WARNING: Your DDD Details Are Not Safe! (merged)
#251
DVD Talk Legend
I could log in and see my info during the height of the problem, but I could NOT log in and see random other people's info as well.
I can still log in OK, and for the last few hours I haven't gotten other people's accounts to pop up. Others say they still see the issue as recently as an hour or two ago.
I can still log in OK, and for the last few hours I haven't gotten other people's accounts to pop up. Others say they still see the issue as recently as an hour or two ago.
#254
DVD Talk Hall of Fame
Joined: Dec 1999
Posts: 9,464
Likes: 0
Received 1 Like
on
1 Post
From: Formerly known as (ahem) "LASERMOVIES"/California
Originally posted by invisiblegt
We're still in the early stages of internet commerce, technically speaking. There are bound to be errors and mishaps. This is one such mishap.
People make mistakes...
We're still in the early stages of internet commerce, technically speaking. There are bound to be errors and mishaps. This is one such mishap.
People make mistakes...
#257
Suspended
Joined: Mar 2004
Posts: 243
Likes: 0
Received 0 Likes
on
0 Posts
I'm still getting other people's account information when I click the DDD link.
Here's another security issue I discovered. I was chatting with a friend on AOL, and my friend copy and pasted the URL from DDD, and sent it to me via 'IM'. When I clicked that link...I was logged into her account.
DDD obviously has little regard for the privacy and security of the personal information we trust them to protect.
Here's another security issue I discovered. I was chatting with a friend on AOL, and my friend copy and pasted the URL from DDD, and sent it to me via 'IM'. When I clicked that link...I was logged into her account.
DDD obviously has little regard for the privacy and security of the personal information we trust them to protect.
#258
Suspended
Joined: Jan 2002
Posts: 3,964
Likes: 0
Received 0 Likes
on
0 Posts
From: Flava-Country!
Originally posted by DrGerbil
Hear that, DDD? Plan a 30% off sale to assuage our discontent...
Hear that, DDD? Plan a 30% off sale to assuage our discontent...
To allow the slip-up to occur is human error - bad, but shit happens. To allow it to go unchecked for the whole god damned weekend (cause you know there isnt going to be anyone in on sunday) is negligent.
#262
Member
Joined: Jun 2004
Posts: 86
Likes: 0
Received 0 Likes
on
0 Posts
From: San Francisco
Just a warning update:
The problem is NOT fixed over 24 hours later.
I just recieved an email from a kind DDD customer who said he was logged into my account. He even sent me a screen shot, and sure enough, all my account information was right there in the hands of a complete stranger.
I've always really liked DDD, but this is too much.
The problem is NOT fixed over 24 hours later.
I just recieved an email from a kind DDD customer who said he was logged into my account. He even sent me a screen shot, and sure enough, all my account information was right there in the hands of a complete stranger.
I've always really liked DDD, but this is too much.
#263
Moderator
Just click a link or type in the address and you're in. It was only down briefly this morning.
#264
Senior Member
Joined: Feb 2001
Posts: 299
Likes: 0
Received 0 Likes
on
0 Posts
Ever hear of irony and sarcasm?
Originally posted by LASERMOVIES
The sale is going on right now. Just find an account with a credit card you can use and change the shipping address to yours. Be sure to add overnight delivery to get your order fast.
Seriously that question has been asked a million times and there isn't a definite answer or date. But this glitch will probably make a sale inevitable sooner rather than later to try and win the confidence back of customers.
The sale is going on right now. Just find an account with a credit card you can use and change the shipping address to yours. Be sure to add overnight delivery to get your order fast.
Seriously that question has been asked a million times and there isn't a definite answer or date. But this glitch will probably make a sale inevitable sooner rather than later to try and win the confidence back of customers.
#265
New Member
Joined: Oct 2004
Posts: 22
Likes: 0
Received 0 Likes
on
0 Posts
I haven't yet tried logging into my account this morning, but I suspect the problem still hasn't been solved. I'm going to try re-installing Internet Explorer and try logging in through IE instead of AOL and see if that works so i can delete my info.
I did receive an email from another customer yesterday, just for the record I don't bother looking at other customers' account info, I just want to get into my own account.
I hope the problem is resolved soon, I really don't want to stop ordering from DeepDiscount, I ordered twice from them and their prices are great and their shipping services are also very good.
I did receive an email from another customer yesterday, just for the record I don't bother looking at other customers' account info, I just want to get into my own account.
I hope the problem is resolved soon, I really don't want to stop ordering from DeepDiscount, I ordered twice from them and their prices are great and their shipping services are also very good.
#266
DVD Talk Special Edition
Joined: Mar 2004
Posts: 1,930
Likes: 0
Received 0 Likes
on
0 Posts
From: Western PA, Central Florida
Originally posted by Ginwen
Also I thought I'd remind others who haven't gone in yet it doesn't actually show your cc #, just the last 4 digits, and you can't change the shipping info without re-entering the card info, so the worst that is likely to happen is that someone will order a bunch of DVDs to be shipped to your address (in which case, cancelling should be pretty easy).
Also I thought I'd remind others who haven't gone in yet it doesn't actually show your cc #, just the last 4 digits, and you can't change the shipping info without re-entering the card info, so the worst that is likely to happen is that someone will order a bunch of DVDs to be shipped to your address (in which case, cancelling should be pretty easy).
What exactly is the security problem you people are complaining about?
As posted above, no one can get your credit card information.
As posted, no one can change the shipping address so dvd's cannot be paid by you and shipped to someone else.
The very worst might happen is a) someone might be able to order you more dvd's or b) someone can see what you have previously ordered.
Or, is that the problem, you don't want someone to see you actually did order Nurse Betty?
Its a freekin' glitch. Happens often on the net. More than you know. Lighten up!
If you don't want to order from DDD anymore then don't. That will save bandwidth so we can place out multiple orders next time they have a sale!
#267
DVD Talk Platinum Edition
Joined: Sep 2000
Posts: 3,380
Likes: 0
Received 0 Likes
on
0 Posts
Disclosing customer details like full name, address, phone number and email is a serious problem as it practically invites identity theft. Maybe you have not experienced identity theft yourself yet, but I can assure you that it is a huge ordeal.
#268
Senior Member
Joined: Feb 2003
Posts: 630
Likes: 0
Received 0 Likes
on
0 Posts
From: Texas
I just logged into my account and it was correct. I changed the info to bill me later though and checked to see if there were any recent or open orders and there were none thankfully. There really is no reason not to shut down the site completely until the problem has been resolved. In addition all recent orders should be cancelled. This is ridiculous really.
#269
DVD Talk Legend
Originally posted by Jah-Wren Ryel
Disclosing customer details like full name, address, phone number and email is a serious problem as it practically invites identity theft. Maybe you have not experienced identity theft yourself yet, but I can assure you that it is a huge ordeal.
Disclosing customer details like full name, address, phone number and email is a serious problem as it practically invites identity theft. Maybe you have not experienced identity theft yourself yet, but I can assure you that it is a huge ordeal.
My name, address and phone number have already been printed several million times in the phone book, and considering the amount of spam I receive, my email addresses are not well-kept secrets. What information that could lead to identity theft has actually been compromised?
#270
Member
Joined: Apr 2003
Posts: 215
Likes: 0
Received 0 Likes
on
0 Posts
I tend to agree that this is not a particularly big deal. The only information that is readily visible on the site is the same information that can be obtained by typing my name into Google. My only concern is that some prankster might have ordered a ton of DVD's and had them sent to me. I changed my billing method to Bill Me Later, so I am not even worried about that any more. Compared to the DVDPacific fiasco, this is minor.
#272
DVD Talk Special Edition
Joined: Jun 2004
Posts: 1,187
Likes: 0
Received 0 Likes
on
0 Posts
From: Durham, NC
This is why I love my Citibank virtual account number program. It generates a random account number that can only be used once by a particular merchant, and expires in a month.
#274
DVD Talk Hero
Originally posted by Jim
I haven't logged in to DDD for over a month. Do you think it's better to just stay out for now or to login and change my info?
I haven't logged in to DDD for over a month. Do you think it's better to just stay out for now or to login and change my info?
There are plenty of other places to get DVDs so I'm going to wait to see what DDD has to say about the situation.
Originally posted by seymouru
Minor or not, they should take the site down while this problem is occurring.
Minor or not, they should take the site down while this problem is occurring.
#275
Suspended
Joined: Jan 2002
Posts: 3,964
Likes: 0
Received 0 Likes
on
0 Posts
From: Flava-Country!
Originally posted by marty888
My name, address and phone number have already been printed several million times in the phone book, and considering the amount of spam I receive, my email addresses are not well-kept secrets. What information that could lead to identity theft has actually been compromised?
My name, address and phone number have already been printed several million times in the phone book, and considering the amount of spam I receive, my email addresses are not well-kept secrets. What information that could lead to identity theft has actually been compromised?



