Ask Slashdot: How Safe, Really, Is Paying For Things Online?
An anonymous reader writes:
Due to the rash of intrusions into electronic payment systems lately, I've decided to go back to paying cash for everyday purchases, groceries, fuel, and anything else I pay for in person (which also has the positive effect of making balacing my checkbook every month that much easier). The question I have is: For the monthly bills it's just not practical to pay in person (utilities, for instance), how safe are those?
Five minutes of research is telling me that mailing paper checks isn't any more secure than online electronic payments and in fact may be even less secure, but short of literally showing up at the electric company, phone company, ISP, and so on, and paying them cash in person, I can't see any other way to pay them. So how safe is it right now, honestly?
I'm always interested in how Slashdot readers secure their own personal finances -- but how high is the danger that a remote malefactor will hijack and then drain your bank account? Leave your best answers in the comments. How safe, really, is paying for things online?
Five minutes of research is telling me that mailing paper checks isn't any more secure than online electronic payments and in fact may be even less secure, but short of literally showing up at the electric company, phone company, ISP, and so on, and paying them cash in person, I can't see any other way to pay them. So how safe is it right now, honestly?
I'm always interested in how Slashdot readers secure their own personal finances -- but how high is the danger that a remote malefactor will hijack and then drain your bank account? Leave your best answers in the comments. How safe, really, is paying for things online?
You only need to use electronic payments, such as a credit card, not necessarily online. Many thefts used compromised readers during a regular in person transaction, though newer cards make this less likely. Ultimately your retailer will typically store your payment information in a database, along with other personally identifying information. This is even more likely with over the phone purchases. Many companies store it in plain text while few properly hash/encrypt it.
Been paying for stuff online since 1999, frequency of CC number changes is about the same pre and post... occasional bogus charge shows up, call the company, charge is reversed and we get new card numbers... no drama, minor hassle, way better than mailing checks.
I have several checking accounts, and I got tired of paying the check printing companies for... printing my checks. So I bought check stock cheap and I print my own. Apparently, the world has gone from magnetic ink to OCR, so I am home free. If I can print my own checks, so can anyone else print anything they want. I could easily print checks from any other business once I have their account number.
What reduces check fraud is enforcement. Or so I think.
A dingo ate my sig...
Walking around with cash is statistically more dangerous than using credit cards for everything, in the same way that the most dangerous part of a flight is the drive to the airport.
Make that WHEN someone hacks them. Which will almost certainly happen sooner or later. If it's a broad breach instead of just a few accounts, it's a safe bet that in the US neither PayPal nor your money will be anywhere to be found. In the EU where PayPal is subject to banking laws, you may have recourse. Not so in the US where PayPal operates as an unregulated bank. (Why would any sane person give an unregulated bank access to their money?)
You can't see ANYTHING from a car, You've got to get out of the goddamned contraption and walk...Edward Abbey
You can just use your nice high-def camera on your phone to capture someone's Apple Pay screen, say while you're behind them in line and they're getting ready to pay. Free access to ApplePay account with just a picture, no hacking required.
Without that person's specific hardware device (e.g. the iPhone whose screen you photographed), you're not going to be able to use that data you just captured.
#DeleteChrome