http://www.conosco.com/case-studies/moonpig-outsourced-it/ >Protection against cyber attacks Wow...
Moonpig.com Vulnerability – Exposes customer data
101–110 of 124 posts
Re: Moonpig.com Vulnerability – Exposes customer data
#102Earlier quoted context omitted.
It's worth pointing out that the case study is from 2007, there's a good chance that this company is no longer involved and likely wasn't involved in building the API for apps and the security on them.
In any case, once this is out, they will have to take the Moonpig case study from their site.
Re: Moonpig.com Vulnerability – Exposes customer data
#103To anyone thinking of enumerating the customer IDs to play with this, be very careful as it's illegal in the USA. That is exactly what weev was arrested and convicted for.
Re: Moonpig.com Vulnerability – Exposes customer data
#104http://www.conosco.com/case-studies/moonpig-outsourced-it/ >Protection against cyber attacks Wow...
They've already removed it...
http://web.archive.org/web/20150106023452/http://www.conosco...
Re: Moonpig.com Vulnerability – Exposes customer data
#105Earlier quoted context omitted.
Another minor consideration - here in the UK this was posted at 10PM - not exactly a friendly hour. It would have been nice to schedule the post for a time when UK businesses expect to operate. I don't expect they would have thanked you for it in any case, but they would probably have had both a better response time and a better organised response
They had 17 months, and their Twitter account was still posting at 9pm this evening. If they gave two shits about our data (and it might include mine, it definitely includes my mum's), or if they were capable of a sensible helpful coherent response, they'd have done it 16.5 months ago.
I don't know if it's legal to give advance warning of public disclosure - that could easily become a minefield as it might be interpreted as a threat, and linking it to a request to fix could seem coercive.
Re: Moonpig.com Vulnerability – Exposes customer data
#106Earlier quoted context omitted.
My guess is that the ICO wont fine them very much as it did not include full credit card numbers. However they might up it for failings in process, lots of remedial measures etc. They might not even have PCI compliance issues alas. The management will argue that they knew nothing, although that is becoming less of a defence now.
Doesn't matter, if they're a UK based company they fall under the EU GDPR and can receive a fine of 5% of their worldwide turnover for any loss of personal data, blanked out credit card numbers or not. http://en.wikipedia.org/wiki/General_Data_Protection_Regulat...
The ICO in the UK currently has the ability to fine up to £500k as I understand it.
Re: Moonpig.com Vulnerability – Exposes customer data
#107To anyone thinking of enumerating the customer IDs to play with this, be very careful as it's illegal in the USA. That is exactly what weev was arrested and convicted for.
Does anyone know what the legal position in Great Britain is?
Re: Moonpig.com Vulnerability – Exposes customer data
#108Earlier quoted context omitted.
Personally (and I know this is likely to be an unpopular sentiment on HN) I have very little sympathy for weev. He knowingly and deliberately attack a weakness he had found to scrape data, knowing that the access was unauthorized. I disagree that the data was in the public domain (although the Third Circuit disagrees) - just because something is accessible to the public doesn't mean it's in the public domain. Just be…
>I think one part of improving cyber security is prosecuting people who deliberately and maliciously hack into other systems who do so for either monetary gain or fame. This would do nothing except cast a chilling effect over the security community. Everyone would sit on exploits, too afraid of overzealous prosecutors to publish them or even reach out to the affected parties. Unless, of course, you believe the US jus…
Such a protection could provide an equal level of footing with the DMCA (i.e. you aren't liable for malicious attacks on a computer company if you provide full disclosue and advance notice, in the same way YouTube isn't liable for hosting copyrighted content if they provide a takedown mechanism).
Re: Moonpig.com Vulnerability – Exposes customer data
#109To anyone thinking of enumerating the customer IDs to play with this, be very careful as it's illegal in the USA. That is exactly what weev was arrested and convicted for.
Please don't spread this misinformation, the USA justice system doesn't work (... like that). Weev was arrested for having a (very, very) loud mouth and pissing off the wrong, powerful people/businesses/corporations.
If he'd have enumerated customer IDs for a smaller, lesser-known company such as Moonpig, reported it to the media like he did, without being all inflammatory and trollish[0] about it (or without having a history of allegedly doing such things in very different contexts), he'd have gotten a slap on the wrist, a fine, or something (if anything), but not been thrown into prison as he was.
Your post makes it seem like Weev was convicted "for" doing something that is illegal in the USA and that the justice system worked "exactly" how it is supposed to, equally as it would apply to anyone.
[0] stating this as a fact of how it happened, not judging him about this, at all
Re: Moonpig.com Vulnerability – Exposes customer data
#110Earlier quoted context omitted.
> because it's obviously wrong... // Are you trying to say it's morally wrong to read data made publicly available through a site's API? I think that's a stretch. Clearly there are very obviously malevolent things you could do with data acquired with such queries, but just iterating on a URL query string seems pretty far from an obvious moral wrong. Legally questionable, for sure. Morally forthright, doubtful. The wr…
I don't think there's any ambiguity here. Deliberately downloading personal information—clearly not intended to be released publicly—does not seem to be a defensible action. We're not talking about downloading a couple of records and alerting someone about it, after all.
What harm is there in viewing data? None.
Defended.
Which do you find is indefensible, seeking to consume data or consuming it? Or, does one need to actively seek it and also consume it to cross your threshold of immorality? Or ...