Advertisement
Promo

Online business Toolkit

Credit card cookie theft 'unlikely'

Jennifer Mack ZDNet.co.uk

Published: 06 Dec 1999 10:32 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Leading security experts have been quick to play down fears of a possible new form of online credit card theft that uses the cookie technology in Web browsers.

In recent days, it's been reported that Novell CEO Eric Schmidt believes his credit card number was stolen using a cookie, but that is an "unlikely" possibility, according to Paul Fahn, cryptographic analyst for encryption technology provider Certicom. "If the site is run properly and securely it should not be possible but with carelessly implemented security on a site it might be possible."

According to Fahn, the security risk is not so much with the cookies themselves as it is with the company a person is dealing with. Generally, cookies do not contain sensitive information like credit card numbers. Essentially, the information contained on a cookie acts as an account number which can be used to call up private billing information stored on an e-commerce site's secure server to enable faster ordering. According to security experts, the information contained on the cookie is basically useless unless someone is also able to break into a company's server, which should be protected. However, Fahn warns that whether a site is using the best security measures ultimately comes down to a matter of trust.

"The company is the one that controls what gets stored in the cookie file so if they store too much information then that's their fault," explained Fahn. "If this happened (a card number was stolen), it's the company's fault. It's the company's responsibility to protect the consumer against these types of attacks."

Schmidt was not available to discuss the details of how cookies were used to steal his card number, but Adam Shostack, director of technology for Internet privacy software company Zero Knowledge Systems, has his own theory on how the card may have been stolen. "It seems to me, that if his credit card number was stolen the likely places for that to happen would be some e-commerce site where he handed that information over to an insecure server or it was stolen by some clerk at a store or a waitress," said Shostack.

For David Sobel, general counsel for the Electronic Privacy Information Centre, an online privacy advocacy group, even the possibility that cookies could be used to steal credit card numbers demands action. "The technology is always going to be pushed to the limits in terms of getting information," Sobel said. "That means we need legal protections that keep pace with the technological changes."

According to Shostack, taking a "better safe than sorry" attitude is never a bad idea. He believes the best protection against possible misuse of information stored on cookies is knowing which companies are collecting your information, and taking control of how much private data is stored within your browser.

Shostack suggests using a cookie utility like "Cookie Crusher", which lets users see which sites are collecting information or "Cookie Cutter", which instantly erases all the cookies stored in your browser.

What do you think? Tell the Mailroom . And read what others have said.

See also: the e-commerce special .

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
24 out of 42 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:














Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

5 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters