* Posts by RSProutt

3 publicly visible posts • joined 19 May 2020

Down and out: Barclays Bank takes unplanned digital detox, customers not invited

RSProutt

Re: They don't want to listen

@munnoch

What would you have expected any Bank to do once they have been notified that some of their issued credit cards could be compromised ?

If they gave all customers a few weeks warning of the re-issue, that would give the criminals the time to go wild on the cards before the cards was cancelled, thus more customers being scammed, this is a rule set by the FCA, not the Bank. Any financial institute has to act in the best interest of their customers.

Those "re-issue decision" It is not as clear cut as you think.

As for Ticketmaster, they were compromised by running a 3rd party chatbot running on Ticketmaster website, that was poor decisions by not performing verification of 3rd party software running on Ticketmaster's website, and also Ticketmaster allowing the chatbot to run on the payment page.

Easyjet hacked: 9 million people's data accessed plus 2,200 folks' credit card details grabbed

RSProutt

Re: OK, hands up ..

The main website uses tokenisation of Credit Card details.

If it wasn't then all customers details would have gone, this is most likely some 3rd party site which provides a service to EasyJet. Although it is still EasyJet who is responsible.

RSProutt

Re: Other reports are saying they became aware of this in January

You will find that it is not be that the Security Team being "lazy",

What you will find that the Management has chosen not to implement certain Security controls in for "Business Reasons" even though the Security Team has demanded it.

You will find that the Business will have a high turnover of Security Team as people join, try and do their best to secure the Business, then realise that the Management are not on board.