Opcode Online Store Poor Security


Subject: Opcode Online Store Poor Security
From: Shawn Pinchbeck (beams@telusvelocity.net)
Date: Sun Jul 11 1999 - 23:49:52 EDT


 Hi Cecdiscuss,

I just thought I would drop everyone a note of warning about the Opcode
online store.

The other day, I needed an upgrade of Max in a hurry, so I used Opcode's
online "secure" store. I know better than to trust goofy technology, but
I did it anyways! Well the online thing worked fine in its 128-bit
glory, but when the lame person at the other end received my order they
send a copy back to me through email with my VISA card number and expiry
date. This of course defeated the entire purpose of secure shopping by
sending everything through unsecure email. Now I'm hoping that all the
hackers on the planet aren't aware of their lax security and aren't
packet sniffing their mail server and making a collection of credit card
numbers.

I'm not impressed!

Shawn Pinchbeck
beams@telusvelocity.net



This archive was generated by hypermail 2b27 : Wed Jun 11 2003 - 13:09:02 EDT