Skip to main content

NETELLER - Privacy and security design flaw

Yesterday, colleague of mine brought to my notice about a payment system called NETELLER and it's merchant API named NETELLER Direct API V4.

This NETELLER Direct API V4, helps the merchant to collect amount from users. It's simple--same just like early Authorize.net, along with the required amount you collect the user's id and password and post them to their API URL and they'll send you back with success or error codes in XML format.

The major problem with these types of system is security and privacy--you lose both as you're forced to type your username and password in alien web page. If I remember right, this is was the case with Authorize.net and they changed their design to something like PayPal. The PayPal design is somewhat better as you never type or forced to type your username and password in other alien web pages.

The alien merchant web page uses NETELLER Direct API V4 is forced to get user's NETELLER account and password. I'm much sure that the alien website will obviously store such info--but what if they tried to access user's NETELLER account?

The funniest part of this NETELLER design is that they call it more secure and in their security page they advice "Never share your NETELLER Password or Secure ID with anyone. You will never be asked to disclose your password or Secure ID by a NETELLER representative or anyone affiliated with NETELLER."

Beware of NETTELLER!--until they fix their design flaw.

Comments

Popular posts from this blog

The Overrated Tamil Culture

Since the COVID period, I developed an interest in exploring old books from the 1700s to the 1900s through Google Books. I first focused on the celebrated Protestant missionary Ringeltaube, but over time, my curiosity expanded toward understanding the demographics and social practices of that era. In Tamil Nadu, what is often celebrated as "Tamil Culture" revolves around the practice of monogamy, known locally as à®’à®°ுவனுக்கு à®’à®°ுத்தி — meaning one woman for one man. Some even compare this tradition with practices in other states, claiming Tamil culture is especially unique. This sense of pride is particularly strong around Madurai, where people often refer to themselves as “pure Tamil” when compared with neighboring regions like Kanyakumari, whose people they call Malayalis. What’s striking, though, is that this proud image doesn’t always align with historical accounts. A book published in 1885 (I’ve chosen not to mention its title or link to avoid stirring controversy) ma...

Interview question #2

This is related to PHP's array . An array has number of elements. All elements are integers and unique, which means there is no repetitive integers. (e.g.) $foo = array(7, 5, 9, 13, 2, 8); You have to sort the array, provided: You should scan the elements only once. You're not allowed to compare the elements when sorting. (i.e., you're not supposed to use any comparison operators) Sorted resultant array may not be the source array. How will you do that?

Who is RJ Joshua and where is he?

After I have given my Humble Award to RJ Joshua , I have noticed that many people are visiting my blog when they're searching his name in search engines. I used to listen to his English programs on AIR Chennai FM sometime ago; but couldn't get his details on the internet for a long time. Recently I have spotted his photo in potofthots.com and I have stolen that photo too:-) Hope, this little photo of him (with Sanjay Pinto sitting in front) would give good feeling to his fans and well-wishers.