___

  • gravitas_deficiency@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    20
    arrow-down
    2
    ·
    vor 3 Jahren

    The fact that you think it’s reasonable for literally anyone but you to give out your credit card details is a pretty big sign my guy

    • brygphilomena@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      2
      ·
      edit-2
      vor 3 Jahren

      Because banks don’t give out credit card details.

      You created an authorization code which is independent from the credit card details. The authorization code doesn’t get revoked automatically when a card expires or a new card issued.

      • gravitas_deficiency@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        5
        ·
        vor 3 Jahren

        Jesus tap dancing christ. I understand the difference between CC + CCV + expiry date and an oauth token (or whatever protocol they’re using for identification and authentication). I’m saying that not expiring auth codes when new cards are issued is a security and privacy issue. Users should ideally be given a switch to opt in to behavior like that. It should not be the default.