CAD Forum - tips, tricks, discussion and utilities for AutoCAD, Inventor, Revit and other Autodesk products [www.cadforum.cz] ARKANCE | CONTACT - CZ | SK | EN | DE
Over 1.094.000 registered users (EN+CZ). AutoCAD tips, Inventor tips, Revit tips. Try the new precise Engineering calculator. New AutoCAD 2026 commands and variables.
RSS channel - CAD tips RSS tips
RSS discussions

Discussion Discussion forum

?
CAD discussions, advices, exchange of experience

CAD Forum - Homepage CAD discussion forum - ask any CAD-related questions here, share your CAD knowledge on AutoCAD, Inventor, Revit and other Autodesk software with your peers from all over the world. To start a new topic, choose an appropriate forum.

Please abide by the rules of this forum.
This is a peer-to-peer forum. The forum doesn't replace the official direct technical support provided by ARKANCE for its customers.
How to post questions: register or login, go to the specific forum and click the NEW TOPIC button.
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Topic ClosedSuggestion for Improvement of Credit Card Security

 Post Reply Post Reply
Author
AliveInTheLab View Drop Down
RSS robots
RSS robots


Joined: 20.Nov.2009
Status: Offline
Points: 425
Direct Link To This Post Topic: Suggestion for Improvement of Credit Card Security
    Posted: 07.Mar.2016 at 04:00

There are different types of security mechanisms.

  • Something Known

    A password is a classic example.

  • Something Possessed

    A house key is a classic example.

  • Something About You

    Using your thumbprint to unlock your smartphone is fairly common. Retina scans are not yet commonplace.

When credit cards first come into existence, they were secured with something possessed. If you had the card in hand, you could make a purchase. You signed the back the of the card and signed the charge receipt. The store clerk could check that the signatures matched, so possessing the card was aided by something about you - your signature.

Then along comes the internet. Suddenly we don't have the signature. We don't even have the card. All someone needs is the credit card number. This resulted in a fair amount of fraud. So the industry added the 3 digit validation code on the back of the card. I am not sure how this makes any difference. It seems like anyone who hacks a merchant's credit card database would also get this 3 digit code too as all internet transactions seem to ask for this every time. Maybe this number is only required at time of purchase and is not stored with the request for payment data, so it's like something possessed.

This Saturday I helped set up for an Alameda Boys and Girls charity event. My wife Sheryl was part of the decorating committee. The committee was short on sand to fill some centerpieces, so I was dispatched to Home Depot to buy some play sand. I purchased the sand with my credit card. I had to insert the credit card into the register instead of swipe it, because my credit card has the chip in it. The chip generates a unique code each time the card is used. This changes the process from something known, the credit card number, to something possessed, the chip in the card. The transaction went through with no problem.

After returning to the event and continuing to help out, I got this email from my bank:

Fraud

No, I did not try to buy any bullets. I don't even own a gun. So clicked on NO which deactivated my card. Though I carefully considered that the email itself was fraudulent, I was OK with this since I did not have to enter any of my information. For example, I did not type in my credit card info. I then called the 800 number on the back of my credit card and verified that this email was legitimate. The agent and I verified that the Home Depot charge was mine but the attempt to buy bullets was not. So was credit card number was now legitimately deactivated.

Here's the problem. I had preregistered for the charity event using a smartphone application called GiveSmart. This allowed me to bid on items in the event's silent auction. In fact, I was the leading bidder on 11 items. Now the credit card associated with my charitable attempts had been invalidated. I was able to contact GiveSmart who helped me switch my account to another credit card. Thank goodness I had a backup card. I almost canceled it because "Who needs two cards?" Problem solved.

But this begs the question, how can we make all transactions that use a credit card on the internet use something possessed security instead of something known? I guess one way would be to leverage smartphone technology. What if each time we made a purchase on the internet, a text message was sent to our phone that we had to reply to? This would mean you would need the credit card number, something known, and your phone, something possessed. This way even if credit card thieves got your credit card number, it would do them no good unless they also stole and unlocked your phone? Would this be too much of a hassle?

My story has a happy ending, but I wish I could have avoided the whole thing in the first place.

Security is alive in the lab.

Go to the original post...

It's Alive in ihe Lab - Autodesk Labs blog by Scott Sheppard
Back to Top

Related CAD tips:


 Post Reply Post Reply
  Share Topic   

Forum Jump Forum Permissions View Drop Down



This page was generated in 0,070 seconds.