ATTENTION ONLINE HOBBYSHOPS!!!!!

May 26, 2005 74 Replies

Its hard to find anyone in the USA who has started an airline that is actually profitable recently, or a profitable car manufacturer.

Which is probably why Mercedes bought out Chrysler. Car manufactures are cyclical you idiot!

I've been away, but just went through this long thread.

I used to work at Nortel when they were developing a centralized credit card payment handling systems 1987-89.

What they were doing, and I am sure that's what they do today, is create a central database of all card numbers deemed stolen/fraudulent and those of closed/superceded/deceased accounts. Different card number classes trigger different response, some including silent contact of Police Departments.

IF the vendor is a registered credit card vendor, then they should already have the necessary means to verify the "acceptable" status of the card immediately ... without any additional information, such as phone number or other.

THEREFORE, any request for additional information IS a fishing expedition and should be seen as suspect.

[suspect condition number 1] After all, the online order system is "online". That means that it is already tied to the communications network and leaves no justification for a phone number that implies **manual** dialling

[suspect condition number 2] If they are looking confirm the charge due to possible credit limit issues, again, they need to confirm this before confirming the order to the customer. So, since this needs to be, and can be, done immediately via electronic credit card transaction stations, these same do NOT require phone numbers.

[suspect condition number 3] If they cannot do this electronic transaction with the credit card vendor immediately, then, possibly, they present a false front of what is called in computing security parlance a "honeypot" to draw unsuspecting customers to share information in what appears to be a legitimate operation, but is in fact use to gather the information to an offshore fraudulent charge factory.

I know I am a bit late in this discussion, but I felt the need to share this information. I hope it does not scare you all away from the online transaction approach, because it will inevitably replace all other modes.

One last check on validity of vendor. Their "contact us" information should be real. In other words, you can track down their contact details from sources OTHER than their own site, i.e. Bell telephone online directory services.

In other words, I think Ed Cregger walked away appropriately in this situation, from a "network systems security" perspective.

Eric (part-time consultant with Googgun Technologies Inc.)

Eric, what you omitted was suspect condition number 4, in which the person placing the order isn't the cardholder, is not authorized to use the card, and does not have the card in his possession, but only knows the number. That's what the question about the bank's phone number is trying to root out. It has nothing to do with calling the bank.

Yes, I understood that.

I just wrote a 2 page response ... then blew it away. I didn't want to re-start a technical discussion that maybe was better pursued under another newsgroup.

Bottom line, from a vendor standpoint, if using Card Provider systems for initiating transactions, the vendor is deemed no-fault if he has the customer's signature.

The problem then turns into usage of a deemed-valid signature mechanism. I leave it to everyone to individually become informed as to which mechanisms are appropriate and to only deal with vendors using them. You may wish to insist on your Card Provider giving you specific guidance as to what to look for in online transaction security. Each Card Provider's preferred/mandatory process may be different from others, so it is advised that you make a determination for each card that one wishes to use for online transactions.

My suggestion: obtain a card which is used ONLY for online transactions. Make sure it has a low credit limit to match your expected usage. In this manner, any inappropriate use of the card does not cross-over to impact our other (dare I say daily) uses of our cards.

[an idea just popped into my mind: one-time credit cards!]

As an aside, when people ask for information that is beyond what should be necessary, I do as someone else suggested, filling the blanks with obviously invalid info. For example, for telephone numbers, I use

1-888-888-8888. Using something that is not obviously invalid suggests deception on the buyer's part and could turn everything against him, legally. I enter "not for disclosure" in text fields. I enter "X0X 0X0" as postal code here in Canada. Those with a sense of humor may feel tempted to enter "H0H 0H0", but that one is already a codified reject in most systems because of Canada Post's having reserved it for all mail directed to Santa Claus.

Basically, use vendor systems against themselves, whenever you feel that they have crossed the line of the acceptable. In that manner, you get what you want, while they will send you your order because they don't want to lose the sale or add overhead to correct the spurious data.

Eric

Yes, no question that's how it's *supposed* to work, but in real life, lots of retailers will bear testimony to taking it in the shorts when they had what they thought was the genuine signature. So we start getting these point-of-sale ID requirements (something which in years past was expressly forbidden by AMEX, and maybe others), a game which I decline to play, so these days, when buying in person, it's either cash or a debit card with PIN.

But anyhow, what you said (quoted above) is the root of the problem. It's when the merchant doesn't have a physical signature that things can really turn south.

Well, to be fair to Hobby Horse, I went back, filled out the order form and didn't bother including the bank card number. The order was processed anyway and I received a receipt. However, I am still waiting for the receiver and crystal. 8^>

Sorry Hobby Horse. It was one of those days.

Ed Cregger

Having the shipment sent to the billing address of the credit card is a pretty good confidence-inspirer from the merchant side.

You call the credit card issuer and add extra "ship to" addresses as well. I always have stuff shipped to my office rather than to my home (the billing address), since there's nobody at home during the day to sign for packages. Having my office address listed with the credit card eliminates delays/questions when the charge is being authorized.

ED, Just about everyone of us spouts off now and again. Your a bigger man than most. :) mk

My merchant account required me to ONLY ship to that address if I expected fraud coverage. And I had to go through the address verification process with EVERY transaction.

Why be condescending, when my "offerings" were to help clarify a process to help inspire trust by identifying attributes of online processes that should inspire trustworthiness ?

Is it wrong to suggest to follow one's gut about a situation being worthy of a step back for contemplation before proceeding down what might [if wrongly judged] be a costly experience ?

To address your statement: Am I personally a merchant ? No. Have I worked as a merchant ? Yes, long enough to more than sufficiently understand the issue.

Your off-hand comment has no bearing on trying to help others "deal" with the web.

Eric

The reason I made the comment is because your statements show that you showed a lack of understanding of what the small merchant goes through with credit card processing.

All that stuff about what you did a couple of decades ago doesn't apply any more. The landscape has changed dramatically.

I think theft is also a percentage of the item cost.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required