-
Website
http://www.mathewingram.com/work -
Original page
http://www.mathewingram.com/work/2006/07/06/ebay-to-google-checkout-get-lost/ -
Subscribe
All Comments -
Community
-
Top Commenters
-
scrawledinwax
23 comments · 1 points
-
webomatica
35 comments · 5 points
-
howardlindzon
46 comments · 69 points
-
JoeDuck
57 comments · 1 points
-
Karoli
32 comments · 39 points
-
-
Popular Threads
-
In defence of newspapers and serendipity
3 weeks ago · 43 comments
-
Are independent bloggers an endangered species?
2 weeks ago · 8 comments
-
Bloggers, trust, MSM and correction fluid
1 week ago · 2 comments
-
Why media outlets want Facebook Connect
2 weeks ago · 1 comment
-
First Read: Follow the Breadcrumbs : CJR
2 weeks ago · 1 comment
-
In defence of newspapers and serendipity
The overall process seems to be very easy but exactly that makes this solution very vulnerable. During checkout there was no security question to make sure that I’m indeed the owner of the Google account or the associated Credit Cards in that account. Of course I used my username and password but because there are so many Google sites, using the same username and password, it is very easy to loose your login information on a hijacking page as you might not check the url for Ad-Words or Gmail every time you log on as those services never had the possibility to shop with your Credit Card.
Now because you have one account and login information for all it is quite possible that hackers will try to get your login information from any Google service out there! Even worth is the fact that the hacker can change the password without any problem. The owner of the account might not even get any information about the password change as the e-mail is sent to the according and hijacked Gmail account.
Because of this HUGE security risk I would not recommend using Google checkout!
Please checkout the http://www.thebilliondollarpatent.com as s-registration solution that Google should have implemented in their service to make it solid and secure. This solution is requiring a third credential called TAN to make sure that ONLY the owner of that account is able to shop online even in case the account is hijacked.
I hope that everybody is aware of the security issue with Google checkout and will inform Google of a better solution!
Thanks and be safe;-)))!!