Saturday, December 10, 2005

Poorly designed online interfaces make identity theft simple

Risks Digest is a good source of information on all sorts of risks -- including privacy risks. Recently, Marty Lyons posted the following about a particular experience he had renewing this AAA membership.

The Risks Digest Volume 24: Issue 11:

"I recently had to renew my membership with the American Automobile Association (the equivalent to the CAA in Canada, or the RAC in the UK). In the past there was no web interface, but AAA has now moved online. To sign up for an account, I needed to supply a membership number (printed on your plastic member card), and my name (also printed on the card), along with an email address, and a chosen account name. A few seconds later, I was logged in, and was able to check my account info, including mailing address, and type of credit card used for membership.

There was no verification of identity at all during account establishment. At a minimum, mandating that a user-entered postal code match the AAA database prior to creating the account would have afforded some protection.

So with a AAA member number and name, someone is well on their way to identity theft -- the rest of your wallet not required. Since many places take AAA cards to provide discounted services (hotels, car repair, restaurants, movie theatres, etc.) you can imagine the RISK. I've sent a letter to the organization letting them know their web registration needs to be redesigned."

I am not sure someone can steal your identity using your AAA membership, but interfaces like this attached to something more sensitive may lead to big problems.

