Recently (yesterday), I emailed an hotel requesting them to make a booking for 6 months in the future. They emailed back asking me to confirm by sending them details of my credit card. Now I am concerned as to what they are going to do with these details for the next 6 months. Am I paranoid in fearing that their security may not be up to preventing one of their staff stealing this information, in the interim, with fearsome consequences?
I admit that, had they merely asked for a deposit, I would almost certainly have completed that transaction by credit card. Now, I am afraid to even do that.
Didn't find your answer? Ask the community — no account required.
T
Tim
"GPG" wrote
So, did you *email* them back your credit card details?
"GPG" wrote
If you *emailed* them the details, you should worry about eavesdroppers on the internet intercepting the details on the way to them...
R
Richard B.
They will presumably hold the details in their system so that if you don't show, they will still be able to deduct the relevant amount, in my experience usually the cost of the first night's accommodation.
Is the hotel a well known one, or part of a chain of hotels which is well known? If so I shouldn't worry too much.
Asking for a cc number to secure a room seems to be standard practice for the Travelinn, Travlelodge type hotels.
Rgds Richard Buttrey __
T
Tumbleweed
Yep, you are being paranoid. The 6 month issue is irrelevant. What about the many years afterwards? Do you think they delete your credit card details the night after you've stayed? What about booking *anything*, holidays, flights etc, months in advance? And after you've had the holiday, do you then worry that they still have your details and are off to harrods? Better go to cash only so you can sleep easy at night.
J
Jon Green
No, but if they're asking you to email the credit card information, you should be contacting their fraud department, because no reputable organisation (except one with bent employees) would be asking for CC information to be submitted by such insecure means.
And if *they* say it's OK, I'd suggest you publicise the hotel, their emails, and all contact you've had with them -- and under no circumstances deal with them!
Jon
T
Tumbleweed
IME its quite common with small hotels and ones where internet bookings are the exception rather than the rule. In reality there is only a minor additional risk, which is that the email might be intercepted in transit, (in practice a vanishingly small risk), especially compared to the fact that every day many people will see your credit card details....shop assistants, petrol station assistants, checkout operators, and all the numerous 'back office' staff of the companies with which you do business.
Put in another way, suppose you phoned them your cc number? No one would blink an eye over that, but arguably its easier to intercept or overhear a telephone call than an email (and maybe the entire call is recorded 'for customer training'), and who knows how they conduct the transaction..maybe they type the details straight in, maybe its written in a book, maybe its on a post-it note on their screen to be entered later. Or suppose you send it to them in a letter....same thing applies, probably easier to steam open a letter, and the letter probably remains on file, in a form that can be easily accessed (Mk 1 eyeball) compared to password protected email....or maybe they type the details in and then chuck your letter in the bin where anyone who delves into their garbage can read it.
Yet people get all antsy about cc nos in emails as if otherwise there is no way they can be accessed. I am willing to believe that on your planet unless credit card details are in emails there is no way they can be accessed illegally and they are totally secure. However, here on planet Earth this is incorrect.
B
BrianW
There's a new airline advertising free flights to Poland (I forget its name). When you attempt to book, you are directed to a non-secure web page (not https, and no padlock) to enter your credit card details (presumably for tax). Leaving aside how an airline can stay in business if it gives away all of its flights, it's _never_ a good idea to send details such as this unless they are encrypted. Brian
J
Jon Green
In that case, assuming the call wasn't placed using an insecure wireless connection, it's effectively a point-to-point connection, and you've chosen the number to call, so you're likely to have called their front office number. There will be security: call recording, supervisor oversight, and so forth. Yes, there's a certain risk of fraud, but not much. Personally, I wouldn't telephone my details to a company I didn't already expect to have such precautions in place.
The Internet isn't point-to-point. An email from A to B passes over a number of network links, any one of which can be storing or snooping passing packets. I know, I've done it for professional (and above board) reasons, and it's astounding what people will entrust to such an insecure connection.
Furthermore, you leave a copy of your CC information in your "Sent mail" folder, on your machine (for a service technician or a thief to find) or webmail system (for a sysadmin to find -- admittedly lower risk).
If you really don't care about your credit card info, feel free to go to one of those business card printing machines, work up fifty copies of your CC info, and hand them out to strangers in your local shopping mall on a Saturday. That's effectively what you do when you email those details.
Perhaps you should email all the banks and CC companies, and tell them that, despite all the anti-fraud material they've been putting out for the last few years, in your expert opinion it's actually safe to send your financial details unencrypted. I've a notion that you'd not get a very impressed response. Perhaps they might know more about financial security, and the attendant risks, do you not think?
The final arbitors of what's acceptably secure are the merchant services providers. They put up with customer-not-present phone transactions, but I don't think you'll find many that are happy about solicitations for CC information over email.
Jon
J
Jon Green
Amen to that.
It might be worth pinging The Register
formatting link
or The Inquirer
formatting link
about that airline, by the way. They love stories like that, and a touch of name-an'-shame wouldn't go amiss.
Jon
N
nenieorg
Jon Green:
So does a phone call nowadays. There are not that many mechanical exchanges left. Someone with access to one the path's telcos' systems is in the exact same position as someone with access to one of the internet routers or email servers that carries the email.
Telcos' voice networks might be a bit more secure than the internet, but the big difference is not going to be there, but in that a phone call is voice, and while finding card numbers in unencrypted email or other text traffic automatically is trivial, finding one in voice calls is going to be much more hassle, so not worth doing when there are lower hanging fruits.
To that extent an unencrypted Voice-over-IP call on the internet is going to be nearly as safe as a call on the old phone network, and more immune to low tech wiretapping from the street cabinet incidentally.
J
Jon Green
It's not really comparable. Anyone, pretty much, can route IP. There's no OFCOM oversight, there's no Governmental regulation (well, not to the same extent as telecoms operators), you just need to be operating a LAN, a WAN or a trunk network that's in the way of the packets going from A to B, and be in possession of a copy of Ethereal (etc.).
Quite.
Agreed. I'm not sure I'd want to use unencrypted VoIP anyway. Skype's my current tool of choice
formatting link
and that's encrypted end-to-end.
Jon
U
usenet
Although in reality it's doubtful if it's actually any less secure than dictationg your credit card details to someone over the phone.
Are there actually any documented cases of credit card fraud by getting details from an E-Mail?
Join the Discussion
Have something to add? Share your thoughts — no account required.
Didn't find your answer?
Ask the community — no account required
Report Content
You are reporting this content to the moderators. They will look at it
ASAP.