[12843] in Commercialization & Privatization of the Internet
Re: Failings of credit cards
daemon@ATHENA.MIT.EDU (Sean Donelan)
Tue May 31 11:24:38 1994
Date: Tue, 31 May 1994 4:55:48 -0500 (CDT)
From: Sean Donelan <SEAN@sdg.dra.com>
To: com-priv@psi.com
>Today, the dominant form of payment over the Internet is the credit
>card. When we send our credit card numbers out over the net,
>we take our chances.
This depends on how you view what is actually occurring across the Internet.
I would claim the dominant form of "payment" across the Internet (or
perhaps more accurately the method to indicate which account to charge
for services) is the username & password combination. Most of the
commercial systems use this method to identify the user and charge his
or her account. The other parts of the payment process usually occur
by other communication channels, not Internet.
For example, I may have an account with DIALOG. Across the Internet I
can make purchases from Dialog with nothing more than my Dialog account
number and password. Once a month Dialog sends me an invoice that I
pay by mailing a check. Likewise I can setup an account with various
bookstores on the Internet. Most shops issue an account number (usually
no password or PIN) to use when ordering across the Internet. The
bookstore settles my account by charging the amount to a credit card
number I FAXed them earlier. Which eventually ends up with me mailing
a check to pay off the credit card bill.
> The folks with the backbone sniffers
>need not confine themselves to passwords. It's pretty easy to
>pick out a credit card number from a data stream. Furthermore,
>do we know what spool files contain temporary copies of our
>e-mail, and how many sysadmins across the planet have access
>to them? Hopefully the day will come when we'll get rid of crypto
>restrictions and be able to encrypt these sorts of things
>without legal hassle.
Reusable passwords (or credit card numbers) shouldn't be considered
secure with or without encryption. But it is going to be expensive
and painful replacing them with something better.
Of course this isn't unique to the Internet. Most of the networks
in use today have the same technical problems (see the GAO reports).
The real problem is the losses just haven't been big enough to justify
changes.
>But here's a more important issue: how do we trust the vendor on
>the other end with our numbers? Sure, if it's a well-established
>company we can probably trust them. But what if it's some
>garage band selling their jam sessions via a web page? What
>if it's some business in some foreign country? Do we know
>if their local laws will protect us?
This isn't a new problem. One of the big reasons people use credit
cards is the extra protection they get. Not only from the Fair Billing
Act (and its equivalent in other countries), but more importantly
from the bankcard associations. They know their biggest asset it
trust. If the consumer or merchant is afraid to use the bankcard,
the bankcard association loses.
Once upon a time people took travelers' checks on trips. Now people
take their credit card and ATM card. Want to see a credit card
slip in cyrllic or chinese? They look the same the world over.
Of course, this immediately eliminates a lot of small merchants. I
doubt a garage band would ever qualify for a bankcard merchant account.
Sorry, but if I was a banker, I'd wouldn't give a merchant account
to a garage band either.
>If, one day, your credit card number gets posted in a
>Usenet group from Finland, and you've given it out to
>dozens of businesses, who do we blame?
Reusable credit card numbers are a dead technology. We just haven't
figured out how to bury it yet.
>Furtheremore, if credit cards are the only form of net.payment we lose
>the option to shop in privacy. Do we want to have our names
>permanently linked to politically or socially controversial services
>because we once shopped for them over the net? Do we
>want to see the day when all kinds of intimate info starts
>getting leaked onto the net in a big way, the cash-only backlash
>sets in, and our credit card customer base dries up overnight?
>That day is coming.
I think this issue is a lot more complicated, but I'm not sure we
actually need to solve it before implementing various systems.
>The vendor also has to trust the number. Many small
>vendors are not in a position to check numbers in real time.
This is actually a bit amusing. Internet merchants, perhaps more than
any other type of merchant, are extremely well positioned to verify
transactions in real time. Every Internet merchant, by definition, is
connected to a world-wide communications network. Now we just have
to connect the "verifiers" to the same network.
>Even if they can check the numbers they can't truly
>authenticate the identity of the person at the other
>end over the Internet without a prohibitively complex
>authentication system. As it stands now, if Joe Cracker
>wants to order net.goods on my credit, in many
>cases he need merely get my card number and forge
>mail to look like it came from me. Credit card
>fraud is already bad enough (over 3% of credit
>card transaction volume and growing); the card companies
>will be quite loathe to serve Internet-based ordering if
>it starts happening here.
The first rule of banking: If there is money, they will come.
>Finally, the credit card system, with its delayed
>billing assumes billing dispute resolution methods.
>If a customer disputes a bill, the credit card company
>should wipe it off, and the vendor should have good enough
>records and authentication that he can prove the transaction
>took place. Again, this assumes jurisdictional uniformity,
>accounting standards, and high per transaction costs, a
>situation light-years away from somebody running a web
>site on an network that crosses hundreds of jurisdictions
>and dispenses files at $.50 a pop.
Most payment systems have these problems. That's why I'm fairly
skeptical when people claim their system doesn't have these
problems. Processing the transaction originally is relatively
inexpensive. All the exceptions, and disputes are the costly parts.
>What about some of the net.transaction systems that are in
>the works; how close do they come to the ideal of jurisdiction
>independent transaction? The CommerceNet system is fundamentally
>based around the credit card and other methods of payment heavily
>dependent on uniform jurisdiction. It authenticates vendors against
>a public key hierarchy, which is prone to single-point
>failure at the top of the hierarchy, where of course
>CommerceNet has placed itself. No customer
>authentication is provided, as this would be prohibitively
>complex, so the threat of credit card spoofing remains.
I wouldn't dismiss this too quickly. Currently the biggest problem
with credit card transactions on the Internet is consumers are
afraid to send their numbers to the merchants across the Internet.
Coming up with a method for consumers to feel safer would be
a major breakthrough.
You are correct that credit card spoofing remains. But I suspect
Internet merchants are going to be treated like mail-order merchants,
that means the merchant gets screwed, not the bank. But even that
might be acceptable to many Internet merchants if BA, Citicorp, and
the other CommerceNet bank members said what was an acceptable
way to do card transactions across the net. Right now the merchants
are just stumbling around. While its true that there have been
credit card accepting merchants on the Internet for 4 or more years,
I suspect most Internet merchants have long since given up trying
to explain to their bank what they are doing.
Hard figures about credit card usage on the Internet are difficult
to find. I don't think even the bankcard associations have a firm
grip on it. I know I've gotten extremely strange phone calls from
people claiming(?) to be with VISA and MasterCard. A couple of years
ago I tried to start a list for Internet credit card merchants, but
it never got any traffic. Although I got about 50 private messages
from people wanting to know how to get a merchant account (call your
bank, and then the next one, and the next one; but don't call me). I'm
not even sure how to define an "Internet credit card merchant." Is it
someone who says mail your credit card number to 7xxxxxx.xxxx@compuserve.com?
Is it a service like CARL's Uncover that asks for credit card numbers
in real-time on a telnet connection? Is it a bookstore like Computer
Literacy that requests you FAX your credit card number to them instead
of sending it across the Internet?
--
Sean Donelan, Data Research Associates, Inc, St. Louis, MO
Domain: sean@dra.com, Voice: (Work) +1 314-432-1100