Slashdot Mirror


Online Trust Failing Overall

twitter writes "The BBC and ZDNet are reporting on an RSA poll of 1,000 users about failing confidence in ecommerce. 43% of respondents were reluctant to give details to online sites and 70% said that firms were not doing enough to keep their data secure. The BBC goes on to quote experts who back up the perception, ZDNet claims that action is being taken and is well."

4 of 197 comments (clear)

  1. A lot of the problem is bad design by hsmith · · Score: 4, Interesting

    or not taking the security concerns seriously. If you are saving peoples Social Security Numbers and CC Numbers then you should be encrypting that data. Venture to guess how many places actually encrypt that in a database?

    But then again i would say most larger places do take these steps. More often than not I won't buy from somewhere I am unsure of or if they are not in the http://www.bbb.org/. Plus, how many people know how to always use SSL when sending sensitive stuff? I would venture my grandparents and mother have no idea.

    On a side not to the last statement, i would like to say, office depot does NOT use SSL for their secure communications when you order something from in store.

  2. lots of large scale compromises lately by ArbitraryConstant · · Score: 5, Interesting

    While I'm somewhat surprised the average user pays attention to such things, I'm not surprised trust is failing in light of recent large scale compromises.

    Until the industry as a whole adopts a strategy of preventing compromises, this is not going to improve. Most companies would rather pay a PR guy to fix their image after the fact than a security consultant to keep it from happening in the first place. That's certainly not how I want my information taken care of.

    --
    I rarely criticize things I don't care about.
  3. Quotes from the BBC article: by TripMaster+Monkey · · Score: 5, Interesting
    Some [users] resort to using the same one for all their online accounts. Those who use several passwords often write them down and hide them in a desk or in a document on their computer.

    Dear God, ain't this the truth??? I'm a network admin at a large company (please don't ask which), and the password situation here would be laughable if it weren't so sad. I ran LC5 on our hash file here, and was shocked and dismayed at the number of passwords cracked within 10 seconds. I'm constantly finding passwords on sticky notes on monitors and under keyboards, and many users haven't even bothered to change the default Lotus password ('password') to something else! >:(

    Last year, a street survey found that more than 70% of people would reveal their password for a bar of chocolate.

    That seems to be about the right figure for users in my company.

    --
    ____

    ~ |rip/\/\aster /\/\onkey

  4. Proxy CC# by donnyspi · · Score: 4, Interesting

    I like using MBNA bank's credit card number proxy feature whereby you create a onetime use CC# with a limited spending limit to give out online. It's a great feature for paying at Sam's Shady Online Store with a CC# that has a $30 limit and expires in a month.