Note: they only need to have the appearance of encryption and security. When they get investigated, they can always blurt out a list of jargon word technologies they use and thus they can prove to a majority if people that they are indeed "secure". And by majority here, I mean mostly judges, attorneys and the media. Yes, this is the same "security theater" that TSA is engaged in.
For example, let's say you are the customer, and someone gains access to AmEx's database of hashed passwords. All passwords are 8 characters long, so after a quick brute and dictionary attack, almost all of the accounts are cracked. Now, you along with all the customers get together and launch and class-action lawsuit. AmEx will only have to blurt out that they use: "RSA", "DSA", "128bit Encryption", "Monitoring" + many other security related jargon and that will be enough to get them of the hook. That's all AmEx needs to do.
They don't have to secure your data or personal information, they only have too fool most people in case of a lawsuit that they tried to secure the information. If they have that covered, they are all set.
Because almost nobody (except for HNers probably) includes security policies as the critical discriminant when shopping for credit cards, AmEx, Visa, MC and Discover others, don't really have to bother implementing any real security.
Comments
Note: they only need to have the appearance of encryption and security. When they get investigated, they can always blurt out a list of jargon word technologies they use and thus they can prove to a majority if people that they are indeed "secure". And by majority here, I mean mostly judges, attorneys and the media. Yes, this is the same "security theater" that TSA is engaged in.
For example, let's say you are the customer, and someone gains access to AmEx's database of hashed passwords. All passwords are 8 characters long, so after a quick brute and dictionary attack, almost all of the accounts are cracked. Now, you along with all the customers get together and launch and class-action lawsuit. AmEx will only have to blurt out that they use: "RSA", "DSA", "128bit Encryption", "Monitoring" + many other security related jargon and that will be enough to get them of the hook. That's all AmEx needs to do.
They don't have to secure your data or personal information, they only have too fool most people in case of a lawsuit that they tried to secure the information. If they have that covered, they are all set.
Because almost nobody (except for HNers probably) includes security policies as the critical discriminant when shopping for credit cards, AmEx, Visa, MC and Discover others, don't really have to bother implementing any real security.