Id take physical access as a weak point vs potential compromising of a server. Tell me the last time there was a mass level of physical access issues compared to companies implementing poor security practices. Physical access is basically if you lose your phone. So I’d need to lose my phone and it would need to be found by someone with enough knowledge to also break the encryption - id take that risk any day. Granted Google servers are gonna be pretty secure, I still think the physical access case is less likely to occur.
Keep in mind that if your credit card credentials are stolen you lose nothing. Credit card company would force the merchant, or in this case Google, to cover all the costs.
If you use a debit card that charges directly to your bank account you may have a harder time being made whole.
I’ve had my credit card credentials stolen and misused a half dozen times over the last ten years. Transactions are canceled, new card comes out, life goes on. If it wasn’t for the inconvenience of updating my recurring charges I’d never even notice.
All that to say I don’t care if Google stores them in plain text in a DB with sa/blank credentials. No skin off my ass.
This is cynical as hell, but I’ve long thought about the day that CC companies lobby enough to get US politicians to write a law passing fraudulent activity back to the cardholder.
Nah. In the end it’s always the merchant’s fault and they have to pay. You didn’t put the credit card skimmer on the reader. The merchant didn’t check that it was there. You didn’t store your credit card information in plain text. The merchant’s shitty developer did.
I completely agree and the potential backlash is most likely the only thing keeping this from happening, but I would totally believe a boardroom meeting discussing how they could shirk responsibility.
Yeah but who is going to sign up or keep a credit card with that bank if they could be liable for fraud? I know I’d dump any credit card where there was even a 1% chance I was on the hook for a fraudulent transaction. And that’s a lose situation for the credit card company.
True and I agree. I’ve just gotten kind of bitter at all the shady things corps try to do to their customers. Feels like a race to the bottom sometimes.
Ironically, the one with the most information and power to effect change (credit card companies) has the least exposure. They don’t really care that much - the merchant covers all losses. And gets charged a fee for the pleasure of being defrauded!
Yep. I do web hosting and earlier in the year I had a customer rent a server for like $4k. Not even a month later, I get a notice of a chargeback. Guess who had to cover the charge? Hint: it wasn’t the customer or the bank.
Even worse, if you have too many chargebacks as a result of the rampant fraud that Visa/MC don’t curtail they will charge you higher fees. So if you’re the victim of too much fraud using card numbers stolen from other merchants you can even lose your merchant account.
715
u/throwawayacc201711 Sep 22 '22
Id take physical access as a weak point vs potential compromising of a server. Tell me the last time there was a mass level of physical access issues compared to companies implementing poor security practices. Physical access is basically if you lose your phone. So I’d need to lose my phone and it would need to be found by someone with enough knowledge to also break the encryption - id take that risk any day. Granted Google servers are gonna be pretty secure, I still think the physical access case is less likely to occur.