funsec mailing list archives

Re: PayPal Plans Payments Via Text Message?


From: "Mark P. Fister" <mark () fister org>
Date: Fri, 24 Mar 2006 02:07:43 -0800

On Thu, Mar 23, 2006 at 01:32:19PM -0500, Valdis.Kletnieks () vt edu wrote:
Sorry - it's my *job* to think about how many different ways things can go wrong.
Since everybody else and their pet llama George picked up the *obvious* threat
there, I picked the less obvious "Paypal uses this as a new profit center" threat.

I didn't get the sense that you were talking about phishing with the comment, but were
trying to spread FUD about PayPal's policies because of the next sentence.  Regardless
of one's opinion of US legal and corporate environments (see the below quoted email),
all companies, regardless of country, are "in it to make money." PayPal, no different,
has gone to great strides to make all payment use cases:

A) Secure
B) Easy
C) Fast

and the mobile offering is no different.

To address phishing:

I won't.  It's a waste of my time due to the fact that mobile phishing won't be much
different than PC phishing.

In the current US legal environment, corporations are almost *forced* to be
malevolent for their own profit (as their responsibility is to the share
holders, not the customers).  As a result, when it comes down to a choice
between "a way to get another $4/year per customer" and "we do it for free and
swallow the costs because it's The Right Thing To Do", upper management will
almost certainly Do The Wrong Thing.

If faced with a shareholder lawsuit that alleges the management passed up an
obvious way to increase profits by $4/customer/year, across your tens of millions
of customers, what would the defense be?

-- 
Mark P. Fister
http://www.fister.org
Skype: callme://FisterDotOrg
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: