Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Help on website to make it clear that people shouldn't share their credit card information. #857

Open
benrfairless opened this issue Oct 15, 2024 · 6 comments

Comments

@benrfairless
Copy link
Member

For some reason authorities are asking people to email credit card information....

Is this something we need to warn people about?

@benrfairless
Copy link
Member Author

@coopzr
Copy link

coopzr commented Oct 15, 2024

Agencies know their correspondence is going on a public forum. I would have assumed they have an obligation not to be this stupid and ask a user to post their credit card information online. I wonder if the OAIC would like to comment on this matter?

@benrfairless
Copy link
Member Author

@coopzr we do tell authorities that responses will be published on the Internet, however it's in the footer of the email.

Perhaps we should update that message to be a bit clearer that they shouldn't be asking for personal information, shouldn't be sharing it, and should be reporting requests that they receive for personal information?

@coopzr
Copy link

coopzr commented Oct 16, 2024

@benrfairless is clarity the issue? The footer clearly explains the correspondence is occurring on a public forum. I would think government agencies have certain responsibilities when it comes to dealing with the public. Asking an applicant to post their credit card information online for all to see might even be in violation of a Australian privacy principle. Even if not technically a legal issue, common sense says this is a terrible idea.

@benrfairless
Copy link
Member Author

@coopzr good point. I suppose I'm looking at it through the lens of what we can control.

Sidenote, As far as I'm aware it's against industry standards to store credit card information without encryption in any format. Asking people to email credit card information is just asking for trouble.

@benrfairless
Copy link
Member Author

The instances of this happening are relatively minor, but I think having a bigger conversation about how we encourage people not to breach their own privacy is important.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants