Live data from Hacker News

Moonpig.com Vulnerability – Exposes customer data

ifc0nfig.com

91–100 of 124 posts

Re: Moonpig.com Vulnerability – Exposes customer data

#91

Earlier quoted context omitted.

My guess is that the ICO wont fine them very much as it did not include full credit card numbers. However they might up it for failings in process, lots of remedial measures etc. They might not even have PCI compliance issues alas. The management will argue that they knew nothing, although that is becoming less of a defence now.

Social engineering once you have the last four digits of the credit card number and the billing address is almost certainly enough to score full credit card numbers. (e.g. use them to reset password for e.g. Amazon account).

Not to mention that the first few will be in a certain range (or possibly with a certain prefix) depending on the card type. Oh, and the last one is the check digit.

SSNs are worse, though. The last four digits plus your birth date & location might just give the whole thing away.

Re: Moonpig.com Vulnerability – Exposes customer data

#92

Earlier quoted context omitted.

Personally (and I know this is likely to be an unpopular sentiment on HN) I have very little sympathy for weev. He knowingly and deliberately attack a weakness he had found to scrape data, knowing that the access was unauthorized. I disagree that the data was in the public domain (although the Third Circuit disagrees) - just because something is accessible to the public doesn't mean it's in the public domain. Just be…

I agree, and feel that the EFF made quite the strategic error in supporting Auernheimer's appeal.

Weev should probably be in jail for several reasons. Just not the specific reason they sent him to jail for. The EFF had to fight because the conviction set a really bad precedent for other research.

Re: Moonpig.com Vulnerability – Exposes customer data

#93
post #90

Earlier quoted context omitted.

"you are a terrible human being" is not really a simple disagreement. "That seems like a rude thing to do" would be. What you said was a personal attack, and a quite rude one at that.

> What you said was a personal attack, and a quite rude one at that. That's correct, and no doubt the reason for the downvotes.

The downvotes here have grown way out of control. Simple disagreement with the majority opinion results in massive downvoting.

I've even seen numerous posts that contain nothing but factual information that displeases the audience here be voted down into the gray. The post can be in the flattest, most neutral tone possible, and if it's not what people want to hear, down it goes.

It's discouraging, and it's to a point where I no longer feel a desire to participate in this community. Frankly, I'm finding a number of subreddits to be more inviting and more interesting these days.

I don't really see what can be done about it, if you even agree it's an issue, but I did want to make a point of letting you know about a problem I've seen grow worse over recent months.

Re: Moonpig.com Vulnerability – Exposes customer data

#94
post #47
post #45

Earlier quoted context omitted.

I don't disagree with you but I still think I have a good point. He should have gone to the ICO straight away as well as report directly to moonpig then if it wasn't fixed within x amount of time, take next escalation step (which may or may not be public disclosure). Given that it's midnight in the UK now, we're lucky that they acted so quickly (assuming the offline API isn't just scheduled downtime). Going public ha…

I'll add my two cents a non-Brit: I have never heard of the ICO until this thread. Someone please correct me, but the closest thing we have in the states may be contacting the Attorney General? I say this thinking of the argument the rest of the world makes when the DMCA threat is used against a non-US entity.

The ICO is pretty well known in the UK though. I'm not from the UK and I know about them. (Mostly because of their role in the whole eu-cookie-law farce)

Re: Moonpig.com Vulnerability – Exposes customer data

#95

In the address example you can even emit the arguments and it just returns you a large list of addresses. Would expect this to be hitting the news here in the UK tomorrow! Judging by their parent companies website they seem to be PCI certified ( http://careers.photobox.co.uk/security-officer-moonpig/ ) which is likely to be removed from them after this, also given the private information on show I would expect this b…

Been a while since I read PCI DSS but if the PAN isn't there, does it specify you have to protect that information? Also, if they don't actually have the PAN touch their servers (like, using a BrainTree or Stripe-like solution), PCI compliance is quite minimal. Even PCI DSS 3.0 is trivial to deal with using Stripe (they just insert an iframe so the CC info goes directly to their site). Of course, yeah, they don't des…

Reading that job spec I assumed they handle all the PCI side of things themselves, if using stripe etc I doubt you'd need such an involved role.

Given the mess it looks like on the front, I would bet PAN's are stored in clear text too!

Re: Moonpig.com Vulnerability – Exposes customer data

#96
My comment from the other thread:

They also make it very difficult to delete your account. Rather than just have a link on the site, you have to contact customer services and they say they'll respond in 24-48 hours.

Not to mention the ways they try to hide you removing your card details. If you want to remove your card details, do the following:

The easiest way to do this would be to go to the My Account page then click on the ‘Add Moonpig Prepay Credit’ link, click on the Buy link and your saved card details will be shown onscreen. Click on the ‘Remove Card’ option.

Re: Moonpig.com Vulnerability – Exposes customer data

#97

Earlier quoted context omitted.

Personally (and I know this is likely to be an unpopular sentiment on HN) I have very little sympathy for weev. He knowingly and deliberately attack a weakness he had found to scrape data, knowing that the access was unauthorized. I disagree that the data was in the public domain (although the Third Circuit disagrees) - just because something is accessible to the public doesn't mean it's in the public domain. Just be…

I agree, and feel that the EFF made quite the strategic error in supporting Auernheimer's appeal.

The trouble with fighting for human freedom is that one spends most of one’s time defending scoundrels. For it is against scoundrels that oppressive laws are first aimed, and oppression must be stopped at the beginning if it is to be stopped at all.

— H. L. Mencken

Re: Moonpig.com Vulnerability – Exposes customer data

#98

I am a former customer of theirs (in the UK) and just contacted CS about this. I'm also looking into contacting the Information Commissioner's Office as this issue is still open and my personal information (and that of the people I send cards to) is still available to anyone who may want it. I'm pretty sure them ignoring this for a year is illegal as it involves personal information which their privacy policy didn't…

Do it.

I work in eCommerce, we develop a platform - and this stuff pisses me off no end, as it tarnishes the entire industry, and we'll now be dealing with jumpy clients for a month after this news hits the trade rags.

Re: Moonpig.com Vulnerability – Exposes customer data

#99
post #90

Earlier quoted context omitted.

> What you said was a personal attack, and a quite rude one at that. That's correct, and no doubt the reason for the downvotes.

The downvotes here have grown way out of control. Simple disagreement with the majority opinion results in massive downvoting. I've even seen numerous posts that contain nothing but factual information that displeases the audience here be voted down into the gray. The post can be in the flattest, most neutral tone possible, and if it's not what people want to hear, down it goes. It's discouraging, and it's to a point…

Do you have links to examples?

Re: Moonpig.com Vulnerability – Exposes customer data

#100

Earlier quoted context omitted.

Or don't do it in the first place, because it's obviously wrong...

> because it's obviously wrong... // Are you trying to say it's morally wrong to read data made publicly available through a site's API? I think that's a stretch. Clearly there are very obviously malevolent things you could do with data acquired with such queries, but just iterating on a URL query string seems pretty far from an obvious moral wrong. Legally questionable, for sure. Morally forthright, doubtful. The wr…

I don't think there's any ambiguity here. Deliberately downloading personal information—clearly not intended to be released publicly—does not seem to be a defensible action.

We're not talking about downloading a couple of records and alerting someone about it, after all.

Post reply on HN