• HEXUS
  • HEXUS.tv
  • channel
  • gaming
  • lifestyle
  • trust
  • community
  • ESReality
  • HEXUS.community discussion forums

    Welcome to the HEXUS.community discussion forums forums.

    You are currently viewing our boards as a guest which gives you limited access to view most discussions and other features. By joining our free community you will have access to post topics, respond to polls and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

    Go Back   HEXUS.community discussion forums > HEXUS.channels > General discussion

    General discussion Chatter, desires, jokes & rants; some threads are banter some are serious - please show respect for others Add RSS Feed

    Reply
     
    LinkBack Thread Tools
    Old 16-08-2006, 09:11 AM   #1 (permalink)
    Taz
    Senior Member
     
    Taz's Avatar
     
    Join Date: Jan 2005
    Location: London
    Posts: 1,952
    Thanks: 34
    Thanked 21 Times in 20 Posts
    Taz's system
    Would you send your credit card details by e-mail?

    I've just been gobsmacked by a conversation I had with my company's travel agent. I'm not going to name the travel agent as they are a global company.

    I travel a lot for my job and my admin books my flights through our travel agent. They hold my credit card details in my profile and they charge all my flights directly to my credit card. They then send me an invoice and I use that as a receipt for my expenses to claim the cost of the flight back from my company.

    Although that might seem strange, it works well for me as I get loads of BA miles on my BA/AmEx card.

    Anyway, i've got a new credit card now and I need to provide the travel agent with my new credit card details. Unfortunately, the only way that they are accepting profile changes is via e-mail! Hence, they are asking me to send full details of the new credit card via e-mail.

    Naturally, I refused and they are refusing to update my profile. Am I wrong in refusing to provide details of my credit card via e-mail or are they wrong for being so lax in their IT security procedures? They told me that this process has been approved by their IT and finance departments!
    Taz is offline   Reply With Quote
    Old 16-08-2006, 09:12 AM   #2 (permalink)
    Better paid than Directhex :)
     
    dangel's Avatar
     
    Join Date: Aug 2005
    Location: Cambridge, UK
    Posts: 5,609
    Thanks: 177
    Thanked 142 Times in 122 Posts
    dangel's system
    Me? Yes - but then i'm covered for fraud anyway so it's not my problemo if things go south

    Te audire non possum. Musa sapientum fixa est in aure
    -------------------------------------------------------------------------------------------------------------------------------------------------------
    System 001: Asus P5Q Deluxe, Q6600 @ 3.0ghz, D-Tek FuZion V2 CPU Block, GTX280, Alphacool GPU Block, 4GIG Corsair 6400 DDR2 RAM CL4 @ 800mhz, Corsair HX1000, Dell 2001FP, Logitech 5.1, Seagate 7200.10 320gb x 2 (RAID 0), 500 GIG 7200.9 (backups), Antec 1200 case, Thermochill 120.3 rad, Vario Pump, Vista Ult 64/XP Pro 32 [main] WORK IN PROGRESS
    System 002: 4200X2, ASROCK (my ass-rocks!) 939 uATX MB, ATI1650 (passive), Zalman 500W psu, IIyama 17" LCD, £7's worth of 5.1 speakers (they rock) XP Pro [wife/server]
    System 003: AOpen 1557 GLSLaptop, ATI 9600 64mb, 1.5 GIG of DDR2700 memory, 60gig fujitsu HD 8mb cache, Intel Wireless and it's great! XP Pro [main lappy]
    System 004: ASUS A8N Premium, 4200 X2, 2 GIG Corsair, Silverstone HTPC case, XP120 cooler, 8600GTS (passive), Samsung 500GIG, MCE Remote, Samsung 40" LCD (87BDX) via HDMI Vista Home Premium (32) [media centre]
    System 005: 7" Asus Eee PC 701-B Intel Mobile, 2GB DDR2, 4GB Solid State HDD, Linux Deleted - XP to replaced it!, Black [toy]
    Work System 001: HP supplied Quad Core Q6600, 2gb DDR 2, 400gb SATA RAID 0, 250gb SATA backup drive, nVidia 8800GTS 640mb, Dell 2001FP, iiyama VM Pro 451 Vista Ult 64/Vista Ult 32 SERVICE PACK 1 [main work system]

    ---------------------------------------------------------------------------------------------------------------------------------------------------------
    Directory Opus 9 rocks! (click here) Opera Ad-Blocker (click here)

    dangel is offline   Reply With Quote
    Old 16-08-2006, 09:24 AM   #3 (permalink)
    Will work for beer...
     
    nichomach's Avatar
     
    Join Date: Jul 2003
    Location: Preston, Lancs
    Posts: 5,603
    Thanks: 100
    Thanked 88 Times in 63 Posts
    nichomach's system
    Originally Posted by Taz
    They told me that this process has been approved by their IT and finance departments!
    Then their IT and finance departments need a swift kick up the arse. The ONLY way that your CC details should be allowed over t'Internet is via a secured, encrypted process, like a secure http (https) session with their web server. Electronic mail is grossly insecure for this purpose. It's plain, unencrypted text which may be stored at any number of mail relays in its path to them. It's practically inviting someone to commit fraud.

    nichomach is offline   Reply With Quote
    Old 16-08-2006, 09:31 AM   #4 (permalink)
    www.uk3x.com
     
    Spud1's Avatar
     
    Join Date: Jul 2003
    Location: Stafford
    Posts: 4,648
    Thanks: 22
    Thanked 36 Times in 26 Posts
    Spud1's system
    No - i just wouldn't do it. It's not secure, and while the risk is tiny in reality, it's still there, and in todays current culture it wouldnt surprise me if any claims you made over losses were refused due to negligence on your part..

    take it up with your employer if you have to

    Mac Pro, 2x Quad core 2.8ghz Xeon, 512mb 8800GT, 4gb DDR2 FB-Dimm
    Macbook, 1.8ghz Core Duo, 2GB Ram, Superdrive
    iPhone 2G 2.0.1
    "Is it a coincidence that an anagram of gordon brown is "born do wrong" ?, I rest my case.
    Spud1 is offline   Reply With Quote
    Old 16-08-2006, 09:34 AM   #5 (permalink)
    Taz
    Senior Member
     
    Taz's Avatar
     
    Join Date: Jan 2005
    Location: London
    Posts: 1,952
    Thanks: 34
    Thanked 21 Times in 20 Posts
    Taz's system
    Yes, I will take it up with my employer. Originally we were asked to fill in a paper form and that was posted to the travel agent. It now appears that they only accept e-mail.

    AmEx will point-blank refuse to honour any claim of fraud if i've been negligent enough to send the information via e-mail.
    Taz is offline   Reply With Quote
    Old 16-08-2006, 09:49 AM   #6 (permalink)
    More l33t than dangel
     
    directhex's Avatar
     
    Join Date: Jul 2003
    Location: /dev/urandom
    Posts: 13,337
    Thanks: 27
    Thanked 252 Times in 199 Posts
    directhex's system
    Originally Posted by Taz
    I've just been gobsmacked by a conversation I had with my company's travel agent. I'm not going to name the travel agent as they are a global company.

    I travel a lot for my job and my admin books my flights through our travel agent. They hold my credit card details in my profile and they charge all my flights directly to my credit card. They then send me an invoice and I use that as a receipt for my expenses to claim the cost of the flight back from my company.

    Although that might seem strange, it works well for me as I get loads of BA miles on my BA/AmEx card.

    Anyway, i've got a new credit card now and I need to provide the travel agent with my new credit card details. Unfortunately, the only way that they are accepting profile changes is via e-mail! Hence, they are asking me to send full details of the new credit card via e-mail.

    Naturally, I refused and they are refusing to update my profile. Am I wrong in refusing to provide details of my credit card via e-mail or are they wrong for being so lax in their IT security procedures? They told me that this process has been approved by their IT and finance departments!
    email is slightly less secure than a postcard, in terms of keeping details hidden.

    anything you wouldn't write on a postcard for everyone at Royal Mail to gawk at, you don't put in email.

    directhex is online now   Reply With Quote
    Old 16-08-2006, 10:14 AM   #7 (permalink)
    formerly |SilentDeath|
     
    Join Date: Aug 2003
    Posts: 4,715
    Thanks: 36
    Thanked 15 Times in 10 Posts
    phone them?

    or encrypt the email.
    SilentDeath is offline   Reply With Quote
    Old 16-08-2006, 10:56 AM   #8 (permalink)
    Meow.
     
    Mike Fishcake's Avatar
     
    Join Date: Jun 2005
    Location: Manchester
    Posts: 2,847
    Thanks: 65
    Thanked 86 Times in 44 Posts
    Do
    not
    do
    it.

    Mike Fishcake is offline   Reply With Quote
    Old 16-08-2006, 11:01 AM   #9 (permalink)
    A. Nother
     
    Join Date: Jul 2006
    Location: home
    Posts: 240
    Thanks: 2
    Thanked 4 Times in 2 Posts
    mallett's system
    you should never put any sort of persoanl details in emails as god knows who has access to them, id change travel agents if they dont sort it out
    mallett is offline   Reply With Quote
    Old 16-08-2006, 11:10 AM   #10 (permalink)
    HEXUS.social member
     
    Funkstar's Avatar
     
    Join Date: Aug 2005
    Location: Aberdeen
    Posts: 12,138
    Thanks: 172
    Thanked 297 Times in 267 Posts
    Funkstar's system
    i had to email or fax credit card info to the US for a subscription to a Banjo magazine (present for my cousin). Used a one time only card number from Cahoot and faxed it across. Not exactly practical for you though
    Funkstar is online now   Reply With Quote
    Old 16-08-2006, 11:29 AM   #11 (permalink)
    Taz
    Senior Member
     
    Taz's Avatar
     
    Join Date: Jan 2005
    Location: London
    Posts: 1,952
    Thanks: 34
    Thanked 21 Times in 20 Posts
    Taz's system
    I've asked for a fax number that will go to one person at the travel agent (i.e. not a general fax machine sitting by the water dispenser for example). If they can ensure reasonably secure receipt of a fax then i'm happy to do that.

    The problem is that this global travel agent is used by my company as the official travel agent. Hence, I cannot just go to another travel agent. Also, they won't accept a profile change over the phone.

    My best bet is to just post a letter to them (as I did before), assuming they will accept this but it seems that they *only* accept profile changes via email, which is truly incredible!
    Taz is offline   Reply With Quote
    Old 16-08-2006, 11:48 AM   #12 (permalink)
    Meow.
     
    Mike Fishcake's Avatar
     
    Join Date: Jun 2005
    Location: Manchester
    Posts: 2,847
    Thanks: 65
    Thanked 86 Times in 44 Posts
    Taz - I seriously think you need to write the company a letter of complaint, and quote several official documents that highlight the insecurity of email, and the gross misinformation that has the potential to endanger the financial details of all of their customers that have used the scheme.

    Encouraging someone's customers to email credit card details is surely corporate negligence?

    Mike Fishcake is offline   Reply With Quote
    Old 16-08-2006, 12:00 PM   #13 (permalink)
    A Straw? And Fruit?
     
    Bazzlad's Avatar
     
    Join Date: Jul 2003
    Location: The Big Rhesus House Stourbridge
    Posts: 3,006
    Thanks: 82
    Thanked 58 Times in 39 Posts
    Is this a joke?
    I'd prefer to find a shaddy looking man in a pub and hand him £100. Don't be dumb.

    Rhesus - My band.
    Feisty 2007? I OWNED it.
    Bazzlad is offline   Reply With Quote
    Old 16-08-2006, 12:10 PM   #14 (permalink)
    Crazy HEXUS.net
     
    Stoo's Avatar
     
    Join Date: Jul 2003
    Location: The Void.. Floating
    Posts: 10,417
    Thanks: 27
    Thanked 60 Times in 48 Posts
    Stoo's system
    I've done it before, but I've split the details into 3 separate emails, better than nothing, but still not recommended..

    Originally Posted by silent ben
    Nanotechnology is going to be huge.
    Stoo is online now   Reply With Quote
    Old 16-08-2006, 12:17 PM   #15 (permalink)
    TALK TO ME
     
    Agent's Avatar
     
    Join Date: Jul 2003
    Location: Internet
    Posts: 14,245
    Thanks: 257
    Thanked 421 Times in 323 Posts
    Dont they have anything like PGP ?

    Agent is offline   Reply With Quote
    Old 16-08-2006, 12:26 PM   #16 (permalink)
    A Straw? And Fruit?
     
    Bazzlad's Avatar
     
    Join Date: Jul 2003
    Location: The Big Rhesus House Stourbridge
    Posts: 3,006
    Thanks: 82
    Thanked 58 Times in 39 Posts
    if it's going to the IT department write it in binary.

    Rhesus - My band.
    Feisty 2007? I OWNED it.
    Bazzlad is offline   Reply With Quote
    Reply

    Breadcrumb
    Go Back   HEXUS.community discussion forums > HEXUS.channels > General discussion


    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Trackbacks are On
    Pingbacks are On
    Refbacks are On
    Forum Jump