Mountain Bikes · Public discussion

Middleman Registration

Started by Corvus Corvax · · Last activity · 28 posts · 905 views

Thread navigation

Jump through the discussion

Go to the original post, the replies on this page, or the latest preserved contribution.

Thread details

What we know about this thread

Original section
Mountain Bikes
Published
1 June 2005
Last activity
2 June 2005
Original author
Corvus Corvax
Posts
28
Discussion status
Public discussion
Total views
905
Views / 30 days
0

The navigation and discussion metadata provide context. Posts remain in their original chronological order.

Showing posts 21–28 of 28
Posts remain in their original chronological order.

Text size
  1. Corvus Corvax said:
    MattB said:

    All you can do is take reasonable care. This company is well-respected
    and your choices are to hope they play nice with your data (most likely
    they will) or to bag it (and lots of other things because this is now
    how business works these days). If they were careless they'd be out of
    business pretty quickly.

    This is a fact. One can't do business without exposure, obviously.

    Quoted message said:

    You know these guys are a third party because they make it obvious. If
    you've signed up for more than a couple of things online directly with a
    company chances are you've used a third party then, but they just
    decided that they didn't want to reveal that to you. It's a very common
    practice.

    This is an excellent point as well. But in this circumstance the
    security issues are different because the middleman is not making the
    transaction (or registration) information available online via a logon.
    Also, as I pointed out to the gentleman who cannot tell haiku from free
    verse, the nature of the information involved is different. The race
    registration contains information I _never_ give to online vendors. I
    want the promoters to have my wife's cell phone number in case I am
    injured. But she doesn't want it in bikereg.com's marketing database,
    now does she?

    I'm going to hold my nose and give them what they want. But the thing
    that astounds me is the number of people who, like Ride-A-Lot or the
    people who run bikereg.com, make their living running online
    transaction sites who obviously do not think deeply about security
    issues. For example, business and university sysadmins who routinely
    use your social security number as a personal ID. Another relevant
    example is somebody who asks for your birth date when simply asking for
    age would do the same job without compromising data used by (for
    example) credit card companies as confidential security info. I mean,
    why would anybody hack a bike race site, right? Anybody who says that
    isn't thinking.

    Whenever I fill out any form, online or not, I ask: why do they want to
    know this, and is it any of their business? Often it isn't. I've been
    asked to show a driver's license to return a pair of shorts to the
    store. This kind of thing is becoming increasingly common, largely
    because of people who just shrug and say "what's the diff?"

    CC

    Those are reasonable gripes. Maybe you should call them and ask why they
    need the non-necessary information. Maybe they never thought about it
    and just decided to make everything required "just in case". Bringing it
    to their attention may get it addressed (or may not, but what can it
    hurt?). Maybe you can opt-out of being in their marketing database, or
    maybe they don't even have one. Chances are, they market to promoters,
    not individual competitors. If they just sell their database then they
    are the scum of the Earth, but I really doubt they could get away with
    doing that more than once before causing an huge outcry. That became an
    industry no-no very quickly several years ago and companies generally
    don't get away with it anymore.
    FWIW an application I wrote collects birthdays instead of age for people
    buying ski passes. The reason being, this system calculates your age at
    the time or purchase and if you just offer your age we can't accurately
    calculate it when you renew in the future, or based on some arbitrary
    date like the beginning of the ski season.
    It's good to wonder why a piece of information is needed. Sometimes it
    isn't, and sometimes it is but maybe it's not an obvious reason. I agree
    the old practice of using your SSN as your login name is terrible. They
    did that when I went to school (so I could log on to the VAX) and I had
    no say in the matter. At the time I didn't think much about it because
    the Internet was an experimental thing that the public didn't know
    existed. Now I'd be [censored] and would raise a stink.
    Times have changed...

    Matt

  2. MattB said:

    I agree the old practice of using your SSN as your login name is terrible. They
    did that when I went to school (so I could log on to the VAX) and I had
    no say in the matter.

    Ah, VAXen. Brings me back.

    Many moons ago at University of Montana, back in the day when you got
    allocated "time" on a mainframe that ran out incredibly quickly when
    you played a lot of Adventure, I used to hoover up computer time using
    the following method. Your student ID was your social security number.
    Computer accounts created for students in programming classes used the
    social security number as both account name and initial password. I
    would just cruise the halls of the computer science department right
    after the first round of midterms and read the grades posted on the
    professors' doors. I would write down all the ids of students who had
    not showed up for the first midterm. Nine out of ten times, they had
    never logged in to their course accounts, and I had as much free
    computer time as I wanted.

    CC

  3. Corvus Corvax said:


    MattB said:

    I agree the old practice of using your SSN as your login name is terrible. They
    did that when I went to school (so I could log on to the VAX) and I had
    no say in the matter.

    Ah, VAXen. Brings me back.

    Best computer ever made (along with VMS as the OS), IMHO! To this day
    the DEC Alpha chip remains the fastest processor technology. Intel
    still hasen't come close and Compaq through it all away. What a shame!

    --
    o-o-o-o Ride-A-Lot o-o-o-o
    www.schnauzers.ws

  4. Corvus Corvax said:


    MattB said:

    I agree the old practice of using your SSN as your login name is terrible. They
    did that when I went to school (so I could log on to the VAX) and I had
    no say in the matter.

    Ah, VAXen. Brings me back.

    Many moons ago at University of Montana, back in the day when you got
    allocated "time" on a mainframe that ran out incredibly quickly when
    you played a lot of Adventure, I used to hoover up computer time using
    the following method. Your student ID was your social security number.
    Computer accounts created for students in programming classes used the
    social security number as both account name and initial password. I
    would just cruise the halls of the computer science department right
    after the first round of midterms and read the grades posted on the
    professors' doors. I would write down all the ids of students who had
    not showed up for the first midterm. Nine out of ten times, they had
    never logged in to their course accounts, and I had as much free
    computer time as I wanted.

    CC

    Ah, so you're a hacker yourself! Stop! Thief!

    CSI students at WSC (here in Gunnison) got virtually unlimited time on
    the VAX, but if you really used up a ton they'd tell you to back off.
    I never got into gaming much, so it wasn't much of an issue for me.
    I did freak them out by requesting modem access so I could do my work
    from home instead of coming to the lab. Many hoops had to be jumped
    through to get that blazing 2400 baud access (and the nay-sayers said
    "you can't emulate a real VT52 on a friggin' Mac!"😉. Of course then I'd
    use Kermit and download cool stuff for my Mac+ from other, more
    progressive institutions, which would take all night.
    I hated the CSI profs who would insist I turn in my assignments on
    greenbar, because that required a trip to the lab to use the tele type.
    The cooler profs would accept stuff on plain old fanfold 8.5x11.

    Ah, those were the days!

    Matt

  5. MattB said:
    Corvus Corvax said:


    MattB said:

    I agree the old practice of using your SSN as your login name is
    terrible. They
    did that when I went to school (so I could log on to the VAX) and I had
    no say in the matter.

    Ah, VAXen. Brings me back.

    Many moons ago at University of Montana, back in the day when you got
    allocated "time" on a mainframe that ran out incredibly quickly when
    you played a lot of Adventure, I used to hoover up computer time using
    the following method. Your student ID was your social security number.
    Computer accounts created for students in programming classes used the
    social security number as both account name and initial password. I
    would just cruise the halls of the computer science department right
    after the first round of midterms and read the grades posted on the
    professors' doors. I would write down all the ids of students who had
    not showed up for the first midterm. Nine out of ten times, they had
    never logged in to their course accounts, and I had as much free
    computer time as I wanted.
    CC

    Ah, so you're a hacker yourself! Stop! Thief!

    CSI students at WSC (here in Gunnison) got virtually unlimited time on
    the VAX, but if you really used up a ton they'd tell you to back off.
    I never got into gaming much, so it wasn't much of an issue for me.
    I did freak them out by requesting modem access so I could do my work
    from home instead of coming to the lab. Many hoops had to be jumped
    through to get that blazing 2400 baud access (and the nay-sayers said
    "you can't emulate a real VT52 on a friggin' Mac!"😉. Of course then I'd
    use Kermit and download cool stuff for my Mac+ from other, more
    progressive institutions, which would take all night.
    I hated the CSI profs who would insist I turn in my assignments on
    greenbar, because that required a trip to the lab to use the tele type.
    The cooler profs would accept stuff on plain old fanfold 8.5x11.

    Ah, those were the days!

    Matt

    Wow! Similar situation here. 1982 and two months after the IBM PC was
    introduced, I am in Ohio Univerisity with a computer. Out of 16,000
    students that year there were two of us with our own computers. I
    actually became a student teacher in my freshmen year for Intro to Micro
    Computers since I finished all the assignments in the first two days of
    the class. I also had to beg for VAX dialup, but being in with the
    Profs helped that one. There's nothing like being able to work on
    assignments at your leisure (in the dorm room with beer) when people are
    lined up for an hour to get to one of 15 terminals.

    --
    o-o-o-o Ride-A-Lot o-o-o-o
    www.schnauzers.ws

  6. Per Corvus Corvax:

    Quoted message said:

    So. Point of discussion. Why should anyone trust these guys with all
    that information?

    Naivete or ignorance.
    --
    PeteCresswell

  7. Per Ride-A-Lot:

    Quoted message said:

    Cause you want to do it and they have the contract with the promoters.
    I also suppose they need more pertinent info to cover theirs (and the
    promoters) asses. What if you get hurt and are not conscious? They all
    ask for this info.

    The one that would have gotten my attention was the credit card info.

    I gave mine to VeriSign last year and was rewarded with a repeating fradulent
    charge about six months later. Everybody had a story....but bottom line is
    that a third party harvested my credit card number and made up some BS service
    and started charging me for it.
    --
    PeteCresswell

  8. (PeteCresswell) said:


    Naivete or ignorance.

    Nice to see I'm not the only member of the tinfoil hat brigade around
    here.

    CC

Active in the last 60 minutes

Active in this thread

0 users · 0 guests ·0 bots ·0 total

No signed-in users are active right now.

No known search crawlers active right now.