Live data from Hacker News

Moonpig.com Vulnerability – Exposes customer data

ifc0nfig.com

61–70 of 124 posts

Re: Moonpig.com Vulnerability – Exposes customer data

#61

Disgusting - this should be priority one for them to fix. I just changed all my details to ones from a fake name/address generator, then emailed moonpig to close my account. I will lose about 80 pence, but nevermind. I didn't see an option to get rid of my credit card details, so that may still be vulnerable, especially with the NameOnCard field in the api.

I know my mum has a Moonpig account so I'm pissed about this, but I don't recall if I have an account.

Recently, I have mostly been using CFHDocmail. It's 96p for a full colour A5 greeting card of your own design.

(It's also cheaper to use them to send letters than it is for me to buy a stamp. They also do postcards, going as low as 38p delivered. Lots of mailmerge and API stuff available too iirc, but I've never used any of it.)

Edit: They may use windowed envelopes for the cards, when I tested they didn't, but now I've been told they do. I've not sent one to myself since my original testing, and none of the recent recipients have said either way. I'll make a quick one and sent it to myself!

Re: Moonpig.com Vulnerability – Exposes customer data

#62
post #27

This is irresponsible disclosure. You should have contacted the information commissioners office. They would have used legal powers to force Moonpig to rectify this. There are very steep penalties for not protecting customer data. Now that you've publicly disclosed this, opportunists (people one level above script kiddies) will probably grab a data dump and compromise every customer. Dealing with this via legal chann…

Agree with clobec, I think this is irresponsible to disclose this so publicly.

There'll be a lot of collateral damage now.

Re: Moonpig.com Vulnerability – Exposes customer data

#63
post #59

Earlier quoted context omitted.

OP here and I agree with you. The ICO genuinely didn't even cross my mind and in hindsight I probably should of gone via that channel before publicly disclosing. Are there any set procedures to follow for this sort of thing?

Another minor consideration - here in the UK this was posted at 10PM - not exactly a friendly hour. It would have been nice to schedule the post for a time when UK businesses expect to operate. I don't expect they would have thanked you for it in any case, but they would probably have had both a better response time and a better organised response

They had 17 months, and their Twitter account was still posting at 9pm this evening.

If they gave two shits about our data (and it might include mine, it definitely includes my mum's), or if they were capable of a sensible helpful coherent response, they'd have done it 16.5 months ago.

Re: Moonpig.com Vulnerability – Exposes customer data

#64

To anyone thinking of enumerating the customer IDs to play with this, be very careful as it's illegal in the USA. That is exactly what weev was arrested and convicted for.

Or don't do it in the first place, because it's obviously wrong...

Re: Moonpig.com Vulnerability – Exposes customer data

#65
post #43
post #27

This is irresponsible disclosure. You should have contacted the information commissioners office. They would have used legal powers to force Moonpig to rectify this. There are very steep penalties for not protecting customer data. Now that you've publicly disclosed this, opportunists (people one level above script kiddies) will probably grab a data dump and compromise every customer. Dealing with this via legal chann…

You're getting mad at the wrong person here, full stop. This is gross, inexcusable negligence and incompetence. I'm surprised this guy didn't wait more than a few months, given the severity of this problem. > whilst protecting customer data from any opportunistic bad actor Riiiight. Do you honestly think something this basic wouldn't be discovered by criminals soon, if not already?

I would say that the period August 2013 to January 2015 is more than "a few months".

Re: Moonpig.com Vulnerability – Exposes customer data

#66
post #14

http://www.conosco.com/case-studies/moonpig-outsourced-it/ >Protection against cyber attacks Wow...

To be fair to them they were just infrastructure not backend. I'm sure their firewall works perfectly, the trouble is the legitimate traffic that's allowed to do anything it wants!

So they delegated security to a separate team, which only got to put "reinforced firewalls and IPS appliances" around an app which was still missing basic internal security checks. (And it's hard to see how firewalls could do the checks on their own, without access to the app's data stores or duplicating app logic -- either of which makes it no longer a firewall.)

Unfortunately, it's all too easy to get this kind of partial solution from a "security team" that's distinct from (and worse, sometimes hostile to) the team that actually develops the app.

Re: Moonpig.com Vulnerability – Exposes customer data

#67
post #63
post #59

Earlier quoted context omitted.

Another minor consideration - here in the UK this was posted at 10PM - not exactly a friendly hour. It would have been nice to schedule the post for a time when UK businesses expect to operate. I don't expect they would have thanked you for it in any case, but they would probably have had both a better response time and a better organised response

They had 17 months, and their Twitter account was still posting at 9pm this evening. If they gave two shits about our data (and it might include mine, it definitely includes my mum's), or if they were capable of a sensible helpful coherent response, they'd have done it 16.5 months ago.

Have you read any of the above?

It's clear they didn't care, that's why I'm saying the ICO should have been informed. That would force them to give a shit.

Re: Moonpig.com Vulnerability – Exposes customer data

#68
post #57
post #30

They have 3 other brands: http://photobox.co.uk http://uk.paper-shaker.com https://sticky9.com Only the later seems to enforce SSL. I registered a dummy account on photobox, username/password/email, via their form which was not using ssl.

Photobox acquired Moonpig in 2011 [1]. In 2010, Photobox got called out for emailing passwords in plaintext[2], and were quick to take to twitter to say "It will never happen again."[3] At that point, it had only been happening for 4 years [4]. Coupled with the tone of the job advert already posted by others [5], it doesn't seem too hard to imagine a corporate culture where security is not a serious concern until thi…

The number of companies that send (and possibly store) plain text passwords is scary. I keep reporting them to http://plaintextoffenders.com/

Re: Moonpig.com Vulnerability – Exposes customer data

#69
post #63
post #59

Earlier quoted context omitted.

Another minor consideration - here in the UK this was posted at 10PM - not exactly a friendly hour. It would have been nice to schedule the post for a time when UK businesses expect to operate. I don't expect they would have thanked you for it in any case, but they would probably have had both a better response time and a better organised response

They had 17 months, and their Twitter account was still posting at 9pm this evening. If they gave two shits about our data (and it might include mine, it definitely includes my mum's), or if they were capable of a sensible helpful coherent response, they'd have done it 16.5 months ago.

In reply to the child post (of my other comment), because I can't do so directly due to nesting limited:

>Have you read any of the above?

>It's clear they didn't care, that's why I'm saying the ICO should have been informed. That would force them to give a shit.

I had, at the time of writing my post, read all the comments on this story. I was commenting specifically on the parent's point about what time of day the story of was posted. I don't disagree with you re: ICO.

However I don't think it's fair to characterize the disclosure as irresponsible. The fault lies with the vendor for not patching. Publicizing guy followed industry standard practices for responsible disclosure. Vendor is just fucking useless.

I'm unhappy, as I'm sure it'll cause an increase in spam and possibly spearphishing to my mum, which I will subsequently have to deal with. Yey. But that's Moonpig's fault.

Edit: And in response to the response to the response...

>Why are you saying the fault lies with the vendor? Do you think nobody knows that? Do you think that's not obvious? Do you think that's what I was commenting about?

Because it does. No, I think everyone knows that, however it was relevant to the rest of the paragraph. I don't think that was what your child post was about, however I didn't want to make ANOTHER post to voice my opinion.

>There's a difference between reading and comprehension.

I read AND UNDERSTOOD the comments, I was of course referring to your rhetorical question implying that I hadn't even read them. Apparently you didn't comprehend that?

Re: Moonpig.com Vulnerability – Exposes customer data

#70

To anyone thinking of enumerating the customer IDs to play with this, be very careful as it's illegal in the USA. That is exactly what weev was arrested and convicted for.

Or don't do it in the first place, because it's obviously wrong...

>because it's obviously wrong... //

Are you trying to say it's morally wrong to read data made publicly available through a site's API? I think that's a stretch. Clearly there are very obviously malevolent things you could do with data acquired with such queries, but just iterating on a URL query string seems pretty far from an obvious moral wrong.

Legally questionable, for sure. Morally forthright, doubtful.

The wrong comes in using data nefariously, surely; not in merely observing it.

Post reply on HN