This is nice to know... :( [Archive] - SpeedGuide.net Broadband Community

View Full Version : This is nice to know... :(


denolth2
11-21-01, 10:28 AM
Just when you thought things couldn't get worse, saw this news article on wired.com....

A Tell-All ZD Would Rather Ignore
By Declan McCullagh
2:00 a.m. Nov. 20, 2001 PST
If you subscribe to any of Ziff Davis' computer magazines, you may want to double-check your credit card bill next month.
Ziff Davis Media, which publishes such popular tech titles such as Yahoo Internet Life and PC Magazine, accidentally posted the personal information of about 12,500 magazine subscribers on its website.
On Monday, Ziff Davis removed the data, which included hundreds of credit card numbers, and said its engineers had taken steps to prevent additional security leaks.
"We discovered that there was a problem on the site and we pulled the information down," said Ziff Davis spokesman Randy Zane. "We're contacting all the subscribers -- the people who were affected."
Because Ziff Davis' 1.3-MB text file included names, mailing addresses, e-mail addresses and in some cases credit card numbers, a thief who downloaded it would have enough information to make fraudulent mail-order purchases. An executive at one New York magazine firm called the error "a bush-league mistake for a major online publisher."
Zane said Ziff Davis relies on EDS and Omeda database technology to protect subscriber information. He refused to provide details, except to say that "we were doing a promotion not using the EDS and Omeda products."
In interviews, two people who appeared on the Ziff Davis list said they had typed in their information when responding to a promotion for Electronic Gaming Monthly.
"I went to the site and signed up for the free year, but did not sign up for the second year, which was not free," said Jerry Leon of Spokane, Washington, whose Visa number and expiration date appeared in the file. "I get the feeling that this was one huge scam, but that card is now dead, and any charges made on it will be refused."
"If it was just a stupid accident, they are going to regret failing a community that worries about this stuff ever happening, but if something less innocent has occurred, they may as well fold the tents," said Leon, who signed up through AnandTech's hot deals forum.
Rob Robinson, whose address information -- but not credit card number -- was on display, says he subscribed to Electronic Gaming Monthly through a promotion on ebgames.com.
"I'm annoyed that my home info as well as a valid e-mail is available to anyone. That's quite a valuable list of gamers' personal data up for grabs. I feel really bad for the poor folks who are going to have to cancel their credit cards," Robinson said.
It's not clear whether Electronic Gaming Monthly subscribers were the only ones affected by the security snafu, and Ziff Davis refused to provide details. The file appeared at the address http://www.zdmcirc.com/formcollect/ebxbegamfile.dat until around noon EST on Monday.
That address began circulating around Home Theater Forum discussion groups over the weekend, and Ziff Davis at first erased the contents of the database at around 9 a.m. EST Monday. But its system continued to add new subscribers to the public file until Ziff Davis administrators blocked access to that address around midday Monday.
"Every week we learn of new cases where companies used insecure technology or unsecure servers to handle business that utilizes financial information or customer information," says Jericho, who edits the security news site attrition.org. "In the rush to be e-appealing for e-business they e-screw up time and time again."
Jericho has compiled a list of miscreant firms whose shoddy security practices have exposed customer information. The hall of shame includes notables such as Amazon, Gateway, Hotmail and Verizon.
Ziff Davis Media publishes 11 print magazines. It is a separate company from ZDNet, which is owned by CNET Networks.

Ain't it lovely that these corporate IT folks still haven't got their act together? After all this time? :) :( :o :D ;) :rolleyes: :confused: :mad:
den2 ;O

CompGeek83
11-23-01, 12:39 AM
ha the funny part about this is my subscription to EGM is about up and my moms credit card statement has a new charge resubscribing me to EGM, but we didn't authorize them to continue my subscription, she called the credit card and had the charge marked as "unauthorized"

master7
12-11-01, 05:06 PM
LoL. The EGM thing was a crackup.

This is why:

I went to they site to subscribe - and to my security-probing inner child's glee - the posted information went right to a public-access .DAT file. That includes CC numbers, such as your mom's probably. They have since fixed the problem - but it was weird.

BTW: This is just for people to check up on if their CC # was leeked, don't be stupid.

And YES, I am in there (Jeff Kimbro)

[edit]

On 2nd thought, I have taken off the link of the mirror of the DAT file, but if you would like to know if you are affected, just respond w/ your real name, and I will take a look to see if your CC # is there. Also, if someone requests it, I will link it again, but until then, I don't trust anyone enough to link it.

Croc
12-12-01, 01:30 AM
Same old, same old!!!!

This story has surfaced before. LOL

Seen it at least 3 times and the only change is the date the "leak" was supposed to have happened. All other wording > the same right down to "your mother's credit card.

If true they have a real ongoing security problem that would driven them out of e-commerce.

Have fun.

Croc.