Corvus Corvax said:MattB said:All you can do is take reasonable care. This company is well-respected
and your choices are to hope they play nice with your data (most likely
they will) or to bag it (and lots of other things because this is now
how business works these days). If they were careless they'd be out of
business pretty quickly.This is a fact. One can't do business without exposure, obviously.
Quoted message said:You know these guys are a third party because they make it obvious. If
you've signed up for more than a couple of things online directly with a
company chances are you've used a third party then, but they just
decided that they didn't want to reveal that to you. It's a very common
practice.This is an excellent point as well. But in this circumstance the
security issues are different because the middleman is not making the
transaction (or registration) information available online via a logon.
Also, as I pointed out to the gentleman who cannot tell haiku from free
verse, the nature of the information involved is different. The race
registration contains information I _never_ give to online vendors. I
want the promoters to have my wife's cell phone number in case I am
injured. But she doesn't want it in bikereg.com's marketing database,
now does she?I'm going to hold my nose and give them what they want. But the thing
that astounds me is the number of people who, like Ride-A-Lot or the
people who run bikereg.com, make their living running online
transaction sites who obviously do not think deeply about security
issues. For example, business and university sysadmins who routinely
use your social security number as a personal ID. Another relevant
example is somebody who asks for your birth date when simply asking for
age would do the same job without compromising data used by (for
example) credit card companies as confidential security info. I mean,
why would anybody hack a bike race site, right? Anybody who says that
isn't thinking.Whenever I fill out any form, online or not, I ask: why do they want to
know this, and is it any of their business? Often it isn't. I've been
asked to show a driver's license to return a pair of shorts to the
store. This kind of thing is becoming increasingly common, largely
because of people who just shrug and say "what's the diff?"CC
Those are reasonable gripes. Maybe you should call them and ask why they
need the non-necessary information. Maybe they never thought about it
and just decided to make everything required "just in case". Bringing it
to their attention may get it addressed (or may not, but what can it
hurt?). Maybe you can opt-out of being in their marketing database, or
maybe they don't even have one. Chances are, they market to promoters,
not individual competitors. If they just sell their database then they
are the scum of the Earth, but I really doubt they could get away with
doing that more than once before causing an huge outcry. That became an
industry no-no very quickly several years ago and companies generally
don't get away with it anymore.
FWIW an application I wrote collects birthdays instead of age for people
buying ski passes. The reason being, this system calculates your age at
the time or purchase and if you just offer your age we can't accurately
calculate it when you renew in the future, or based on some arbitrary
date like the beginning of the ski season.
It's good to wonder why a piece of information is needed. Sometimes it
isn't, and sometimes it is but maybe it's not an obvious reason. I agree
the old practice of using your SSN as your login name is terrible. They
did that when I went to school (so I could log on to the VAX) and I had
no say in the matter. At the time I didn't think much about it because
the Internet was an experimental thing that the public didn't know
existed. Now I'd be [censored] and would raise a stink.
Times have changed...
Matt