Thursday 29 September 2016

About the security of online services

Some time ago, I started receiving in my Gmail inbox notifications of purchases from the Playstation Network... the thing is: I neither have a Playstation nor registered an account on that network!

My Gmail account has been protected for a long time with 2-factor authentication; therefore, I was not worried about the security of my account.
Those emails are just the annoying consequence of at least two facts:
- A dumb user who cannot remember or type their email address correctly.
- An online service that does not care to verify the email address during the registration process.

Since I considered it not worth digging into the support pages of PSN to search for a solution, I initially decided to add a filter to Gmail to delete those emails automatically.

Last week, I received a welcome email from Uber and, soon after, a receipt of my very first trip around Philadelphia (US).
Again, even though I suppose it is a lovely place to visit, I have never been to Philadelphia!
And I never registered an account with Uber.

Same as above, someone used my email to register an account (same person? no way to know).

As I got annoyed by these notifications, I have decided to spend one evening trying to find a way to either delete these accounts or disable the notifications.

Uber

After reading throughout their support site, I finally landed on the page to delete an account.
To delete the account, you first have to log in.
You might ask how I can log in if I did not create the account in the first place? Easy: request a password reset!
I reset the password, logged in, and finally clicked on the button to delete the account.
Ridiculous.


PSN

Here the problem is finding the support page. After a good thirty minutes in the forum, I found a link to the US online support live chat.

Being outside the US, a message on the waiting page informed me the service was not available, and I had to contact the Support Team for my country.

Select your country on this page:

https://www.playstation.com/country-selector/


Then scroll to the bottom of the page and click on Support (this is the UK Support page)


Search for "chat".


This is the link to the UK Live Chat.


Since the service is available from 10:30 to 19:00 Monday to Saturday, I will contact them tomorrow and hopefully find a solution.


What amazes me is the total lack of verification from these services. I could not access any sensitive information regarding these persons, but in the Uber case, I could find where this person has been in the last two weeks - not what I define as privacy.


The bottom line is: for the services you care about, always enable the 2-factor authentication and try and change your password as often as possible!

No comments:

Post a Comment