While shop­ping for cars this week­end, we decided to do a VIN his­tory check against the cars we were look­ing out.   While we didn’t find any that had been in a flood or a wreck (the things they scare you into doing these checks), we did find a few cars that had been used as rental cars.  When you are doing these checks there are really only two major com­pa­nies to do them with, you have a choice of Car­Fax or Autocheck.  I’ve used Car­Fax in the past, so I decided to try out Autocheck.  Both offer the same infor­ma­tion, and if I had to tell you to use one or the other, I would tell you to choose whichever is cheap­est for the day.

So I signed up, handed over the credit card num­ber, and sud­denly I was logged in.   I was iffy because they never prompted me for a pass­word, yet there was a log out but­ton at the top of the screen.   This was sup­posed to allow for unlim­ited searches for 60 days, so how is my account secured?   Not want­ing to close the win­dow I was actively work­ing in (just in case) I opened another browser and attempted to login.   It asked me for my email address and click next.   I was then logged in — no pass­word at all.

Now it doesn’t seem that you can review your look up his­tory, since all his­tor­i­cal lookups are sent to you via email and they are not stored on the server.   What it does allow is peo­ple to bypass account secu­rity since if you know an email address of some­one with this ser­vice you can get your own searches for free.    You would think this would be at least slightly more secure since it’s run by one of the largest credit agencies.

blog comments powered by Disqus