WARNING: Your DDD Details Are Not Safe! (merged)
#201
Senior Member
DDD, DDCD, Digital Eyes, and DVDPlanet are all apparently owned by Infinity Resources--all this is from searching DVD Talk. I called this number below and they closed at 3 CST and won't open until Monday (if they do--it is a holiday in some places). I take it some of you were able to talk to csr's? I am too chicken to go to the site but thought I would pass this info on since I remembered this from the past. Also tried to get an operator on this number but no luck.
Deke Rivers wrote this about a year ago for the bricks and mortar store:
"Its called Music Movies and More
900 North Rohlwing Road
Itasca IL
(630)-775-3300 x5175
Its between Thorndale and Irving on Rohlwing
West side of Rohlwing"
Deke Rivers wrote this about a year ago for the bricks and mortar store:
"Its called Music Movies and More
900 North Rohlwing Road
Itasca IL
(630)-775-3300 x5175
Its between Thorndale and Irving on Rohlwing
West side of Rohlwing"
#202
Senior Member
Originally posted by Eric F
By posting this here and having me log-in you just made my account accessable by other people. The thread in the store-forum says:
By posting this here and having me log-in you just made my account accessable by other people. The thread in the store-forum says:
#203
DVD Talk Gold Edition
Joined: Jul 2002
Posts: 2,342
Likes: 0
Received 0 Likes
on
0 Posts
From: Papillion, NE!
I checked my account and everything was okay. I made some changes like deleted my CC, then logged out. Logged back in and everything was still fine, but when I tried to logged out it wouldn't let me. So I exited out of the internet and deleted all cookies. That did it.
So, hopefully everything will be okay and hopefully nobody got hurt during this problem. Its plenty spooky.
So, hopefully everything will be okay and hopefully nobody got hurt during this problem. Its plenty spooky.
#204
Member
Joined: Jun 2004
Posts: 86
Likes: 0
Received 0 Likes
on
0 Posts
From: San Francisco
Hmm, I thought everything was fixed (it's already 4:30PM PST), but when I went to the site, I had total access to a guy named David's account. Unfortunately, I had signed onto my own account on another browser and was unable to log off until I cleared all DDD cookies.
#205
Member
Joined: Sep 2001
Posts: 163
Likes: 0
Received 0 Likes
on
0 Posts
This is a big deal in terms of a reputation hit. But I can dispute charges pretty easily with AmEx. I'm not sweating things and I'll continue to shop at DDD. I just hope they improve their IT infrastructure.
#206
DVD Talk Legend
So what's the consensus? When I left at 3pm central I could still see other accounts, but tonight I can't any more. I got brave and logged into my account. I logged in and out fine.
So is this fixed? Did anyone ever hear from DDD?
Something else to remember: If someone was to get into your account, change your email, get your password emailed to them, then change your email back without you knowing, they would have your email/password combo...even after the site is corrected.
So is this fixed? Did anyone ever hear from DDD?
Something else to remember: If someone was to get into your account, change your email, get your password emailed to them, then change your email back without you knowing, they would have your email/password combo...even after the site is corrected.
#207
New Member
Joined: Oct 2004
Posts: 22
Likes: 0
Received 0 Likes
on
0 Posts
Hi, I've been experiencing this problem all day, it's
9:15 EST and still can't log into my account. I managed to log in once this morning, thought the problem was fixed and haven't been able to log in again. I've been trying for the past half hour and kept getting other accounts, should I continue trying to log in or wait until the problem is solved? I've been using AOL if that helps.
I hope the problem does get fixed soon, as I would still like to continue shopping with them, as their prices and shipping service are very good.
9:15 EST and still can't log into my account. I managed to log in once this morning, thought the problem was fixed and haven't been able to log in again. I've been trying for the past half hour and kept getting other accounts, should I continue trying to log in or wait until the problem is solved? I've been using AOL if that helps.
I hope the problem does get fixed soon, as I would still like to continue shopping with them, as their prices and shipping service are very good.
#210
Member
Joined: Apr 2002
Posts: 207
Likes: 0
Received 0 Likes
on
0 Posts
From: Upper West Side of the Center of the Universe
I just checked their site again - 9:30 EST and it logged me directly into Stephen's account... It's hard to believe that they won't just take their site off-line until they figure out how to fix their issues.
#211
DVD Talk Special Edition
Joined: Jul 2003
Posts: 1,038
Likes: 0
Received 0 Likes
on
0 Posts
From: Falls Church, VA
Yeah, at this point, this has passed into the stage of being utterly ridiculous. Early this morning and now tonight I've been getting a variety of "Hello, Soandsos!"
Clearly people from this board have gotten in contact with DDD, so they are aware of the issue. I would think such a serious case of more than likely a shitty security system allowing people to defraud their customers would catch their attention. Leaving the site up is just absurd.
I logged on around midnight to place an order unaware of this issue and then later when it was mentioned on DVDtalk around 5am... I couldn't change the credit card info at that time and gave up. Thankfully no one screwed around on my account today, but not for a lack of DDD allowing them access to.
I have to say, I think I'm done with them for the time being. This security hole is unacceptable this day and time for even ten minutes... But twenty four hours, and it's still ongoing? I'll pay a couple bucks more and use a site that cares about security and customer protection.
Clearly people from this board have gotten in contact with DDD, so they are aware of the issue. I would think such a serious case of more than likely a shitty security system allowing people to defraud their customers would catch their attention. Leaving the site up is just absurd.
I logged on around midnight to place an order unaware of this issue and then later when it was mentioned on DVDtalk around 5am... I couldn't change the credit card info at that time and gave up. Thankfully no one screwed around on my account today, but not for a lack of DDD allowing them access to.
I have to say, I think I'm done with them for the time being. This security hole is unacceptable this day and time for even ten minutes... But twenty four hours, and it's still ongoing? I'll pay a couple bucks more and use a site that cares about security and customer protection.
#213
Wow. I've wanted to give them the benefit of the doubt on this, but if they're knowingly leaving the site up while the problem is still occurring, that's inexcusable.
They have a history of communicating pretty openly with this forum. It'll be interesting to hear their explanation, and how they attempt damage control. This could have huge implications for their business.
They have a history of communicating pretty openly with this forum. It'll be interesting to hear their explanation, and how they attempt damage control. This could have huge implications for their business.
#214
DVD Talk Legend
Originally posted by AndyMorrison
There's a huge difference between having your site hacked and arbitrarily displaying confidential data to site visitors. If someone had hacked DDD I would be more sympathetic. The fact that this is of DDD's doing and keeps occurring places it in a completely different category.
There's a huge difference between having your site hacked and arbitrarily displaying confidential data to site visitors. If someone had hacked DDD I would be more sympathetic. The fact that this is of DDD's doing and keeps occurring places it in a completely different category.
#215
DVD Talk Gold Edition
Joined: Nov 2003
Posts: 2,893
Likes: 0
Received 0 Likes
on
0 Posts
From: currently Philly originally from Puerto Rico
Originally posted by Bill Needle
Something else to remember: If someone was to get into your account, change your email, get your password emailed to them, then change your email back without you knowing, they would have your email/password combo...even after the site is corrected.
Something else to remember: If someone was to get into your account, change your email, get your password emailed to them, then change your email back without you knowing, they would have your email/password combo...even after the site is corrected.
Angel
#216
DVD Talk Special Edition
Joined: Aug 2004
Posts: 1,716
Likes: 0
Received 0 Likes
on
0 Posts
As it stands (10:27 EST), I logged into DDD under my username.
The title in the corner read "Welcome Matthew." I checked out each link at the top of the page (Home, Help, etc.) and everything worked fine.
My info was still there, and upon cursory glance, nothing was changed.
My order status showed nothing new had been ordered, nor anything added to my shopping cart.
I clicked "log out" and it logged me right out. (I use Opera, FYI.)
So, for me, everything seems to be in order.
The title in the corner read "Welcome Matthew." I checked out each link at the top of the page (Home, Help, etc.) and everything worked fine.
My info was still there, and upon cursory glance, nothing was changed.
My order status showed nothing new had been ordered, nor anything added to my shopping cart.
I clicked "log out" and it logged me right out. (I use Opera, FYI.)
So, for me, everything seems to be in order.
#217
DVD Talk Special Edition
Joined: Aug 2004
Posts: 1,716
Likes: 0
Received 0 Likes
on
0 Posts
As it stands (10:27 EST), I logged into DDD under my username.
The title in the corner read "Welcome Matthew." I checked out each link at the top of the page (Home, Help, etc.) and everything worked fine.
My info was still there, and upon cursory glance, nothing was changed.
My order status showed nothing new had been ordered, nor anything added to my shopping cart.
I clicked "log out" and it logged me right out. (I use Opera, FYI.)
So, for me, everything seems to be in order.
The title in the corner read "Welcome Matthew." I checked out each link at the top of the page (Home, Help, etc.) and everything worked fine.
My info was still there, and upon cursory glance, nothing was changed.
My order status showed nothing new had been ordered, nor anything added to my shopping cart.
I clicked "log out" and it logged me right out. (I use Opera, FYI.)
So, for me, everything seems to be in order.
#218
Senior Member
Joined: Apr 1999
Posts: 896
Likes: 0
Received 0 Likes
on
0 Posts
From: Cleveland, OH
When I went to the site earlier tonight, I was welcomed as "Compromised by DDD." I viewed "account info" and saw the information for Frank Cantone. He had checked Bill Me Later, so I only saw his personal info and orders, no CC #.
This was not my info, but his last name is very close to mine. Coincidence?
I logged out and closed the window. When I reopened it now, about 2 hours later, I see the same "Welcome Compromised by DDD," but the account info for James J McMahon. Maybe they did get hacked?
This was not my info, but his last name is very close to mine. Coincidence?
I logged out and closed the window. When I reopened it now, about 2 hours later, I see the same "Welcome Compromised by DDD," but the account info for James J McMahon. Maybe they did get hacked?
#219
Member
Joined: Jun 2003
Posts: 190
Likes: 0
Received 0 Likes
on
0 Posts
I have not logged into DDD.com for a few days now. Should I log in and delete my credit card info before logging back out ??????? Or should I just not log in at all and leave everything in my account as is ?
thanks
thanks
#221
DVD Talk Legend
Since it doesn't seem to be certain that logging in opens up your account, it might be prudent to log in, delete your automatic credit card billing (if you use it) and any other info you want confidential, check your orders for fraud, and log out. I also changed my password, so that later when things are resolved I can put it back to my preference if I wish and know that it hasn't been compromised in the meantime.
#222
DVD Talk Legend
Originally posted by zidane349
i was charged with an order of 600$. i canceled my credit card.
i was charged with an order of 600$. i canceled my credit card.
Also, if I recall, sometimes DDD orders don't show up in the "order status" section until a business day after the order, meaning perhaps you won't see fraudulent orders until Monday.
#225
DVD Talk Ultimate Edition
here's what is happening for me with my compuserve software:
I visit the site and I get someone elses "welcome" messege. if I click on the account info to try to edit it for them and to get their email to let them know I get an error messege.
by the way, the names I'm getting are Andrew and Maxwell.
I visit the site and I get someone elses "welcome" messege. if I click on the account info to try to edit it for them and to get their email to let them know I get an error messege.
by the way, the names I'm getting are Andrew and Maxwell.



