gamesas.com Credit Card Security Announcement

Post » Sun Aug 24, 2008 9:55 pm

Hi everyone,

We are aware of player concerns over payment security on gamesas.com.

Rest assured that all financial transactions and sensitive data on gamesas.com use an approved, PCI-compliant, fully-secure payment technology including HTTPS/SSL inside the store frame, regardless of the parent URL displayed in the browser.

Please also note that, per PCI standards and industry best practices, our payment partner GameSpy never stores your credit card details, but instead securely registers them with one of the largest and most secure credit card gateways and card issuers in the world, so there is no opportunity for ‘hacking’ this data from either Crytek or GameSpy.

Thank you,
EA/Crytek
User avatar
Taylah Illies
 
Posts: 3369
Joined: Fri Feb 09, 2007 7:13 am

Post » Sun Aug 24, 2008 4:30 pm

That sounds great, but it would be even more secure if there was nothing to steal. Having the option not to save credit card information on the server would make a lot of people feel better.
User avatar
El Khatiri
 
Posts: 3568
Joined: Sat Sep 01, 2007 2:43 am

Post » Sun Aug 24, 2008 10:14 pm

Thank you for that well needed explanation about security. We do, however, need an option to remove the info if one wishes to do so.
User avatar
CYCO JO-NATE
 
Posts: 3431
Joined: Fri Sep 21, 2007 12:41 pm

Post » Sun Aug 24, 2008 11:54 pm

I prefer Paypal. Or simple just be able to buy these packs on Steam, for example.
User avatar
Siobhan Wallis-McRobert
 
Posts: 3449
Joined: Fri Dec 08, 2006 4:09 pm

Post » Sun Aug 24, 2008 2:44 pm

Thank you for that well needed explanation about security. We do, however, need an option to remove the info if one wishes to do so.
Exactly what he said xD
User avatar
Heather Dawson
 
Posts: 3348
Joined: Sun Oct 15, 2006 4:14 pm

Post » Sun Aug 24, 2008 12:48 pm

That does not change the fact that there is currently no option to refuse gamesas from retaining my credit card info, and no matter how secure you feel your system is, that will never replace the peace of mind that I would have when I know that I did not allow the site to retain my payment info. Further more you should want to put an option in there to allow for that, because if something were to happen it would put us the customers in a VERY actionable position. It would be a shame if EA or CRYTEK were on the receiving end of a lawsuit just because you wanted to save a few dollars and refuse us the option of not saving our credit card info. Until this is changed I have altered my saved info to prevent any hacker wannabes from using my info.

Yours truly,
Daffy D Duck
8675309 Crytek Blows Ave
EA SUX CO, 80203

Thank you and have a crappy tomorrow!
User avatar
BRAD MONTGOMERY
 
Posts: 3354
Joined: Mon Nov 19, 2007 10:43 pm

Post » Sun Aug 24, 2008 11:37 am

Hi everyone,

We are aware of player concerns over payment security on gamesas.com.

Rest assured that all financial transactions and sensitive data on gamesas.com use an approved, PCI-compliant, fully-secure payment technology including HTTPS/SSL inside the store frame, regardless of the parent URL displayed in the browser.

Please also note that, per PCI standards and industry best practices, our payment partner GameSpy never stores your credit card details, but instead securely registers them with one of the largest and most secure credit card gateways and card issuers in the world, so there is no opportunity for ‘hacking’ this data from either Crytek or GameSpy.

Thank you,
EA/Crytek

I have to disagree!
PCI DSS 2.0 Requirement 4.1.e Testing Procedures says clearly:
"For SSL/TLS implementation: *Verify that HTTS appears as a part of the browser Universal Locator (URL)."

That means any Website that has no HTTPS in the URL cannot by PCI DSS 2.0 compliant!

The idea behind that requirement is: that the cardholder can verify by himself, on which website his data is send to. If you use frame technology a customer does not see where the data is going and whether this is done on a secure way or not. This opens a weakness in the security chain. It is very simple to attack a HTTP site rather than a HTTPS site!

Just for the understanding: I worked now for more than 3 years as a certified PCI DSS auditor.

Best regards

L1belle
User avatar
Charlotte Lloyd-Jones
 
Posts: 3345
Joined: Fri Jun 30, 2006 4:53 pm

Post » Sun Aug 24, 2008 12:38 pm

So in other words, "its a secure payment method...trust us" Right? Sorry I dont know you, and there are people in my own family I wouldnt trust with my credit card info!
User avatar
Unstoppable Judge
 
Posts: 3337
Joined: Sat Jul 29, 2006 11:22 pm

Post » Mon Aug 25, 2008 1:43 am

sorry tom, i verify again now.

When ask "add a credit card", website mode is HTTP only.

sorry, but open your eyes.

I can't write my card number if no encryption.

say it's secured is very bad for you, learn security https before say such nonsense

http://www.gamesas.com/addcard/ url when i want add a card, this url work fine, but not https, sorry

Why this adress exist in http if need https ? learn about it cry_tom. clic on it and search why.

try https://www.gamesas.com/addcard/ , don't match, sorry, it's not secured and all paiement are not
secured, number card wanders freely on the net

User avatar
Amy Siebenhaar
 
Posts: 3426
Joined: Fri Aug 10, 2007 1:51 am

Post » Sun Aug 24, 2008 7:07 pm

Still don't trust it in any way - if the creditcard is the only payment-method, I'll NEVER trust it. Add Paypal and a few other ways to pay and THEN we can talk about purchasing DLC.
User avatar
Oscar Vazquez
 
Posts: 3418
Joined: Sun Sep 30, 2007 12:08 pm

Post » Sun Aug 24, 2008 7:23 pm

So in other words, "its a secure payment method...trust us" Right? Sorry I dont know you, and there are people in my own family I wouldnt trust with my credit card info!

I've had a look, the frame is secure but what's outside it (the actual page and other stuff) isn't.

Image

This means a hacker can attack the page and bring it down or manipulate it, but won't be able to get your card details too easy as that's what's encrypted.

However it is a slight security issue, full https for the entire store page would be a much better reassurance however it's not as bad as the scaremongers are making out.
User avatar
kevin ball
 
Posts: 3399
Joined: Fri Jun 08, 2007 10:02 pm

Post » Mon Aug 25, 2008 4:07 am

thanks for sharing that n00binator.
User avatar
Alister Scott
 
Posts: 3441
Joined: Sun Jul 29, 2007 2:56 am

Post » Sun Aug 24, 2008 9:39 pm

No PayPal, no DLC for me...
User avatar
Valerie Marie
 
Posts: 3451
Joined: Wed Aug 15, 2007 10:29 am

Post » Sun Aug 24, 2008 6:25 pm

we don't wanna give ya money
User avatar
Blackdrak
 
Posts: 3451
Joined: Thu May 17, 2007 11:40 pm

Post » Sun Aug 24, 2008 11:38 am

Just to add to my last post, you can run the frame itself in it's own window as https

Example:

https://crysis2pc.d2gstore.gamespy.com/Cards/Cards.aspx

The only problem is you will still get an only partially encrypted error in your browser due to the fact the images are not encrypted (which is fault of direct2drive). If you block all images from being displayed and restart your browser you get a fully secured connection.
User avatar
His Bella
 
Posts: 3428
Joined: Wed Apr 25, 2007 5:57 am

Post » Sun Aug 24, 2008 7:32 pm

Not everyone has a creditcard. I think it's stupid just to offer one payment method.
User avatar
Sarah Kim
 
Posts: 3407
Joined: Tue Aug 29, 2006 2:24 pm

Post » Sun Aug 24, 2008 6:41 pm

sorry tom, i verify again now.

When ask "add a credit card", website mode is HTTP only.

sorry, but open your eyes.

I can't write my card number if no encryption.

say it's secured is very bad for you, learn security https before say such nonsense

http://www.gamesas.com/addcard/ url when i want add a card, this url work fine, but not https, sorry

Why this adress exist in http if need https ? learn about it cry_tom. clic on it and search why.

try https://www.gamesas.com/addcard/ , don't match, sorry, it's not secured and all paiement are not
secured, number card wanders freely on the net

Can t you understand this adress is just the global page adress ???? If you re looking code, all the store data are into an Iframe calling an HTTPS adress.
User avatar
Brooke Turner
 
Posts: 3319
Joined: Wed Nov 01, 2006 11:13 am

Post » Mon Aug 25, 2008 3:18 am

No way I give away all these informations for 4 cards, which are too expensive btw. I would go to the store and buy it there, but that's not possible. Great! I really wanted to buy that dlc =(
User avatar
sally R
 
Posts: 3503
Joined: Mon Sep 25, 2006 10:34 pm

Post » Sun Aug 24, 2008 9:57 pm

crytek, would you kindly.,. make this DLC purchasable in EA store?

like other EA games as BFBC2 and MOH map packs?

It would be much more accessible for me and lot of others alos.
User avatar
Myles
 
Posts: 3341
Joined: Sun Oct 21, 2007 12:52 pm

Post » Sun Aug 24, 2008 8:51 pm

I added my credit card to 2 different accounts and still cant purchase the DLC!!!
User avatar
Bek Rideout
 
Posts: 3401
Joined: Fri Mar 02, 2007 7:00 pm

Post » Sun Aug 24, 2008 5:15 pm

I also would love the option to erase my credit card from the store.

As for now i just modify the expiry date my name and address after any transaction to protect my identity !
User avatar
My blood
 
Posts: 3455
Joined: Fri Jun 16, 2006 8:09 am

Post » Sun Aug 24, 2008 12:43 pm

Yeah, it's even worse for people that have/use "Debit Cards" .. Unlike Credit Cards, you could have your account wiped clean, regardless of your security options, "NOTHING" is 100% full proof, nothing! I don't use CreditCards, I only use my Debit Card.

I guess the ONLY secure thing to do is go purchase a "pre-paid credit card" and put $10.00 on it, that way it does'nt matter, but some online sites won't accept them and some do. Problem with the "pre-paid" ones is "filling in the shipping/billing address info", you have to call them first and setup that all up, then use it, and thats a big hairy pain in the arse.
User avatar
Conor Byrne
 
Posts: 3411
Joined: Wed Jul 11, 2007 3:37 pm

Post » Sun Aug 24, 2008 5:08 pm

yeah it's safe when no hackers leak the server :))
User avatar
Paula Rose
 
Posts: 3305
Joined: Fri Feb 16, 2007 8:12 am

Post » Sun Aug 24, 2008 3:24 pm

So you reply to this, but not to the people who cant purchase it?

Nice Priorities their Crytek.. round of applause anyone? no good.
User avatar
john page
 
Posts: 3401
Joined: Thu May 31, 2007 10:52 pm

Post » Sun Aug 24, 2008 5:25 pm

.
. ITS DEJA VU ALL OVER AGAIN
.
“We know that some people have been playing with an unfair advantage in the Crysis 2 demo. Rest assured that although the demo does not have these features installed, our team has been working for some time on various anti-cheat measures that have been introduced for the retail release of Crysis 2.”

"We are aware of player concerns over payment security on gamesas.com. Rest assured that all financial transactions and sensitive data on gamesas.com use an approved, PCI-compliant, fully-secure payment technology including HTTPS/SSL inside the store frame, regardless of the parent URL displayed in the browser."

Feel secure?
User avatar
Monique Cameron
 
Posts: 3430
Joined: Fri Jun 23, 2006 6:30 am

Next

Return to Crysis