Opcode Online Store Poor Security

Subject: Opcode Online Store Poor Security
From: Shawn Pinchbeck (beams@telusvelocity.net)
Date: Sun Jul 11 1999 - 23:49:52 EDT

 Hi Cecdiscuss,

I just thought I would drop everyone a note of warning about the Opcode
online store.

The other day, I needed an upgrade of Max in a hurry, so I used Opcode's
online "secure" store. I know better than to trust goofy technology, but
I did it anyways! Well the online thing worked fine in its 128-bit
glory, but when the lame person at the other end received my order they
send a copy back to me through email with my VISA card number and expiry
date. This of course defeated the entire purpose of secure shopping by
sending everything through unsecure email. Now I'm hoping that all the
hackers on the planet aren't aware of their lax security and aren't
packet sniffing their mail server and making a collection of credit card

I'm not impressed!

Shawn Pinchbeck

This archive was generated by hypermail 2b27 : Wed Jun 11 2003 - 13:09:02 EDT