On 02/15/2017 12:46 PM, Kai Hendry wrote:
> Ok, signed up to ACTIVATE! (better name would be DE-ACTIVATE!). Guess I
> shouldn't be surprised it goes from asking no personal information to
> asking for your birthday...
>
https://s.natalian.org/2017-02-15/ezlink-activate.png
That looks slightly odd. It might be a step better than asking for
NRIC/FIN/passport number, although that is already asked for if you need
help with a transaction at station anyway. Don't know what to assume.
> And the insurance for upto 10SGD of loss sounds hilarious.
It's lead generation for an insurer.
I'd have to guess at protection measures here (rate-limiting, logging
client IP addresses, alerting on unusual activity, ...) but I note that
it doesn't appear to work for a generic card. Presumably either (a) the
person looking has to be signed in and/or (b) only cards registered with
the scheme have their transaction data fed to the site.
- Roland