Live data from Hacker News

Moonpig.com Vulnerability – Exposes customer data

ifc0nfig.com

101–110 of 124 posts

Re: Moonpig.com Vulnerability – Exposes customer data

#102
post #17

Earlier quoted context omitted.

It's worth pointing out that the case study is from 2007, there's a good chance that this company is no longer involved and likely wasn't involved in building the API for apps and the security on them.

In any case, once this is out, they will have to take the Moonpig case study from their site.

Yup that link is now 404

Re: Moonpig.com Vulnerability – Exposes customer data

#104
post #14

http://www.conosco.com/case-studies/moonpig-outsourced-it/ >Protection against cyber attacks Wow...

They've already removed it...

Way back machine to the rescue!

http://web.archive.org/web/20150106023452/http://www.conosco...

Re: Moonpig.com Vulnerability – Exposes customer data

#105
post #63
post #59

Earlier quoted context omitted.

Another minor consideration - here in the UK this was posted at 10PM - not exactly a friendly hour. It would have been nice to schedule the post for a time when UK businesses expect to operate. I don't expect they would have thanked you for it in any case, but they would probably have had both a better response time and a better organised response

They had 17 months, and their Twitter account was still posting at 9pm this evening. If they gave two shits about our data (and it might include mine, it definitely includes my mum's), or if they were capable of a sensible helpful coherent response, they'd have done it 16.5 months ago.

yes, quite clear that they didn't give it the priority it warranted (aka giving a shit) - just wanted to point out that there was a friendlier option timing wise. For my money, I'd have seen this disclosed 11 months ago - it's a serious vulnerability to the extent that I'm glad I've never used moonpig.com - but I'd have seen it disclosed in the UK daytime when the company was awake to be able to shut down its API. There's even an argument to be had that waiting as long as this is a little irresponsible - although that's covered to some extent by following up.

I don't know if it's legal to give advance warning of public disclosure - that could easily become a minefield as it might be interpreted as a threat, and linking it to a request to fix could seem coercive.

Re: Moonpig.com Vulnerability – Exposes customer data

#106
post #48

Earlier quoted context omitted.

My guess is that the ICO wont fine them very much as it did not include full credit card numbers. However they might up it for failings in process, lots of remedial measures etc. They might not even have PCI compliance issues alas. The management will argue that they knew nothing, although that is becoming less of a defence now.

Doesn't matter, if they're a UK based company they fall under the EU GDPR and can receive a fine of 5% of their worldwide turnover for any loss of personal data, blanked out credit card numbers or not. http://en.wikipedia.org/wiki/General_Data_Protection_Regulat...

A cursory read of your own link would have told you that the new Data Protection Regulation is not yet in force and so the figure you quote is incorrect.

The ICO in the UK currently has the ability to fine up to £500k as I understand it.

Re: Moonpig.com Vulnerability – Exposes customer data

#107
post #103

To anyone thinking of enumerating the customer IDs to play with this, be very careful as it's illegal in the USA. That is exactly what weev was arrested and convicted for.

Does anyone know what the legal position in Great Britain is?

Generally it may fall under the Computer Misuse Act and 'unauthorised access to computer material'. Presumably from Moonpig's perspective inputting alternative customer IDs would be considered to be unauthorised access...

Re: Moonpig.com Vulnerability – Exposes customer data

#108

Earlier quoted context omitted.

Personally (and I know this is likely to be an unpopular sentiment on HN) I have very little sympathy for weev. He knowingly and deliberately attack a weakness he had found to scrape data, knowing that the access was unauthorized. I disagree that the data was in the public domain (although the Third Circuit disagrees) - just because something is accessible to the public doesn't mean it's in the public domain. Just be…

>I think one part of improving cyber security is prosecuting people who deliberately and maliciously hack into other systems who do so for either monetary gain or fame. This would do nothing except cast a chilling effect over the security community. Everyone would sit on exploits, too afraid of overzealous prosecutors to publish them or even reach out to the affected parties. Unless, of course, you believe the US jus…

No, it would be better if responsible disclosure was codified in the CFA. That's worthy of a campaign - but weev didn't practice that, so he's a poor figurehead for such a campaign.

Such a protection could provide an equal level of footing with the DMCA (i.e. you aren't liable for malicious attacks on a computer company if you provide full disclosue and advance notice, in the same way YouTube isn't liable for hosting copyrighted content if they provide a takedown mechanism).

Re: Moonpig.com Vulnerability – Exposes customer data

#109

To anyone thinking of enumerating the customer IDs to play with this, be very careful as it's illegal in the USA. That is exactly what weev was arrested and convicted for.

> That is exactly what weev was arrested and convicted for.

Please don't spread this misinformation, the USA justice system doesn't work (... like that). Weev was arrested for having a (very, very) loud mouth and pissing off the wrong, powerful people/businesses/corporations.

If he'd have enumerated customer IDs for a smaller, lesser-known company such as Moonpig, reported it to the media like he did, without being all inflammatory and trollish[0] about it (or without having a history of allegedly doing such things in very different contexts), he'd have gotten a slap on the wrist, a fine, or something (if anything), but not been thrown into prison as he was.

Your post makes it seem like Weev was convicted "for" doing something that is illegal in the USA and that the justice system worked "exactly" how it is supposed to, equally as it would apply to anyone.

[0] stating this as a fact of how it happened, not judging him about this, at all

Re: Moonpig.com Vulnerability – Exposes customer data

#110

Earlier quoted context omitted.

> because it's obviously wrong... // Are you trying to say it's morally wrong to read data made publicly available through a site's API? I think that's a stretch. Clearly there are very obviously malevolent things you could do with data acquired with such queries, but just iterating on a URL query string seems pretty far from an obvious moral wrong. Legally questionable, for sure. Morally forthright, doubtful. The wr…

I don't think there's any ambiguity here. Deliberately downloading personal information—clearly not intended to be released publicly—does not seem to be a defensible action. We're not talking about downloading a couple of records and alerting someone about it, after all.

>does not seem to be a defensible action //

What harm is there in viewing data? None.

Defended.

Which do you find is indefensible, seeking to consume data or consuming it? Or, does one need to actively seek it and also consume it to cross your threshold of immorality? Or ...

Post reply on HN