Skip to content

Comment on Blippy And Credit Card Numbers - Official Blippy Blogparent

Comments

I read their response. Their response is precisely why this is a big deal. They should have known that credit card numbers might have been in the description field - anyone who deals with bank feeds with any regularity would know that.

Banks and merchants have been doing stupid things for decades; but what they haven't been doing is publishing those details for all to see.

One would hope that Blippy had done some due-diligence and had some concepts about the kind of data they'd be dealing with when they decided to take transaction feeds and publish them. They've clearly figured that out now.

My point was that it didn't seem like they were treating this as something truly serious.

It's not the bank's fault because that wasn't meant to be public information when they built their system. It wasn't the consumer's fault (any more than signing up for a questionable service) because they aren't supposed to know the details of what's inside a transaction feed. By default, it's Blippy's fault because they should have known better.

Nobody is asking them to fall on their sword over this; but it would have been nice to get some indication that they thought it was a big deal.

>> "it would have been nice to get some indication that they thought it was a big deal."

It could have been a big deal, if it had affected more than 4 beta users, or if they hadn't noticed and hadn't fixed it.

I'd rather base level of outrage on what happened rather than what could have happened. Obviously you take all precautions you can possibly think of, but shit happens.

If the CVV and expiry were there as well it would have been much worse, just the numbers are not that important.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.