Live data from Hacker News

Clickbank order details in plain view

google.com

61–70 of 81 posts

Re: Clickbank order details in plain view

#61
post #59

Has anyone realized all of this has to do with clkbank.com NOT ClickBank.com Looks like a fake site all together...

It's pretty common to have multiple domains, especially affiliate marketing websites. ClickBooth has clickboothlnk.com, NeverBlue has many random alphanumeric domains.

This certainly is Clickbank.com

Re: Clickbank order details in plain view

#63
post #40

Earlier quoted context omitted.

There's no payment card information besides what's acceptable to show (last four and card type). Full name and email address is PII, but not necessarily in breech of PCI. I don't believe SOX has anything specifically mentioning full name and email PII either. If that's the case, the only thing that would make it a PCI or SOX violation is if the company says in their data privacy policy that they will protect this PII…

Looks like some of these are showing a customer's physical address too. I sure hope that wouldn't be PCI compliant. https://www.clkbank.com/orderDetail.htm?rcpt=504d78866YCRFEF... (Click on View Details under Tracking Number)

PCI is designed to protect credit card fraud, not customer's address information. Banks don't care about the risk of identify theft, but rather credit card fraud.

Re: Clickbank order details in plain view

#64
post #41

Earlier quoted context omitted.

Cardholders name is PCI data. So in most cases the customer?s name and the cardholders name would fall under the auspices of PCIDSS. This is definitely a breach.

Correct. From the DSS, 'Cardholder data includes: Primary Account Number (PAN), Cardholder Name, Expiration Date, Service Code'

This is not true, I used to work in the industry and you can use a hosted credit card solution (where you transfer customers to a secure payment page) without needing PCI compliance.

If it were correct, and the card holder name needed to be secure, the company I worked at would not have received level 1 PCI compliance. The solution sends back the truncated card number, expiry date and the full card holder name.

Of course I'm assuming the banks wouldn't want you to make that data public, but you are allowed to store it without needing to be PCI compliant.

CVV code is another matter, under no circumstances are you allowed to store it, unless you're a level 1 compliant payment processor.

Re: Clickbank order details in plain view

#65

Hi, this is Matt Hulett the CEO of ClickBank. ClickBank was recently made aware of a situation in which customers were posting their information using social bookmarking sites, which are indexed by Google. As a result, ClickBank is taking steps to limit the information that a consumer can inadvertently share through such services. We take customer privacy very seriously and believe that all individuals share responsi…

"...believe that all individuals share responsibility for maintaining the security of personal information that is posted online."

You (CLICKBANK) posted this information online--not your customers. Are you seriously trying to blame them for the fact that your development team seems to have no concern for security and privacy?

Re: Clickbank order details in plain view

#66

Hi, this is Matt Hulett the CEO of ClickBank. ClickBank was recently made aware of a situation in which customers were posting their information using social bookmarking sites, which are indexed by Google. As a result, ClickBank is taking steps to limit the information that a consumer can inadvertently share through such services. We take customer privacy very seriously and believe that all individuals share responsi…

I'm puzzled. How is taking customer privacy seriously compatible with leaving private information indexable, let alone accessible through unrestricted urls?

Re: Clickbank order details in plain view

#67
post #12

The founder sure knows about technology: "As a research scientist for the NSA, Dr. Tim Barber was..."

I wonder if their new CFO that started today wants to take back what he said about ClickBank's "strong digital platform."

http://www.prweb.com/releases/2013/6/prweb10846812.htm

Re: Clickbank order details in plain view

#68
post #51

Earlier quoted context omitted.

Did you get the job?

No. It was a week long, paid interview. After a couple of days I decided not to come back. Mainly because the main project seemed illegal (which I'll admit held some criminal mastermind allure) and I had another job lined up in Japan. In retrospect, I wish I would have done it as the job in Japan was terrible and I've not come across a similar opportunity since.

Contact them again?

Re: Clickbank order details in plain view

#69
post #68
post #51

Earlier quoted context omitted.

No. It was a week long, paid interview. After a couple of days I decided not to come back. Mainly because the main project seemed illegal (which I'll admit held some criminal mastermind allure) and I had another job lined up in Japan. In retrospect, I wish I would have done it as the job in Japan was terrible and I've not come across a similar opportunity since.

Contact them again?

I don't think they exist anymore.

Re: Clickbank order details in plain view

#70
post #37
post #34

Does Google pull links from Gmail and attempt to index them? I am wondering how they knew to index these pages with random URLs (the "security through obscurity" employed by ClickBank and defended in the support ticket referenced in the comments here).

I'm fairly certain they do, from experiences in the past where otherwise completely private (but unprotected) URLs have ended up indexed.

If you're browsing with chrome or a browser with the google toolbar urls will be submitted to google automatically.
Post reply on HN