{"id":1848,"date":"2016-01-15T01:02:28","date_gmt":"2016-01-14T23:02:28","guid":{"rendered":"http:\/\/www.greenman.co.za\/blog\/?p=1848"},"modified":"2016-01-15T01:13:04","modified_gmt":"2016-01-14T23:13:04","slug":"trust-us-were-a-payment-gateway","status":"publish","type":"post","link":"https:\/\/www.greenman.co.za\/blog\/?p=1848","title":{"rendered":"Trust Us, We&#8217;re a Payment Gateway"},"content":{"rendered":"<p><img decoding=\"async\" src=\"http:\/\/www.greenman.co.za\/blog\/wp-content\/uploads\/2016\/01\/Boule01.jpg\" alt=\"\" \/><\/p>\n<p>A friend told me today about an experience of attempting to book a flight on <a href=\"http:\/\/www.kulula.com\/\">kulula.com<\/a>. His credit card wasn&#8217;t working, but there was an option for bank transfer (EFT), so he chose that.<\/p>\n<p>The EFT option used <a href=\"http:\/\/sidpayment.com\/\">SID<\/a>, a payment option promising secure EFT transactions. All good so far, so he followed the link.<\/p>\n<p>The SID window asked him to enter his bank account login details&#8230; You know, the kind you&#8217;re constantly warned about to never give to anyone and never to enter on any other site except your banks.<\/p>\n<p>I couldn&#8217;t believe that this is actually what happened (perhaps the friend had missed his morning coffee), so I checked it for myself. Looking into SID&#8217;s documentation, they claim to be externally verified, not to store the login details, and to use the bank&#8217;s own security system. But yes, you are asked to enter your bank account login details in their window.<\/p>\n<p>I&#8217;ve got no reason to doubt that SID does what it says, but the methodology seems hopelessly flawed.<\/p>\n<p>Let&#8217;s say I start a new payment system called SAD. At the same time I launch my casino website, relying on trusted SAD security. I state clearly that SAD uses the bank&#8217;s own security systems, and doesn&#8217;t store any of the login credentials. Totally secure!<\/p>\n<p>The transaction succeeds, and the customer has a credit to spend on my casino site. They spend many happy hours on my casino website, winning up a storm, and dreaming of their new Tesla. For some reason the cashout option isn&#8217;t working today, but check back soon&#8230;<\/p>\n<p>Some time later, they decide to check their bank balance, and find, to their horror, it&#8217;s all gone. They immediately phone their bank. Perhaps the conversation goes something like this:<\/p>\n<p>HORRIFIED CUSTOMER: There&#8217;s a transaction clearing out my entire balance! It wasn&#8217;t me! The transaction needs to be reversed!<\/p>\n<p>BANK: Hmm, our records indicate you logged in from internet banking, and transferred the money out. When was the last time you remember logging in?<\/p>\n<p>HC: Er, I logged in to winbigbillionscasino.com and made a R50 transfer to their account from my bank account, using the safe and secure SAD system.<\/p>\n<p>BANK: OK, no problem, we&#8217;re refunding the money now, apologies for the mistake.<\/p>\n<p>Or perhaps not&#8230;<\/p>\n<p>Perhaps the bank, in their charming and professional manner, laughs you off the phone and tells you you&#8217;re and idiot for giving your login details to another site.<\/p>\n<p>Merchants asking customers to trust them, assuring them that their bank details are secure, is a recipe for disaster. Just don&#8217;t do it.<\/p>\n<p>Related posts:<\/p>\n<ul>\n<li><a href=\"http:\/\/www.greenman.co.za\/blog\/?p=1734\">South African Banks SSL Security<\/a><\/li>\n<\/ul>\n<p><em><a href=\"https:\/\/commons.wikimedia.org\/wiki\/File:Boule01.jpg\">Image from Wikimedia Commons<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A friend told me today about an experience of attempting to book a flight on kulula.com. His credit card wasn&#8217;t working, but there was an option for bank transfer (EFT), so he chose that. The EFT option used SID, a payment option promising secure EFT transactions. All good so far, so he followed the link.&hellip; <a class=\"more-link\" href=\"https:\/\/www.greenman.co.za\/blog\/?p=1848\">Continue reading <span class=\"screen-reader-text\">Trust Us, We&#8217;re a Payment Gateway<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[7],"tags":[],"class_list":["post-1848","post","type-post","status-publish","format-standard","hentry","category-metal-technical","entry"],"_links":{"self":[{"href":"https:\/\/www.greenman.co.za\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1848","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.greenman.co.za\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.greenman.co.za\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.greenman.co.za\/blog\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.greenman.co.za\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1848"}],"version-history":[{"count":8,"href":"https:\/\/www.greenman.co.za\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1848\/revisions"}],"predecessor-version":[{"id":1857,"href":"https:\/\/www.greenman.co.za\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1848\/revisions\/1857"}],"wp:attachment":[{"href":"https:\/\/www.greenman.co.za\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1848"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.greenman.co.za\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1848"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.greenman.co.za\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1848"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}