Holy living fuck. And this is a company that basically has encryption and security tied into its basic business. I think I might have to cancel my AmEx, cause they are obviously idiots over there.
Why does it matter, really? If someone hacks your account and somehow charges a bunch of stuff to your AmEx, then you're not going to be held responsible anyway. And since it's a credit card, you don't even have to pay out of pocket or take interest on the disputed amount.
In fact, I've never dealt with a company that makes it easier to dispute incorrect charges on a card; It's usually a matter of calling them, to which they respond "ok, we'll take it off."
If AmEx thought the amount they'd have to spend on security upgrades would be less than the money they're losing to fraud, they'd spend it. It's almost certainly more difficult than it seems on the surface. A random confused customer service rep's mail is worth a chuckle, but it's not a smoking gun that proves widespread incompetence.
Note: they only need to have the appearance of encryption and security. When they get investigated, they can always blurt out a list of jargon word technologies they use and thus they can prove to a majority if people that they are indeed "secure". And by majority here, I mean mostly judges, attorneys and the media. Yes, this is the same "security theater" that TSA is engaged in.
For example, let's say you are the customer, and someone gains access to AmEx's database of hashed passwords. All passwords are 8 characters long, so after a quick brute and dictionary attack, almost all of the accounts are cracked. Now, you along with all the customers get together and launch and class-action lawsuit. AmEx will only have to blurt out that they use: "RSA", "DSA", "128bit Encryption", "Monitoring" + many other security related jargon and that will be enough to get them of the hook. That's all AmEx needs to do.
They don't have to secure your data or personal information, they only have too fool most people in case of a lawsuit that they tried to secure the information. If they have that covered, they are all set.
Because almost nobody (except for HNers probably) includes security policies as the critical discriminant when shopping for credit cards, AmEx, Visa, MC and Discover others, don't really have to bother implementing any real security.
I seriously doubt others are much better, so unless you're planning on withdrawing from the modern banking system, I wouldn't bother..
I met a guy who did that, and I definitely wouldn't bother with that. He ended up going off-grid too because the power company hated dealing with him and his cash so much. Well, his "eccentricity" might contributed to their opinion of him.
Why are you making the assumption the person who wrote this response has anything to do with the security procedures that ensure data confidentiality? It's obvious the person is not a security specialist and is only repeating whatever he/she picked up at the last training session.
Comments
Holy living fuck. And this is a company that basically has encryption and security tied into its basic business. I think I might have to cancel my AmEx, cause they are obviously idiots over there.
Why does it matter, really? If someone hacks your account and somehow charges a bunch of stuff to your AmEx, then you're not going to be held responsible anyway. And since it's a credit card, you don't even have to pay out of pocket or take interest on the disputed amount.
In fact, I've never dealt with a company that makes it easier to dispute incorrect charges on a card; It's usually a matter of calling them, to which they respond "ok, we'll take it off."
If AmEx thought the amount they'd have to spend on security upgrades would be less than the money they're losing to fraud, they'd spend it. It's almost certainly more difficult than it seems on the surface. A random confused customer service rep's mail is worth a chuckle, but it's not a smoking gun that proves widespread incompetence.
If they steal your identity, it might not be a lot of fun.
Identity theft's such a fun phrase. http://www.youtube.com/watch?v=CS9ptA3Ya9E
Note: they only need to have the appearance of encryption and security. When they get investigated, they can always blurt out a list of jargon word technologies they use and thus they can prove to a majority if people that they are indeed "secure". And by majority here, I mean mostly judges, attorneys and the media. Yes, this is the same "security theater" that TSA is engaged in.
For example, let's say you are the customer, and someone gains access to AmEx's database of hashed passwords. All passwords are 8 characters long, so after a quick brute and dictionary attack, almost all of the accounts are cracked. Now, you along with all the customers get together and launch and class-action lawsuit. AmEx will only have to blurt out that they use: "RSA", "DSA", "128bit Encryption", "Monitoring" + many other security related jargon and that will be enough to get them of the hook. That's all AmEx needs to do.
They don't have to secure your data or personal information, they only have too fool most people in case of a lawsuit that they tried to secure the information. If they have that covered, they are all set.
Because almost nobody (except for HNers probably) includes security policies as the critical discriminant when shopping for credit cards, AmEx, Visa, MC and Discover others, don't really have to bother implementing any real security.
I seriously doubt others are much better, so unless you're planning on withdrawing from the modern banking system, I wouldn't bother..
I met a guy who did that, and I definitely wouldn't bother with that. He ended up going off-grid too because the power company hated dealing with him and his cash so much. Well, his "eccentricity" might contributed to their opinion of him.
I work for a bank, and while we have our problems (http://mcherm.com/permalinks/1/password-in-pieces), we aren't anywhere NEAR this bad.
Why are you making the assumption the person who wrote this response has anything to do with the security procedures that ensure data confidentiality? It's obvious the person is not a security specialist and is only repeating whatever he/she picked up at the last training session.
Ehh, you're not going to be liable for the vast majority of security flaws. I wouldn't overworry yourself, the alternatives are much more dangerous.
And after you cancel your Visa, Mastercard, etc., because they are no doubt the same kinds of idiots, how are you going to pay?
Cash?