Live data from Hacker News

Moonpig.com Vulnerability – Exposes customer data

ifc0nfig.com

21–30 of 124 posts

Re: Moonpig.com Vulnerability – Exposes customer data

#21

Apparently they hired these guys to help with "protection against cyber attacks" http://www.conosco.com/case-studies/moonpig-outsourced-it/ Awful...

Their first "solution": Fixed price outsourced IT department

To be fair, the complete security failure outlined in the article is at the app level and not something I'd expect most IT departments to bear responsibility for (unless they were directly consulted about how good of an idea using basic auth with hardcoded credentials is and gave an OK on it).

Of course, I wouldn't be too surprised if the app/API here were also outsourced to a low fixed price development shop.

Re: Moonpig.com Vulnerability – Exposes customer data

#23

I am a former customer of theirs (in the UK) and just contacted CS about this. I'm also looking into contacting the Information Commissioner's Office as this issue is still open and my personal information (and that of the people I send cards to) is still available to anyone who may want it. I'm pretty sure them ignoring this for a year is illegal as it involves personal information which their privacy policy didn't…

Please do contact ICO! Regulation needs people to complain. ICO don't investigate complaints if there's been 3 month (?) delay.

Re: Moonpig.com Vulnerability – Exposes customer data

#24

I am a former customer of theirs (in the UK) and just contacted CS about this. I'm also looking into contacting the Information Commissioner's Office as this issue is still open and my personal information (and that of the people I send cards to) is still available to anyone who may want it. I'm pretty sure them ignoring this for a year is illegal as it involves personal information which their privacy policy didn't…

My guess is that the ICO wont fine them very much as it did not include full credit card numbers. However they might up it for failings in process, lots of remedial measures etc.

They might not even have PCI compliance issues alas.

The management will argue that they knew nothing, although that is becoming less of a defence now.

Re: Moonpig.com Vulnerability – Exposes customer data

#25

Earlier quoted context omitted.

If this were the USA it would certainly be bad enough to warrant prosecution of the researcher. I am not familiar with laws in the UK, however. Keep in mind the similarities between this research and weev's research. This type of blatant insecurity definitely should be punished and I wish more policy makers both cared, and made the effort to understand the terminology behind phrases like "No authentication", "Plainte…

First of all, the company could definitely be sued for negligence in the US. Not sure if they could in the UK. Second, there are not that many similarities between this research and weev's research. In this case, the researcher created 2 accounts which he had control over, then read data from both of the accounts despite not authenticating to either of them. He did not access any other customer's information (or at l…

I honestly don't think it is unfair. "Both technically violated the CFAA" is an important sentence.

The legal system is very complicated and sometimes small details make very big differences in cases. I'm not convinced others in the legal system would see this as different

Re: Moonpig.com Vulnerability – Exposes customer data

#26
post #17

Apparently they hired these guys to help with "protection against cyber attacks" http://www.conosco.com/case-studies/moonpig-outsourced-it/ Awful...

It's worth pointing out that the case study is from 2007, there's a good chance that this company is no longer involved and likely wasn't involved in building the API for apps and the security on them.

In any case, once this is out, they will have to take the Moonpig case study from their site.

Re: Moonpig.com Vulnerability – Exposes customer data

#27
This is irresponsible disclosure. You should have contacted the information commissioners office. They would have used legal powers to force Moonpig to rectify this. There are very steep penalties for not protecting customer data.

Now that you've publicly disclosed this, opportunists (people one level above script kiddies) will probably grab a data dump and compromise every customer.

Dealing with this via legal channels would have ensured a resolution whilst protecting customer data from any opportunistic bad actor.

Shame on you. I can't wait for myself and my wife to get doxxed now. Thanks.

Also, FYI; the whole card number isn't returned because they are probably tokenising the full card number with their payment gateway.... Or at least, I hope.

DOWNVOTING because you don't agree with me? How rude. I believe I'm a making a valid point, there are legal channels in place to help with this sort of thing.

EDIT. someone people think I do no hold moonpig responsible for this. I do! I am not blaming the security researcher. What I am saying is that some countries (like the one where moonpig is incorporated and operates) have agencies that deal with issues like these. Getting these agencies involved before public disclosure is a much nicer way to deal with these sorts of issues.

I'm aware that this exploit may already have been used but that doesn't mean that we should tell everyone about it until it is resolved. Getting the ICO involved may have resolved this issue a long time ago.

My disclosure - I have a friend that works at the ICO and she tells me that these issues usually take them (on average) 2 months to sort out. COmpanies get very anxious when the ICO contact them.

Re: Moonpig.com Vulnerability – Exposes customer data

#29

I am a former customer of theirs (in the UK) and just contacted CS about this. I'm also looking into contacting the Information Commissioner's Office as this issue is still open and my personal information (and that of the people I send cards to) is still available to anyone who may want it. I'm pretty sure them ignoring this for a year is illegal as it involves personal information which their privacy policy didn't…

In my other comment, I said the ICO should have been the first place this was reported rather than putting it on the net for opportunistic bad actors to dump all their customer data in pastebin.....
Post reply on HN