Fraud Threat Halts Knuth's Hexadecimal-Dollar Checks
Barence writes "You may be aware of Donald Knuth, the creator of TeX and author of The Art of Computer Programming, who used to post checks to anyone who spotted an error in one of his books — one hexadecimal dollar, or $2.56. No one cashed them though. This blogger has two of them proudly on his wall, but the sad news is that modern day bank fraud has put a stop to Knuth's much-loved way of keeping his books free of errors." (Here's Knuth's own post about the sad change.)
Not if you define a dollar as a hundred pennies...
On second thought, let's not go to the internet. 'Tis a silly place.
Think of a dollar as "100" cents. 0x100 cents = 256 (decimal) cents.
Regarding checks, with their watermarks, UV-readable text,and what not, I don't think they would fall under the category of 'absurdly easy to fake'. However, people are absurdly easy to fool. So the result is the same. And with credit cards, are you talking about making physical fake cards? Because that's not exactly something one can whip up with supplies from the local hardware store. Generating valid numbers however, along with a little social engineering, the same results can be had with little effort.
I judt got a nre Kinesis keybiartf so please excusr ant egregiou typos.
Actually, don't the cheques start at $2.56, and then shift left by 1 as each error is found, up to a maximum of $327.68? (It's wise of Knuth to put a cap on it.. you might be tempted to cash a cheque worth (164)*$0.01..)
The tao of democracy: the government you can vote for is not the real government.
Which is enough evidence that these sorts of things aren't costing the banking industry a whole lot.
This suggests one or more of the following three things are true:
1) There ISN'T ACTUALLY an epidemic of checking/credit fraud aside from a few high profile high press cases (see also: terrorism, pedophilia, and other "woo, the world is SCARY!" kinds of stories
2) When fraud happens, banks are reasonably well equipped to recover the losses (some other bank has to exist on the other end of the wire, naturally)
3) The government doesn't have sufficient laws to protect the victims of these sorts of things where banks are held responsible, so banks have no motivation to fix what amounts to broken financial operations
More Twoson than Cupertino
The right way is a money order. The USPS actually issues money orders for this very purpose, and they charge only a very nominal fee on top of it.
No, it most likely won't. What you say may have been true 10 or even 5 years ago, but is generally not true with modern check imaging systems. The "Check 21" legislation basically enabled all banks to move to electronic check image storage. Of course, they had to upgrade all of their imaging systems to recognize that cost savings, and these new systems are quite discerning, especially for higher-value checks. Manual inspection is required for most high-value checks, and even things like a changed paper stock or layout can be flagged for manual review.
Also, nearly every company of reasonable size is required to implement positive pay, meaning they send a list of check numbers, dollar amounts, and payees to the bank before the checks are actually cut. So when you go to cash a fake check, the bank knows it is fake immediately. There are of course ways to get around this, especially with personal accounts (which usually do not offer positive pay), but check fraud is no longer as simple as portrayed in Catch me if you Can.
That said, check still fraud remains a major cost for banks, and believe it or not they are working hard to make it less possible. But there is as yet no "magic bullet" technology to replace paper checks. Chip-and-PIN, smartcards, etc. all suffer from different security and operational issues. They also cost a lot to implement worldwide, even after including the costs of paper check fraud. A paper check is fairly easily validated, can be sent through the mail, and requires no "secure" hardware terminals at every merchant.
My bank at least will charge me an additional fee if the check isn't MICR-encoded.
I work for a living desinging systems that process checks and credit cards. I couldn't agree with you more; the aging bank standards are absoluely ridiculous in terms of security.
What I don't see anyone pointing out (and what poor Knuth apparently doesn't know) is that these shortcomings have been somewhat mitigated in the rules for processors and merchants and banks. It's not a great solution, it's not even a good solution, but it's hardly the END OF THE WORLD that people seem to be claiming.
You are probably all familiar with the fact that you have a maximum fraud liability on your credit card of $50, and in practice, you'll never be charged anything, not a penny, if someone uses your credit card for fraud. Simply call your bank, explain the situation, and they will issue chargebacks for any charged you did not authorize. You will in the chargebacks, and your money will be returned and you will not be one penny the poorer. (The merchant who accepted the credit card, on the other hand, gets royally screwed, but that's another story.)
Well, the same is not true of written checks; you probably know you need to issue a 'stop payment' and your bank will likely charge you for that. But written checks aren't what people are freaking out about here, and do take quite a bit of effort to forge successfully (a lot less than cash, but still)... we're talking about ACH payment made through the NACHA system. i.e. "Electronic Checks." And there are very strict rules in place from the NACHA, you can order the book online if you feel like wasting a weekend reading the boringest stuff ever.
The important part is this: You can dispute an ACH transaction just like you can a credit card transaction. Anyone who processes "electronic checks" is /required/ to allow up to 60 days for the customer to dispute a fradulent ACH charge. And if you /do/ call in to dispute it, beleive me, it's going to work out the exact same way as the online credit card purchase; you will get your money back and be no poorer (and the merchant will get fucked again!).
So... everybody don't panic. yes, the systems are horrible. No, they aren't changing around here anytime soon; all efforts are stupid or doomed to fail (e.g. VERIFIED BY VISA which is both). But the bottom line is, your money is safe. A simple call to your bank /will/ solve any problems with people making fraudulent electronic charges to your credit card or checking account. I guarantee it. If your bank gives you ANY hint of a problem with a chargeback drop them like a hot potato and go to a better bank. But they won't; I've never run into a situation where you as a consumer is going to have the slightest bit of trouble.
If you're the merchant, on the other hand, you are well and truly fucked. Heh.