Sunny Belfast Hi 24 °C | Lo 11°C

Rhodri Marsden: So you thought your credit card was safe?

Wednesday, 19 August 2009

I've had many pieces of well-meaning advice given to me by my father over the years – most of them ways to avoid repeating my embarrassing DIY errors – but one memorable maxim of his was "never let your credit card out of your sight".

Before the advent of PIN terminals, following this rule would require him to pursue slightly perturbed waiters around restaurants until they gave him a slip of paper to sign; I don't think he knew exactly what underhand deeds he was looking out for, but having never been defrauded while using the technique, he stuck doggedly to it.

He never worried about what happened to the credit card information after the transaction – where his number might be stored and who might have access to it – figuring that that was all probably taken care of by companies employing sophisticated security measures. Most of the time, that's probably true. But not always.

On Monday, a 28-year-old Floridan by the name of Alberto Gonzalez, along with two unnamed Russian co-conspirators, were charged in the US for stealing some 130 million credit and debit card numbers by hacking into the databases of a number of American companies that process card transactions. Gonzalez, already in federal custody for his part in the previous record-breaking theft of 40 million card numbers, is alleged to have used sophisticated software to infiltrate the systems and scoop out the data. If found guilty, all three face 35 years in prison.

Those unfortunate enough to own one of the 130 million compromised cards will probably be spluttering in indignation as to why these companies hang on to such details anyway. The answer is that they're legally obliged to, for a length of time, in case of queried transactions. But why aren't they forced to do it in a way that doesn't put our own security at risk?

There is a worldwide standard (the PCI-DSS) that any companies dealing with cardholder information are obliged to sign up to, but many security experts have pointed out that it's possible to tick all the PCI's boxes and still be insecure. The offence allegedly committed by Gonzalez is as vivid an illustration of that as one can imagine.

For once, this lapse in online security has nothing to do with us, the general public. We're guilty of all manner of stupidity when it comes to our personal financial security – writing down PIN numbers on Post-it notes, using the word "password" as our password – but in this case there's nothing we could have done, save for withdrawing entirely from the 21st century and using cash instead.

So what should these companies be doing to protect us? Graham Cluley, from internet security firm Sophos, has expressed his disbelief that our card details aren't encrypted when they're stored, so that hackers just find random gobbledygook. "If they were properly encrypted," he says, "it would take until the sun burns out for anyone to decode it."

But it's not just the companies storing our details that need to shape up. The 130 million stolen credit card numbers would be of no use to anyone if they couldn't be used to buy stuff. Any masterminds wouldn't have been the ones picking a card number and using it to buy soft furnishings on eBay; they'd sell the numbers on to other criminals in blocks of a few thousand. But eventually, someone would pretend to be you and use your money, because it's still disconcertingly easy to do.

Online shopping is a click-happy cinch, but with that convenience comes risk; if you can tap out your 16-digit number, expiry date and a supposed "secret" three-digit number on the back of your card to book a flight to the South of France, so can anyone else. We may balk at the idea of carrying around an additional device (of the kind Barclays customers now have to use for online banking) to enter our PIN every time we make a credit card purchase online, but when these kind of measures are inevitably introduced, we'll have to grin and bear it. It's for our own good, after all.

As for the likes of Alberto Gonzalez, they're talented individuals capable of writing sophisticated software that can detect weaknesses in even the strongest computer defences. Indeed, such characters frequently find themselves with job offers in the industry following their release from prison. But after a 35-year stretch, technology is likely to have marched on a bit too far for anyone to catch up. Marched on so far, one would hope, that our money would finally be safe from marauding cybercriminals. Fingers crossed.

Source: Independent

The Troubles: Northern Ireland's First Minister and Deputy First Minister

NiteLife: The Roost, Granny's, Bert's

Had a big night out? Click here to send your pics

Balmoral Show: Pictures and Results

Balmoral Show

In Pictures: North West 200

North West 200

Old School Pics: Alex Higgins

Old School

To launch gallery click image or select school below

Methodist College, Campbell College, Grosvenor,
Bangor Grammar, Dunlambert, St Augustine's,
St Dominic's, Royal Academy, Ballymena Academy

The Troubles: Northern Ireland's First Minister and Deputy First Minister

Gallery: Awesome images of Titanic

Gallery: Awesome images of Titanic

Teletoons by Stevie Lee

Teletoons by Stevie Lee

Follow us on Twitter

Out & About: The Garrick

Out & About: The Garrick

Columnist Comments

jane_graham

Why my kids feel Olympics are not the real thing now

I did quite well in my school exams, but the only thing for which I can confidently say I stood out like a beacon among my fellow pupils was my record-breaking 100-metres dash.
readers_editor

Think your money is legal tender? Don’t bank on it

Readers have a habit of shining spotlights on unexpected issues that throw up interesting queries. Or, on occasion, a downright can of worms.

eamon_mccann

World must open its eyes and see Israel for what it is

Why pick on Israel when there's so much injustice in the rest of the world? The answer is to be found in the specific circumstances which gave rise to the launch of the BDS (Boycott, Divestment and Sanctions) campaign in July 2005.
liam_clarke

PR machine is driving Sinn Fein power push

Sinn Fein's ard fheis opens in Killarney tomorrow. Like most conferences held by successful political parties, it is a well-managed set-piece. It is a PR event and it is aimed at the voters watching on TV.
robert_mcneill

Why bringing up our kids should be child's play... or maybe it's not

Nurse, the screens! Yup, top experts have issued new warnings about kiddies watching nothing but tellies and computers, while real life flits by unnoticed outside.
Belfast Telegraph Quizzes

TeleToons

Teletoons gallery by Stevie Lee

Latest Comments