Live data from Hacker News

Moonpig.com Vulnerability – Exposes customer data

ifc0nfig.com

11–20 of 124 posts

Re: Moonpig.com Vulnerability – Exposes customer data

#12
In the address example you can even emit the arguments and it just returns you a large list of addresses. Would expect this to be hitting the news here in the UK tomorrow!

Judging by their parent companies website they seem to be PCI certified (http://careers.photobox.co.uk/security-officer-moonpig/) which is likely to be removed from them after this, also given the private information on show I would expect this breach of the data protection act to be meaning a large fine for them.

For anyone at risk from this you can't just cancel your account, but you can manually go through and delete quite a bit of data such as address books and they then disappear from the API calls.

Re: Moonpig.com Vulnerability – Exposes customer data

#13
Disgusting - this should be priority one for them to fix.

I just changed all my details to ones from a fake name/address generator, then emailed moonpig to close my account. I will lose about 80 pence, but nevermind.

I didn't see an option to get rid of my credit card details, so that may still be vulnerable, especially with the NameOnCard field in the api.

Re: Moonpig.com Vulnerability – Exposes customer data

#17

Apparently they hired these guys to help with "protection against cyber attacks" http://www.conosco.com/case-studies/moonpig-outsourced-it/ Awful...

It's worth pointing out that the case study is from 2007, there's a good chance that this company is no longer involved and likely wasn't involved in building the API for apps and the security on them.

Re: Moonpig.com Vulnerability – Exposes customer data

#18

In the address example you can even emit the arguments and it just returns you a large list of addresses. Would expect this to be hitting the news here in the UK tomorrow! Judging by their parent companies website they seem to be PCI certified ( http://careers.photobox.co.uk/security-officer-moonpig/ ) which is likely to be removed from them after this, also given the private information on show I would expect this b…

Been a while since I read PCI DSS but if the PAN isn't there, does it specify you have to protect that information? Also, if they don't actually have the PAN touch their servers (like, using a BrainTree or Stripe-like solution), PCI compliance is quite minimal. Even PCI DSS 3.0 is trivial to deal with using Stripe (they just insert an iframe so the CC info goes directly to their site).

Of course, yeah, they don't deserve the benefit of the doubt here. Given such a terrible API they probably are a mess inside, too.

Re: Moonpig.com Vulnerability – Exposes customer data

#19

Surely this is bad enough to warrant criminal prosecution? Not sure if that's even possible in the UK but it ought to be...Shameful to have sat on that for over a year. Shameful.

If this were the USA it would certainly be bad enough to warrant prosecution of the researcher. I am not familiar with laws in the UK, however. Keep in mind the similarities between this research and weev's research. This type of blatant insecurity definitely should be punished and I wish more policy makers both cared, and made the effort to understand the terminology behind phrases like "No authentication", "Plainte…

First of all, the company could definitely be sued for negligence in the US. Not sure if they could in the UK.

Second, there are not that many similarities between this research and weev's research. In this case, the researcher created 2 accounts which he had control over, then read data from both of the accounts despite not authenticating to either of them. He did not access any other customer's information (or at least he's suggesting he didn't).

Weev on the other hand scraped private information for over 100,000 customers and shared it with friends and reporters.

Both technically violated the CFAA, but weev's offense is a much greater violation of customer privacy, while this researcher has not violated anyone's privacy.

I still don't think weev should have gotten any jail time, but you're making an unfair comparison.

Re: Moonpig.com Vulnerability – Exposes customer data

#20

I am a former customer of theirs (in the UK) and just contacted CS about this. I'm also looking into contacting the Information Commissioner's Office as this issue is still open and my personal information (and that of the people I send cards to) is still available to anyone who may want it. I'm pretty sure them ignoring this for a year is illegal as it involves personal information which their privacy policy didn't…

I've also sent customer services an email demanding an explanation and the closure of my account and deletion of personal data if true and sent an email to the ICO.

In reality I don't hold out much hope but fingers crossed we can get some pressure behind this and force companies to take security seriously, especially when the vulnerability is responsibly reported as this seems to have been originally.

Post reply on HN