Tag Archives: Privacy

Is It Safe To Give Out your CVV Code?

If you’re a regular online shopper like me, you’re sure to be familiar with your credit card security code – otherwise known as the card verification value (or CVV).

If not, you can find the 3-4 digit code on the back of your VISA/MasterCard (the final 3 digits of the number printed on the signature strip) or on the front of your Amex card (the separate 4 digit code above the card number).

 

The intended purpose of the CVV is to provide added security when making purchases over the internet – it helps to verify that you’re in possession of the card, as the code shouldn’t be known to anyone other than you as the card holder. So it’s essentially a way of counteracting credit card fraud.

 

Is it safe to give out your CVV?

For online shopping, the answer is generally yes – it’s just simply a good idea to stick with well-known, reputable companies that you trust. You’ll find that most online retailers nowadays do require a CVV for purchases, which is encouraging because it means that they’re actively trying to prevent fraudulent transactions occurring on their site.

You may also be asked for your credit card security code when processing a payment over the telephone. As with online transactions, it’s usually safe to do this – you just need to be sure that no one overhears the details you give out (so avoid public places when doing this).

On the other hand, when purchasing an item or service in person, you should never provide the details of your CVV. In fact, there’s no need for the retailer or service provider to request this – it doesn’t show up when the card is scanned normally and they have other ways of verifying that you’re the authorised card holder (signature or another form of identification) should they need to.

Handing over your CVV for purchases completed offline serves no purpose other than providing someone with the opportunity to steal the information. Because if they were to do this, they’d have everything they need to go ahead and make a bunch of fraudulent online transactions – on you!  

Tips for staying safe

To avoid any issues with security or credit card fraud, there are a few things you can do:

  • Only transact with reputable websites that you trust. And when you do, follow our 10 golden rules for safe online shopping.
  • Install internet security software on your PC, tablet and/or smartphone. Doing this will help you steer clear of malware and phishing messages that could lead you to fake websites designed to steal your personal details.
  • Always keep a close eye on your bank statement to identify any charges that haven’t been authorised.   
  • Never read out the full details of your credit card in a public place, or write them down anywhere for someone else to find.
  • Avoid making payments over the phone with a credit card, unless you make the call directly and obtain the number from a trusted source. Scammers have been known to cold call victims and convince them that money is owed immediately for a problem that doesn’t exist!
  • Don’t provide your CVV when processing a payment in person. It should never be required and if someone tells you otherwise, it’s a reason to be highly suspicious!   

Have you had any dramas when using your credit cards online? Share your story with us below.

The web gets ready for voice recognition

News broke earlier in January that Facebook has acquired Wit.ai, an 18 month old startup that specializes in voice recognition technology. At first, this might seem like a strange move but upon closer inspection, the rationale is clear.

Millions of users are turning to mobile as their preferred platform, where typing long messages and interacting with friends is far more challenging than on a PC keyboard.

It’s clear that companies like Facebook face a challenge to make mobile interaction easier and more engaging.

Using Wit.ai’s expertise, Facebook can build a mobile-first platform with a voice activated interface and text-to-speech messaging some obvious steps.

The Facebook acquisition highlights the excitement and potential behind voice recognition technology. We are potentially witnessing a fundamental shift in the way we interact with our technology forever.

As we start integrating voice activated functionality into new smart devices and services we use on a daily basis, my primary concern isn’t one of convenience but of security.

As I wrote in this blog in September 2014, there is much work to be done in securing our digital devices from voice commands.

Most voice recognition technologies scan commands for meaning and then execute them. I believe there is a need for an additional step, one of authentication.

Does the person issuing the command have the authority to do so? When I ask the device to execute a command, does it validate that it is really me and not someone else?

As I demonstrate in the below video, it is quite simple to have a device act upon a voice command issued by a synthetic voice or by a 3rd party that has an access to the device – even remotely:

Video

Voice hacking a device

 

As Facebook and other leading companies add more voice activation technologies to their roadmap, it’s important to realize that we are also increasing the number of services and devices that are potentially vulnerable to voice attacks. So considering this, , let’s build it with safety in mind.

The arrival of toy drones

Drones have landed – as one of the hottest gifts over this past holiday season and one of the biggest hits at the 2015 Consumer Electronics Show this past week.

Unmanned aircraft systems (UAS), as they are also known, are like model airplanes on steroids. They can hover, fly and often come equipped with cameras. They can belong to you or anyone else for under $100 dollars.

The cheap availability and growing capabilities of drones means that there are privacy and safety issues at stake.

We’ve already seen drones experience near misses with aircraft at major airports while unmanned flying cameras are an obvious threat to privacy.

It’s clear that drones are going to be around for a while and that legislation is needed to set reasonable and responsible limitations for recreational drone use.

However, regulation is still very much up in the air, if you’ll pardon the pun.

 

Who is taking action on drones?

The U.S. Federal Aviation Administration has issued a list of do’s and don’ts for flying safety regarding model aircraft for recreational use. These mostly focus on keeping them away from flying aircraft, airports and within sight line of the user. (See guidelines here.)

National Parks Service has banned drones from all National Parks, worried that the noise and proximity to wildlife would disturb nesting, migratory, and reproductive habits. The NPS also noted visitor safety was an issue.

Drone industry officials announced that they are teaming up with the government and model aircraft hobbyists to launch a safety campaign, which includes a website (www.knowbeforeyoufly.com) that includes safety tips and FAA regulations.

In the U.K, the Civilian Air Authority has already set protocols, mostly involving flying over congested areas and airspace, and the European Aviation Safety Agency is developing EU-wide safety standards which reportedly will be as high as those for manned aircraft.

Commercial use of drones has become a thorny subject and there is pending legislation in U.S. Congress that might even require commercial drone operators to have pilot licenses.

With all this legislation in the works, it’s clear there’s a lot more to this year’s hot toy story than first meets the eye. And you can bet there’s going to be a lot more to come…

Title image courtesy of firstsing

The drones are coming, what could go wrong?

Continuing from Consumer Electronics Show 2015 here in Las Vegas where we were covering this week the first impresisions of the show and also some lessons that this digital invasion is leaving us. Now, we will approach another interesting topic that involves privacy and new technology: drones.

The post The drones are coming, what could go wrong? appeared first on We Live Security.