren't liable for fraudulent use of your credit card.


Simpo Two

Original Poster:

91,816 posts

290 months

Yesterday (21:34)
quotequote all
Furbo said:
If he only saw one side, he doesn't have all your card details.
The card has the number on the back so he saw number, start and expiry dates and CVV code. That's enough isn't it?

Yes, I've given the same info over the phone to specific companies when buying something, but not to a foreign gentleman with an unmarked van. The better news is that it was an Amazon order so unless he's rogue it should be OK. But still, I've never shown my CC to anyone before which was why I thought 'Hang on...'

BertBert

21,021 posts

236 months

Yesterday (21:37)
quotequote all
I'm very confused. You were asked for id, you chose to show your credit card and you think there a conspiracy?

Wasn't that all of your making?

xx99xx

2,756 posts

98 months

Yesterday (21:41)
quotequote all
Usually the ID required purchases from Amazon are just a 'whats your date of birth' question at the doorstep. Never had a problem.

I'd have provided driving licence if required as it's in a box upstairs and easily accessible.

Furbo

3,716 posts

57 months

Yesterday (22:04)
quotequote all
Simpo Two said:
Furbo said:
If he only saw one side, he doesn't have all your card details.
The card has the number on the back so he saw number, start and expiry dates and CVV code. That's enough isn't it?

Yes, I've given the same info over the phone to specific companies when buying something, but not to a foreign gentleman with an unmarked van. The better news is that it was an Amazon order so unless he's rogue it should be OK. But still, I've never shown my CC to anyone before which was why I thought 'Hang on...'
Is yours one of those cards where you can see the reversal of the number from the back? Not all cards are like that.

It's vanishingly unlikely you'd have had a problem and, almost certainly, it would have been your card company who footed the bill if you had.

I've had actual fraud on my card and haggled with my card company not to cancel, because a new card would be a week away from arriving.


Simpo Two

Original Poster:

91,816 posts

290 months

Yesterday (22:10)
quotequote all
BertBert said:
I'm very confused. You were asked for id, you chose to show your credit card and you think there a conspiracy?

Wasn't that all of your making?
I thought he'd just look at it to check the name, not possibly photograph it.

Furbo said:
Is yours one of those cards where you can see the reversal of the number from the back? Not all cards are like that.
It's printed on the back. Not on the front at all.

Furbo said:
I've had actual fraud on my card and haggled with my card company not to cancel, because a new card would be a week away from arriving.
Not a problem for me, I run two different CCs so will use the other one.

Maybe if they ask again I'll decline and play the 'because GDPR' act spin

Dave.

7,827 posts

278 months

Yesterday (22:12)
quotequote all
Furbo said:
Is yours one of those cards where you can see the reversal of the number from the back? Not all cards are like that.

It's vanishingly unlikely you'd have had a problem and, almost certainly, it would have been your card company who footed the bill if you had.

I've had actual fraud on my card and haggled with my card company not to cancel, because a new card would be a week away from arriving.
Most credit and debit cards have all the info on one side now, and just the bank logo on the other....



Simpo Two

Original Poster:

91,816 posts

290 months

Yesterday (22:30)
quotequote all
Ha, I just checked My Orders and the item isn't even showing as out for delivery! Something not joined up there.

Super Sonic

12,949 posts

79 months

Yesterday (22:44)
quotequote all
Simpo Two said:
Ha, I just checked My Orders and the item isn't even showing as out for delivery! Something not joined up there.
So what was the delivery?

kestral

2,155 posts

232 months

Yesterday (22:49)
quotequote all
Simpo Two said:
I ordered some wine by mail order and the delivery driver wanted ID to prove I was over 18. Driving licence or passport he said. But they were filed away so I asked if a credit card would do. He said 'maybe' so I showed him the back where my name was. He pointed his phone at it, tapped it a few times then said 'OK' and off he went.

10 seconds later I realised that he could easily have taken a photo of it, and all the info needed to commit fraud is there. Same for passports and driving licences. I phoned the CC company and they said the only way to be sure is to cancel the card - so I did.

Isn't this requirement for ID (that gets a phone pointed at it) a blatant open door for all sorts of nefarious activities?
You let him take a photo of it ! rolleyes