Credit Card Activation a security risk

You may have received a credit card with a sticker on it asking you to activate your card by calling a special number for your home phone.

The credit card verification system uses caller ID or ANI to check the number you’re calling from and checks to see if that’s the home number they have on record for you. The idea is that only the legitimate cardholder can call from their home phone. I mean you have to be inside my house to call from my home number, right?

I use a VoIP system as my home phone. Any calls I make are transmitted over the internet before they make it onto the regular telephone system. I’ve got a regular phone number — in fact it’s the same number I’ve had for five years, even before I used VoIP. My phone number shows up in caller ID, just like a “regular” phone. The difference is, for normal landlines, the caller ID information is set at the local phone office. For my VoIP system, the number is set in my phone system — a little box that sits on a shelf in my house.

That means I could change my caller ID to show any number I wanted. I can show mine. I could show yours. I could show up as anybody.

A bad guy that intercepts a new credit card only needs to know your home phone number to use a similar system. And it’s not hard to get someone’s home phone number.

So why are credit card companies using an easily-discovered and easily-spoofed token for authentication?

Dan
October 10, 2006 2:18 PM

Maybe because in the history of credit cards, voip is very new technology. They’ve been around in commercial/personal use for something like 50+years now, and voip? A few years, tops. Mind you, activating online requires you to enter, what, your phone number? postcode? digits on the card/paper? All this is verifiable through taking your maill (when they take your card in the first place). Social security number? Obtainable. Mothers maiden name? Same. Frequent fliers number? Easy. Makes you wonder what IS a safe way to verify personal information/identity. At least you’re covered on a credit card for misuse :)

James
October 11, 2006 2:49 AM

It is a bit stupid of them to not test that is secure before using it and if they had this flaw should have been noticed and sorted lets hope they stop this form of activation soon.

Tama D.
October 12, 2006 4:46 PM

I don’t think it is designed to deter the most sophisticated of criminals and hackers, but I think it is rather cost efficient and effective deterrent from petty thieves and what nots from snatching a new card in the mail and activating it.

Harald
October 14, 2006 8:16 AM

Telephone-based card activation has been around for a lot longer than VoIP systems. Credit card systems take a long time to change. And the coffin’s nail: There are much easier ways to steal your credit card…


Your comments:

Text only, no HTML. URLs will automatically be converted to links. Your email address is required, but it will not be displayed on the site.

Name:

Not your company or your SEO link. Comments without a real name will be deleted as spam.

Email: (not displayed)

If you don't feel comfortable giving me your real email address, don't expect me to feel comfortable publishing your comment.

Website (optional):

Follow me on Twitter

Lijit Search

Best Of

Recently Read

Get More

Subscribe | Archives

Recently

Ideas, Risk, and Investors (Jan 1)
Over at SacStarts, I have piece up discussing a common question I get from entrepreneurs....
VoiceXML for web developers (Dec 17)
Building voice applications isn't hard at all. Any web developer can do it.
De-skunking a dog (Oct 27)
How to clean up your pet after a skunk attack.
Pressure sales via Twitter (Oct 16)
Sticking an ad in my face when we first meet is a good way to lose my interest.
Loma Prieta, 20 years later (Oct 13)
Looking at the earthquake from October 17, 1989
Red light cameras don't work (Oct 13)
Cameras installed to catch people running red lights aren't about traffic safety at all.
Jack-o-lantern pumpkin carving patterns (Oct 12)
It's a tradition, what can I say?
SEO realities (Oct 12)
The real search engine optimization. Works every time.

Subscribe to this site's feed.

Elsewhere

IMified
Build instant messaging applications. (My company)
SacStarts
The Sacramento technology startup community.
Pinewood Freak
Pinewood Derby tips and tricks

Contact

Adam Kalsey

Mobile: 916.600.2497

Email: adam AT kalsey.com

AIM or Skype: akalsey

Resume

PGP Key

©1999-2010 Adam Kalsey.
Content management by Movable Type.