Live data from Hacker News

Moonpig.com Vulnerability – Exposes customer data

ifc0nfig.com

51–60 of 124 posts

Re: Moonpig.com Vulnerability – Exposes customer data

#51
post #47
post #45

Earlier quoted context omitted.

I don't disagree with you but I still think I have a good point. He should have gone to the ICO straight away as well as report directly to moonpig then if it wasn't fixed within x amount of time, take next escalation step (which may or may not be public disclosure). Given that it's midnight in the UK now, we're lucky that they acted so quickly (assuming the offline API isn't just scheduled downtime). Going public ha…

I'll add my two cents a non-Brit: I have never heard of the ICO until this thread. Someone please correct me, but the closest thing we have in the states may be contacting the Attorney General? I say this thinking of the argument the rest of the world makes when the DMCA threat is used against a non-US entity.

Moonpig is UK based. He could have looked up how to report a data breach in the UK.

Not sure what the DMCA reference is about. I understand that people use DMCS on companies that are not US based therefore it has no power. Still not sure why you mentioned that though.

Re: Moonpig.com Vulnerability – Exposes customer data

#52
post #42
post #27

This is irresponsible disclosure. You should have contacted the information commissioners office. They would have used legal powers to force Moonpig to rectify this. There are very steep penalties for not protecting customer data. Now that you've publicly disclosed this, opportunists (people one level above script kiddies) will probably grab a data dump and compromise every customer. Dealing with this via legal chann…

That's a pretty heavy handed definition of irresponsible disclosure. The onus of patching security flaws is on the company, not the security researcher. Responsible disclosure is a courteous and respectful form of helping a company fix their vulnerabilities, but it ceases to be responsible if agreeing to keep a vulnerability private enables the company to swipe it under the rug. Top security talent at Facebook and Go…

I still don't see why he had to do this?

He has plenty of time to inform the ICO of this issue. He contacted moonpig then let the sit on this for a year.

If he wants to be a disclosure hero, he could have at least told the ICO at the same time he told moonpig.

The issue is 100% Moonpigs fault but he chose to disclose publicly rather than use the legal route set up to deal with these kinds of issues.

The whole responsible disclosure scene needs a reboot and people need educating on the responsible way to deal with these issues. Public disclosure should be a last resort (within reason). Not even contacting the ICO before doing this is shocking to me.

Re: Moonpig.com Vulnerability – Exposes customer data

#53
post #47
post #45

Earlier quoted context omitted.

I don't disagree with you but I still think I have a good point. He should have gone to the ICO straight away as well as report directly to moonpig then if it wasn't fixed within x amount of time, take next escalation step (which may or may not be public disclosure). Given that it's midnight in the UK now, we're lucky that they acted so quickly (assuming the offline API isn't just scheduled downtime). Going public ha…

I'll add my two cents a non-Brit: I have never heard of the ICO until this thread. Someone please correct me, but the closest thing we have in the states may be contacting the Attorney General? I say this thinking of the argument the rest of the world makes when the DMCA threat is used against a non-US entity.

The ICO is a bureaucrat with responsibility for enforcing the Data Protection Act. There is a small amount of overlap with the Surveillance Commissioner who oversees all surveillance, especially under RIPA (regulation of investigatory powers act).

The ICO is reasonably good - I don't get any (personal) junk telephone calls or junk mail because of our laws about how companies handle my data. (This seems like a trivial example now I've typed it! But it did mark a clear difference between before and after ICO).

https://ico.org.uk/

The website and reporting is much better than it used to be. ("Please download, print, and complete this MS Word document, then post it to this address")

Re: Moonpig.com Vulnerability – Exposes customer data

#54
post #52
post #42

Earlier quoted context omitted.

That's a pretty heavy handed definition of irresponsible disclosure. The onus of patching security flaws is on the company, not the security researcher. Responsible disclosure is a courteous and respectful form of helping a company fix their vulnerabilities, but it ceases to be responsible if agreeing to keep a vulnerability private enables the company to swipe it under the rug. Top security talent at Facebook and Go…

I still don't see why he had to do this? He has plenty of time to inform the ICO of this issue. He contacted moonpig then let the sit on this for a year. If he wants to be a disclosure hero, he could have at least told the ICO at the same time he told moonpig. The issue is 100% Moonpigs fault but he chose to disclose publicly rather than use the legal route set up to deal with these kinds of issues. The whole respons…

OP here and I agree with you. The ICO genuinely didn't even cross my mind and in hindsight I probably should of gone via that channel before publicly disclosing. Are there any set procedures to follow for this sort of thing?

Re: Moonpig.com Vulnerability – Exposes customer data

#56
post #51
post #47

Earlier quoted context omitted.

I'll add my two cents a non-Brit: I have never heard of the ICO until this thread. Someone please correct me, but the closest thing we have in the states may be contacting the Attorney General? I say this thinking of the argument the rest of the world makes when the DMCA threat is used against a non-US entity.

Moonpig is UK based. He could have looked up how to report a data breach in the UK. Not sure what the DMCA reference is about. I understand that people use DMCS on companies that are not US based therefore it has no power. Still not sure why you mentioned that though.

Yea, you're right; I thought that some context might be needed after I posted.

They aren't related whatsoever, however the thought process of being put into the same position as the security research in this article is what made the connection for me. Assuming that the author wasn't from the UK (he probably is, but bare with me), as someone from the States I would have assumed that having an email exchange with the company was more than enough especially if there a reply on their end.

From my perspective, again knowing nothing about UK law (as much as people in the UK, China, or Fiji may know about US Law), I wouldn't know where to turn after that. Maybe a teaser post, without disclosing everything? If it weren't for the fact that the author stated that he had several two-way conversations with a representative of the company, I would have more sympathy for moonpig.

Speaking of which: How effective is the ICO?

Re: Moonpig.com Vulnerability – Exposes customer data

#57
post #30

They have 3 other brands: http://photobox.co.uk http://uk.paper-shaker.com https://sticky9.com Only the later seems to enforce SSL. I registered a dummy account on photobox, username/password/email, via their form which was not using ssl.

Photobox acquired Moonpig in 2011 [1]. In 2010, Photobox got called out for emailing passwords in plaintext[2], and were quick to take to twitter to say "It will never happen again."[3] At that point, it had only been happening for 4 years [4].

Coupled with the tone of the job advert already posted by others [5], it doesn't seem too hard to imagine a corporate culture where security is not a serious concern until things go wrong.

[1] http://www.bbc.co.uk/news/business-14275632

[2] http://www.pcpro.co.uk/news/security/360163/photobox-sorry-a...

[3] https://twitter.com/PhotoBox/status/20719242964

[4] http://blog.dave.org.uk/2006/06/more-password-s.html

[5] http://careers.photobox.co.uk/security-officer-moonpig/

[edited for clarity]

Re: Moonpig.com Vulnerability – Exposes customer data

#58

Earlier quoted context omitted.

First of all, the company could definitely be sued for negligence in the US. Not sure if they could in the UK. Second, there are not that many similarities between this research and weev's research. In this case, the researcher created 2 accounts which he had control over, then read data from both of the accounts despite not authenticating to either of them. He did not access any other customer's information (or at l…

Personally (and I know this is likely to be an unpopular sentiment on HN) I have very little sympathy for weev. He knowingly and deliberately attack a weakness he had found to scrape data, knowing that the access was unauthorized. I disagree that the data was in the public domain (although the Third Circuit disagrees) - just because something is accessible to the public doesn't mean it's in the public domain. Just be…

Doubt it's as unpopular as you think.

Re: Moonpig.com Vulnerability – Exposes customer data

#59
post #52

Earlier quoted context omitted.

I still don't see why he had to do this? He has plenty of time to inform the ICO of this issue. He contacted moonpig then let the sit on this for a year. If he wants to be a disclosure hero, he could have at least told the ICO at the same time he told moonpig. The issue is 100% Moonpigs fault but he chose to disclose publicly rather than use the legal route set up to deal with these kinds of issues. The whole respons…

OP here and I agree with you. The ICO genuinely didn't even cross my mind and in hindsight I probably should of gone via that channel before publicly disclosing. Are there any set procedures to follow for this sort of thing?

Another minor consideration - here in the UK this was posted at 10PM - not exactly a friendly hour. It would have been nice to schedule the post for a time when UK businesses expect to operate. I don't expect they would have thanked you for it in any case, but they would probably have had both a better response time and a better organised response

Re: Moonpig.com Vulnerability – Exposes customer data

#60
post #14

http://www.conosco.com/case-studies/moonpig-outsourced-it/ >Protection against cyber attacks Wow...

To be fair to them they were just infrastructure not backend. I'm sure their firewall works perfectly, the trouble is the legitimate traffic that's allowed to do anything it wants!
Post reply on HN