Gone in 60 Nanoseconds
- 2002.08.13 - Tip Jar
Low End Mac Reader Specials
Memory To Go Special: New 2008 iMac 2GB $42 / iMac Intel Core2 DUO & MacBook Pro 2GB $36 - 1GB $20. MacPro 8 Core Memory 8GB kit $286 / 4GB kit $143 / 2GB kit $93 -- Free shipping available. LIfetime warranty.
Download Typestyler, still the Ultimate Styling Tool for Internet, Print and Video Graphics. Works great in Classic with a Native OS X Version on the way. Free Tryout: www.typestyler.com
LA Computer Company: Specials on AppleCare, iMac's, Apple Batteries and Apple A/C Adapters. Also Great prices on Used Apple Computers. Call 1-800-941-7654 Click Here.
OWC: OWC Mercury On-The-Go FW400/800/USB2/eSATA Portables High Performance A/V Rated, **Bus Powered** **Up to 500GB in the Palm of your Hand** Macworld Editor's Choice, CNET 'Very Good' - from $75.99!
Mac users can finally play Party Poker for Mac. Not only that, they can also learn how to play PokerStars for Mac.
Laptop Hardware Provided by TechRestore - Overnight Mac & iPod Repairs.
Compare products like desktop computers, laptops, and LCD TVs side by side! All the information and reviews to make the best purchasing decision for a new cell phone GPS products or MP3 players. The Ciao network makes searching products easy for you.
Over the last week or so, you have undoubtedly read of the frightening incident wherein the publisher of this site, Dan Knight, had his business PayPal account hijacked and cleaned out - and his bank account along with it. For those of us who regularly transact business on the Internet, this is a chilling story. Perhaps even more troubling is the fact that Dan took all the precautions and did everything right, but Low End Mac still got robbed.
PayPal is essentially a bank in every aspect except the one that matters: legally. It is an electronic clearinghouse, used primarily by buyers and sellers exchanging funds in online auctions. Buyers can use a credit card at PayPal to pay for their purchases, and PayPal sends the money on to the seller, less a small service charge.
This enables sellers to accept credit card payments without going through the hassle of setting up a merchant account with a bank. It is especially helpful to the low-volume, occasional auction seller.
Since it is not officially classified as a bank, PayPal is not subject to most banking regulations. These non-applicable regulations would otherwise offer consumers a measure of protection from fraudulent transactions. While PayPal is very convenient and fills a very important niche in the online community, it is not without its hazards.
Logging in to a PayPal account requires two items: the email address registered to the account and the password. Once logged in, the user has free reign to change the account information in any way, including changing the email address. In Dan's case, the thief correctly guessed the account's email address [it's posted on the site to facilitate donations - dk] and password. Once in, he changed the email address to his own and started transferring money to himself. When the PayPal account ran out of funds, PayPal automatically debited Cobweb Publishing's linked bank account until it, too, was emptied.
In order to be "verified" with PayPal, you have to provide a valid bank account. This account is linked to your PayPal account, enabling money to be transferred between the bank and PayPal. Although it is not strictly required, failing to provide this information severely restricts your use of PayPal.
With none of the government-mandated safeguards of a bank or credit card in place, Cobweb Publishing, the publisher of Low End Mac, is out somewhere in the neighborhood of $1,500. Unlike a credit card, where questionable transactions are usually reversed until everything is sorted out, Cobweb Publishing has lost use of their own money until they can prove fraud. Conceivably, the money could be gone for good. Guilty until proven innocent.
Here are some precautions that all PayPal users should take:
- Set up an email account that is used only for PayPal. Although this is far from foolproof, it will at least give a potential thief another hoop to jump through.
- Choose a password that contains letters, numbers, and symbols (!,#%&, etc.). Don't use words found in the dictionary. Password-cracking programs will figure those out in minutes. The harder the password is to guess, the better. As Dan's case illustrates, however, this is still no guarantee.
- Don't link your bank account with PayPal unless it is absolutely necessary. If you have to, open a separate account for just this purpose, and never leave more than a minimum balance in the account. To transfer funds, move money into the account and then immediately out through PayPal. When you receive funds, withdraw them immediately upon receipt. After reading of Dan's unfortunate adventure, I went to PayPal and removed my bank account. Until I can open a new account devoted solely to PayPal, I will remain an "unverified" member of the PayPal community.
This incident gives us an opportunity to remind you of other precautions that should be taken in online commerce in general:
1. Always pay with a credit card. You receive your greatest degree of fraud protection when using a credit card. Many banks offer Visa or MasterCard debit cards. These cards function as regular, run-of-the-mill credit cards - with one important exception. When you make a charge, the money is automatically drafted from your bank account. You receive no monthly bill other than your bank statement. These cards, when used with your (hopefully) secret PIN, also function as ATM cards. As with PayPal, these cards are oh so convenient. Also like PayPal, they carry their own hidden pitfalls.
It is important to know that, even when used as a credit card, these debit cards do not carry the same level of consumer protection. If your Visa or MasterCard debit card is used fraudulently, you will likely be in the same boat as Dan Knight and Cobweb Publishing. Until and unless you can prove fraud to the bank's satisfaction, you lose the money in question.
I recently had occasion to experience this personally. Kay and I received our bank statement and noticed two different charges from the same store, totaling almost $300. Satisfied that neither of us had made the charges, we contacted the store at which the charges were made. We learned that the merchandise had been mail-ordered by and shipped to someone in our small town. I theorized that the customer was someone who also used our small bank. Credit cards issued by smaller banks usually come from a block of numbers. It is not unusual to have all of the credit cards from these banks have the same numbers except for the last four or five. My thought was that two numbers had been transposed on the order, making the credit card number correspond to our own. After further investigation with both the merchant and our bank, my theory was confirmed. After almost two weeks, we got our $300 returned.
It was alarming that this merchant had done no credit card verification. If he had, he would have immediately known there was a problem, since the name and address of the customer did not match those registered to the credit card. Fortunately we were in a position where losing $300 for two weeks did not put us in a bind. Many people are not. Caveat emptor.
2. If you must use a debit card, use it as a credit card (as opposed to an ATM card) whenever possible. Many stores and point-of-sale devices, after swiping a debit card, will ask whether you want to use the card as "credit," "debit" or "EBT." Always choose credit.
Again, I want to emphasize that treating your debit card like a credit card does not necessarily confer upon you the same protection as if you had whipped out the American Express, but there are several reasons for using it as such. It is just common sense not to expose your PIN to prying eyes anymore than is absolutely necessary. Your debit card + your PIN = unfettered access to your bank account(s) by a criminal, who will be able to collect his spoils in cash without having to go through any third parties.
The other reasons relate to the different way the transaction is handled from the point of sale until it reaches your bank account. I will not publicly discuss those reasons here so that I don't accidentally educate any aspiring criminals, but trust me on this. Don't use your debit card if you don't have to; if you have to, use it as a credit card whenever possible.
3. Don't pay by check, money order, or cash. If something goes wrong, you will have little or no recourse. A deal is a deal is a deal, and in this case it is also final.
4. Don't enter your credit card information on an unsecure Web page or send it via email. All browsers have some sort of lock and key icon, usually in the lower left or right-hand corners, which will show you if the Web page you are on is secure or not. On Internet Explorer for Mac, a small gold closed lock will appear in the lower left-hand corner of the frame of the browser, immediately to the left of the globe icon, whenever you enter a secure page. As for email, the only form of communication less secure is walking down the street with a megaphone.
The vast majority of Web pages are not secure. Don't panic, however. Unless you are entering sensitive information into the page, there is no reason for it to be secure. On most websites, the only secure page is the one where you place your order.
5. Don't give your credit card or bank information to solicitors who call on you. If you did not originate the call for the purpose of placing an order, don't volunteer any financial information.
6. Every reputable website has a general disclaimer that no one from their company will ever contact you and ask for your password, and they mean it.
There is an old joke about a man that comes into a computer shop and tells the technician that he is worried about hackers, viruses, and spies. He directs the shop to make his computer "absolutely secure." The technician removes the floppy drive, CD-ROM, modem, network card, keyboard, and mouse, and then hands the computer back.
Making something absolutely secure will usually have the unintended
side effect of rendering it useless. This is certainly the case with
online commerce. While it cannot be completely secure and without risk,
by taking a few precautions you greatly reduce this risk.
Steve Watkins is the Vice President for Information Technology for a mid-sized bank and also an attorney. He has been a Mac user for about ten years. He has owned some PCs along the way - but always came back to the Mac. If you find Steve's's articles helpful, please consider making a donation to his tip jar.
Recent Practical Mac Articles
- 5 things Apple is doing right in 2008 - and 5 it could do better, 03.24. Apple has made great strides in the past five years, but there are still a few areas that need to be addressed.
- MacBook Air a compelling option for the true road warrior, 02.22. Although it's not intended as a desktop replacement and has a few shortcomings, the lightweight MacBook Air with its 13" display could be the perfect field computer.
- Mailsmith a simple, powerful, spam fighting alternative to Apple Mail, 04.23. Mailsmith is bundled with SpamSieve, integrates with Address Book, and has very flexible scripting tools combined with elegant simplicity.
- Can your spam with SpamSieve, 02.02. "Right out of the box, SpamSieve exceeded the accuracy of the Apple Mail filter I've been training for over a year."
- More in the Practical Mac index.
Links for the Day
- Mac of the Day: Motorola StarMax 5000, May 1997 - This second-generation Mac clone offered 603e, 604e processors.
- List of the Day: The iPod List The iPod List is a forum to discuss the iPod, it's accessories, the iTunes Store, iTunes, and related topics.
- October 13 in LEM history: 98: Evidence that Macs last longer - 99: A Mac is like Prozac - From home computers to a real computer - 00: Tradeoffs for OS X beta - 03: iBook failures - 05: The 2005 iMac G5 value equation - Email on your iPod - OS X on 4 dual-core CPUs - 06: The legendary Apple Extended Keyboard - Stinky old iBook smells like sweat - Apple's climb back to success
Recent Content on Low End Mac
- nVidia Inside Next MacBook?, Time for a Mac Netbook, Asus Launched MacBook Air Killer, and More, The 'Book Review, 10.10. Also photo reveals more about MacBook Pro, comparing 16:9 and 16:10 displays, Apple settles suit over faulty iBook and PowerBook adapters, bargain 'Books from $150 to $2,699, and more.
- TruePower Battery Can Run WallStreet PowerBook Past the 5 Hour Mark, Tommy Thomas, Welcome to Macintosh, 10.10. If you have a rugged old PowerBook but its battery is losing capacity, TruePower can give you plenty of time in the field.
- Economic Crunch May Slow Mac Sales, a Recycled Cube, ToCA Race Driver 3 for Mac, and More, Mac News Review, 10.10. Also don't buy RAM from Apple, customize your Mac's appearance, MacTribe expanding into print, My Apple Space social networking, and more.
- 30% of iPhone 3G Buyers Switched Carriers, EU Battery Rule May Force iPhone Redesign, and More, iNews Review, 10.10. Also iPhone 3G greatest consumer electronics device ever, track presidential polls on your iPhone, Talking English Dictionary, waterproof armbands, several new iPhone apps, and more.
- Best Mac Pro Deals, Low End Mac Deals, 10.10. Used 2.66 GHz 4-core, $1,799; new, $1,949 after rebate; 2.8 4-core, $2,099 shipped; 8-core, $2,599 shipped; 3.0 $3,399 shipped; 3.2, $4,099 shipped.
- Best PowerBook G3 Deals, Low End Mac Deals, 10.10. Used 14" WallStreet G3/266 MHz, $90; Lombard G3/400 MHz, $150; Pismo G3/400 MHz, $300; 500 MHz, $350.
- Best Time Capsule and AirPort Deals, Low End Mac Deals, 10.10. Refurb 500 GB Time Capsule, $249; new, $294; refurb 1 TB, $419; new, $462; AirPort Extreme Card, $39; Base Station, $159; Express, $60.
- Modding Your Old Mac to Make It More Useful, Phil Herlihy, The Usefulness Equation, 10.09. If your old Mac is too slow, too noisy, too plain looking, or has too little room for expansion, you might want to mod it.
- What Would an $800 MacBook Mean for the Mac mini?, Dan Knight, Mac Musings, 10.09. If Apple does release an $800 entry-level MacBook next week, the $600 Mac mini is going to look very overpriced.
- Best iMac G4 Deals, Low End Mac Deals, 10.09. Used 15" 700 MHz CD-RW, $269; 800 Combo, $300; 1 GHz, $390; 17" 1.25 GHz SuperDrive, $400; 20", $529.
- Best 15" MacBook Pro Deals, Low End Mac Deals, 10.09. Used 1.83 GHz Core Duo, $995; 2.16, $1,125; new, 2.2, $1,400 after rebate; refurb 2.4, $1,699; 2.5, $1,999; 2.6, $2,299; rebates on new.
- Best Mac OS X 10.4 'Tiger' Deals, Low End Mac Deals, 10.09. DVD upgrade from 10.3, $75; upgrade bundle with 10.3, $118; full version, $129; family pack, $200; 10-user Server, $350; unlimited, $400.
- The Power of Older Macs, Why Vista Only Sees 3 GB of RAM, Wangwriter Supplies, and More, Charles W. Moore, Miscellaneous Ramblings, 10.08. Also the end of an era as MIT HyperArchive shuts down and another suggestion for profiling Windows computers.
- Migrating My Law Office from Windows to Macintosh, Andrew J Fishkin, Best Tools for the Job, 10.08. By switching to Leopard Server, everyone in the office will be able to move to a Mac - but which ones will best meet their needs?
- Low End Mac Needs Help Moving to Joomla, Dan Knight, Mac Musings, 10.08. We've settled on Joomla as the content management system that should work very well for Low End Mac, but we're running stuck with templates.
- Will Apple's iPhone/App Store Tornado Blow Away the Competition?, Tim Nash, Taking Back the Market, 10.08. The iPod, iTunes, and the iTunes Store paved the way for the success of the iPhone and the App Store - and nobody can match that.
- More links in our archive.
About LEM | Support | Usage | Privacy | Contacts
