johnridley: (Default)
That was nerve-wracking. I've got a balance on my Discover card of several thousand, it's a balance transfer from another card and due to various shenanigans, I'm paying 0% on it forever as long as I keep making minimum payments on it. I'd been doing it manually but I figured why not use their auto-pay?

Problem is that Discover has a really inflexible and scary autopay system. The payment doesn't post until the day AFTER the due date, but they promise that its EFFECTIVE date is the due date so it's OK. Also they don't show it as a pending payment, you just have to hope and trust that it's going to happen. And it doesn't happen until the month AFTER you sign up (sign up in mid-May, the first auto-payment doesn't happen until the next billing cycle, in JULY).

Anyway, I gritted my teeth and went through the due date, and it did push the payment the next day and the new statement shows it correct.

Discover is really ridiculous in so many ways. I also wish they'd learn how to format a proper financial statement. I sure wouldn't use them intentionally, they just had a good zero-interest balance transfer a few years ago when I needed it.
G+ comments behind cut )
johnridley: (Kick in the butt)
I got a note saying I hadn't activated my Discover card, so please call. I did, and they said it must have been a mistake, it was activated. More likely it's an opportunity to get me to call so they can try to sell me stuff.

Anyway, about the first thing the guy did was to say "I see you signed up online, let me check to make sure everything's OK." He verified my email, then said "OK, I'm going to send you an email with your password to make sure you can use our online features."

I said "Wait, WHAT are you going to do?" "Email you your password." "NO YOU'RE NOT. MAN, ****NEVER**** EMAIL PASSWORDS. Email is not secure. If you send my password via email, I'll have to go change it, and what's more, I'll have to search all my passwords for other sites I may have used the same password at, and then go change it on all of those sites. It could take me hours."

He put me on hold to try to stop it, but far before he came back, I had already received the email.

I started to chew him out, said that they should NEVER send passwords in emails, they could be intercepted. Heck, that they shouldn't even KNOW what the password is. He said HE didn't know, he just could have the system send the password. I said "The system shouldn't know what my password is, either. You guys have a weak security system, I can tell you that. And you really need to look at your procedures. If you're regularly emailing passwords, any SMTP traffic coming from your data center has got to be a prime target for people sniffing for passwords.

I also told him that I log into the site 4 or 5 times a month, so I don't know why he assumed I didn't already know my password. If I ASKED for the password, that would be one thing. He just sent it.

He didn't try to sell me anything after that, he just apologized and hung up ASAP.

The one good thing is that their system is badly-designed enough that I couldn't use my regular passwords, which are mixed upper/lowercase, numbers and punctuation. They wouldn't allow the punctuation so I was forced to use a pretty weak password, which means it's not one I probably used on other financial sites.

February 2026

S M T W T F S
123456 7
891011 121314
15161718192021
22232425262728

Syndicate

RSS Atom

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Feb. 14th, 2026 02:37 pm
Powered by Dreamwidth Studios