[8433] in Commercialization & Privatization of the Internet
Online Shopping and Banking?
daemon@ATHENA.MIT.EDU (John (Francis) Stracke)
Thu Nov 18 16:00:05 1993
Date: Thu, 18 Nov 1993 15:42:31 +0500
From: francis@avalle.insoft.com (John (Francis) Stracke)
To: mcimail.com!0005066432@netcom.com
Cc: bobk@cyberspace.com, com-priv@psi.com
In-Reply-To: "Tansin A. Darcos & Company"'s message of Thu, 18 Nov 1993 13:51:46 -0500 (EST) <0119931118135100/0005066432NA1EM-c100000@MCIMAIL.COM>
Paul Robinson <TDARCOS@MCIMAIL.COM> writes:
>bob <bobk@cyberspace.com>, writes:
>> networks. The Wall Street Journal recently had an article that
>> said PCFlowers on Prodigy has become one of the top five FTD
[...]
>> Bankcorp. I'm sure that the Internet will soon have such
>> services.
>
>Yes, if the capability is there, it will eventually show up.
Agreed.
>> banking and stock transactions? Is the primary roadblock
>> the security issue of sending sensitive financial information
>> (such as credit card numbers) over the Net?
>
>That may be a problem but it's probably less than is thought. If you use
>a commercial mail site, you post your message and it is sent via SMTP to
>the destination computer site.
What do you mean by "a commercial mail site"? I don't think (am I
wrong?) this is all that common. Among other things, direct SMTP
isn't necessarily a smart way to send mail; it sets up a real-time
two-way connection for a purpose that doesn't need it. Relaying
optimizes network usage. Perhaps this is how things like MCIMail
work; but large, multiple-host sites generally have a single machine
that's their mail gateway, right?
Moreover, if the sender and/or receiver has a uucp link (which appears
to be fairly common), direct SMTP is right out. :-)
> Your administrator and the administrator
>of the destination site could conceivably read the mail, and the sites in
>between could conceivably monitor all intervening packets for data, but I
If there's relaying going on, then all relay sites become weak points.
Suppose FTD decides to set up orders@ftd.com, with a uucp link to
foo.net; by bribing somebody@foo.net, you could get a <censored> of a
lot of credit card #s.
>suspect the risk is no where near as bad as people think it is; this ain't
>the equivalent of someone writing their Master Card number on a postcard.
No, but it's still bad, and most people aren't going to think about
it; all we'd need would be one set of headlines, screaming "Millions
ripped off on Internet!", and the email-order companies would shut
down.
>How many messages traverse the Internet each day? Two million? Three?
Something like ten times that, I think. But you don't have to check
them all, just the ones that're addressed to a known ordering address.
A very simple filter program could spot them.
>Then what do you do? Unless you are sending a package to the address
>issued on the card, or have a merchant number, only professional crooks
>can use other people's card numbers.
Yes, and? Professional crooks do exist. Are you suggesting they'd be
incapable of getting onto the Net?
> (Or can they? Do most merchats
>check the address to send a package against the subscriber address?)
Some do, some don't. I remember the first thing I bought with a
credit card (a plane ticket) had to be sent to my home, but that was
the only time it was checked; I have had items sent to me at work.
Probably depends on the value of the merchandise.
This is not to say the problems are insoluble, just that they're going
to require some form of authentication. Encryption would be a good
start.
/===========================================================================\
|John (Francis) Stracke | My opinions are my own. |
|Insoft, Inc. |===================================================|
|Mechanicsburg, PA | "Chris is the most self-effacing guy I know." |
|francis@insoft.com | "Well, I'm not *that* good at it." |
\===========================================================================/