|
||||||
| BRZ First-Gen (2012+) — General Topics All discussions about the first-gen Subaru BRZ coupe |
![]() |
|
|
Thread Tools | Search this Thread |
|
|
#15 | |
|
PandaPandaPandaPandaPanda
Join Date: May 2014
Drives: 2015 BRZ Limited CWP
Location: New York City, NY
Posts: 1,432
Thanks: 776
Thanked 697 Times in 438 Posts
Mentioned: 12 Post(s)
Tagged: 1 Thread(s)
|
Quote:
At that point, the retailer gets notified and has a certain amount of time to investigate and remediate (usually hiring a third party consulting firm) as per PCI standards. They have to identify all affected customers, and then notify them AFTER they're confident they have all the names. At that point they also get fined based on how many card numbers were compromised. Usually they're not allowed to, or are advised against, sending mass notifications that their site is breached immediately since that tips off the attackers as well and makes investigations harder. |
|
|
|
|
| The Following 3 Users Say Thank You to PandaSPUR For This Useful Post: |
|
|
#16 | |
|
Junior Senior with Cheese
Join Date: Aug 2014
Drives: 15 BRZ
Location: York, PA
Posts: 3,006
Thanks: 6,837
Thanked 7,049 Times in 2,345 Posts
Mentioned: 13 Post(s)
Tagged: 2 Thread(s)
|
Quote:
|
|
|
|
|
|
|
#17 |
|
Senior Member
Join Date: Oct 2013
Drives: 2019 BMW ///M4
Location: Los Angeles, CA
Posts: 2,332
Thanks: 102
Thanked 1,167 Times in 714 Posts
Mentioned: 28 Post(s)
Tagged: 0 Thread(s)
|
Good thing I use a proxy card
__________________
N1rve
2019 BMW ///M4 - Alpine White | Sakhir Orange/Black Leather | M-DCT | Executive Package | 19" Black 437M Wheels | Carbon Fiber Trim | Sunroof | Active Blind Spot | Heated Steering Wheel | Adaptive M Suspension |
|
|
|
|
|
#18 |
|
Senior Member
Join Date: Jun 2014
Drives: frs
Location: Gunsai
Posts: 4,954
Thanks: 7,467
Thanked 2,980 Times in 1,802 Posts
Mentioned: 23 Post(s)
Tagged: 2 Thread(s)
|
Call me old school but i still use money order for that kind of crap
|
|
|
|
|
|
#19 |
|
Sporadic Member
Join Date: Nov 2015
Drives: 2016 Halo FR-S M/T
Location: Earth
Posts: 3,145
Thanks: 5,221
Thanked 3,552 Times in 1,746 Posts
Mentioned: 50 Post(s)
Tagged: 33 Thread(s)
|
I just now got my letter. Good thing I already have a new card.
|
|
|
|
|
|
#20 |
|
Contract? /人◕ ‿‿ ◕人\
Join Date: Apr 2015
Drives: An orange cone with flappy paddles
Location: Seattle
Posts: 5,029
Thanks: 11,347
Thanked 5,170 Times in 2,703 Posts
Mentioned: 126 Post(s)
Tagged: 5 Thread(s)
|
Received the letter yesterday and went to the CU to request for a new card right after reading it.
That explains the weird call I received few months back that there was suspicious activity originating from France (even though these guys had a Russian IP address) regarding my first card - after 5 years of green pastures. Will I stop buying from them? Things may have changed since I initially was looking into cyber security but the mantra goes: "places are more secure after an attack than before". However, I'm done with major purchases for the car besides consumables. |
|
|
|
|
|
#21 | |
|
Senior Member
Join Date: Oct 2013
Drives: 2019 BMW ///M4
Location: Los Angeles, CA
Posts: 2,332
Thanks: 102
Thanked 1,167 Times in 714 Posts
Mentioned: 28 Post(s)
Tagged: 0 Thread(s)
|
Quote:
Most cyber attacks are because of human error. That means opening E-mail attachments or clicking links. You can even be hacked by being sent a picture. Besides, for a company like ft86speedfactory, they don't own their webserver which means they don't own the security of their site. Their web hosting is provided by 1and1. Domain Name: FT86SPEEDFACTORY.COM Registrar: 1 & 1 INTERNET AG Sponsoring Registrar IANA ID: 83 Whois Server: whois.1and1.com Referral URL: http://1and1.com Name Server: NS-US.1AND1-DNS.COM Name Server: NS-US.1AND1-DNS.DE Name Server: NS-US.1AND1-DNS.ORG Name Server: NS-US.1AND1-DNS.US Status: ok http://www.icann.org/epp#OK Updated Date: 21-mar-2015 Creation Date: 21-mar-2012 Expiration Date: 21-mar-2016 And I hope your password to this forum is different from your bank accounts. When you log in, it's using HTTP and NOT HTTPS, which means your password is NOT ENCRYPTED and can be viewed PLAIN TEXT.
__________________
N1rve
2019 BMW ///M4 - Alpine White | Sakhir Orange/Black Leather | M-DCT | Executive Package | 19" Black 437M Wheels | Carbon Fiber Trim | Sunroof | Active Blind Spot | Heated Steering Wheel | Adaptive M Suspension |
|
|
|
|
| The Following 3 Users Say Thank You to N1rve For This Useful Post: |
|
|
#22 |
|
AutoX-10/10ths every run
Join Date: Jun 2012
Drives: 2013 Scion FR-S AT Firestorm
Location: San Marcos, CA, USA
Posts: 2,611
Thanks: 4,851
Thanked 1,882 Times in 1,025 Posts
Mentioned: 79 Post(s)
Tagged: 0 Thread(s)
|
"And I hope your password to this forum is different from your bank accounts. When you log in, it's using HTTP and NOT HTTPS, which means your password is NOT ENCRYPTED and can be viewed PLAIN TEXT."
^this.
__________________
|
|
|
|
|
|
#23 | |
|
Sporadic Member
Join Date: Nov 2015
Drives: 2016 Halo FR-S M/T
Location: Earth
Posts: 3,145
Thanks: 5,221
Thanked 3,552 Times in 1,746 Posts
Mentioned: 50 Post(s)
Tagged: 33 Thread(s)
|
Quote:
And regarding the issue that FT86SF and possibly its sister site Subispeed don't own their own security, does that apply to their checkout page as well? If that's the case, then there probably wasn't much if at all that they could have been done on their end to prevent this. |
|
|
|
|
|
|
#24 |
|
not playing cards
Join Date: Sep 2014
Drives: a 13 e8h frs
Location: vantucky, wa
Posts: 32,395
Thanks: 53,053
Thanked 37,228 Times in 19,308 Posts
Mentioned: 1118 Post(s)
Tagged: 9 Thread(s)
|
How did you get my password?! Damn!
__________________
|
|
|
|
|
|
#25 |
|
PandaPandaPandaPandaPanda
Join Date: May 2014
Drives: 2015 BRZ Limited CWP
Location: New York City, NY
Posts: 1,432
Thanks: 776
Thanked 697 Times in 438 Posts
Mentioned: 12 Post(s)
Tagged: 1 Thread(s)
|
lol alright.. calm down guys.
It is weird that passwords arent sent over HTTPS. Doesn't mean that they're not encrypted when stored in the forum's database though. Transferring data over HTTP makes it interceptable if you're on an unsecured network like public wifi hotspots. It is recommended to use separate passwords for your more sensitive accounts though. (i.e. some rando miles away cannot just intercept your password that was sent over HTTP) And just because the webserver itself is hosted by another company, doesn't mean that FT86SpeedFactory doesn't have any control over the security. More often than not, the security vulnerabilities come from unpatched software being used. 1and1 provides all kinds of web hosting services ranging from turn-key pre-built websites to "here's a server with port 443 and 80 open, deploy whatever you want". I'm assuming a site like FT86SpeedFactory would go with the latter option, meaning they would have full control over their security posture. Even if they did not, I'm sure whatever third-party service they hired to fix this breach would have recommended it. Shit like this isnt 100% preventable, which is why credit cards have such good fraud protection and you can usually dispute and drop a charge instantly with a phone call. The company will likely get fined for whatever mistakes they made and be required to fix it. Nothing else we can do. |
|
|
|
| The Following User Says Thank You to PandaSPUR For This Useful Post: | Sarlacc (01-14-2016) |
|
|
#26 | |
|
Senior Member
Join Date: Oct 2013
Drives: 2019 BMW ///M4
Location: Los Angeles, CA
Posts: 2,332
Thanks: 102
Thanked 1,167 Times in 714 Posts
Mentioned: 28 Post(s)
Tagged: 0 Thread(s)
|
Quote:
Also, their sister site is hosted by GoDaddy. D Domain Name: SUBIESPEED.COM Registrar: GODADDY.COM, LLC Sponsoring Registrar IANA ID: 146 Whois Server: whois.godaddy.com Referral URL: http://registrar.godaddy.com Name Server: NS1.MEDIATEMPLE.NET Name Server: NS2.MEDIATEMPLE.NET Status: clientDeleteProhibited http://www.icann.org/epp#clientDeleteProhibited Status: clientRenewProhibited http://www.icann.org/epp#clientRenewProhibited Status: clientTransferProhibited http://www.icann.org/epp#clientTransferProhibited Status: clientUpdateProhibited http://www.icann.org/epp#clientUpdateProhibited Updated Date: 17-sep-2015 Creation Date: 09-oct-2011 Expiration Date: 09-oct-2016 It wasn't me!!
__________________
N1rve
2019 BMW ///M4 - Alpine White | Sakhir Orange/Black Leather | M-DCT | Executive Package | 19" Black 437M Wheels | Carbon Fiber Trim | Sunroof | Active Blind Spot | Heated Steering Wheel | Adaptive M Suspension |
|
|
|
|
| The Following User Says Thank You to N1rve For This Useful Post: | KR-S (01-13-2016) |
|
|
#27 | |
|
PandaPandaPandaPandaPanda
Join Date: May 2014
Drives: 2015 BRZ Limited CWP
Location: New York City, NY
Posts: 1,432
Thanks: 776
Thanked 697 Times in 438 Posts
Mentioned: 12 Post(s)
Tagged: 1 Thread(s)
|
Quote:
EDIT: Example for those who care: Info for ft86speedfactory.com: http://www.tcpiputils.com/browse/dom...eedfactory.com DNS info points to 1and1, IP is 65.60.44.147 Info for 65.60.44.147: http://www.tcpiputils.com/browse/ip-...s/65.60.44.147 ISP is SingleHop, Inc., WHOIS info for the IP itself points to SingleHop. The IP is also part of a whole block assigned to SingleHop. That page also states that "server2.subispeed.com" also resolves to this IP. Blah blah blah light recon stuff. |
|
|
|
|
|
|
#28 |
|
Member
Join Date: Sep 2015
Drives: 2014 Monogram
Location: Nevada
Posts: 72
Thanks: 2
Thanked 18 Times in 14 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
i was literally about to order some parts from them :/
|
|
|
|
|
|
|
|
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Security Camera? | tazz786 | Electronics | Audio | NAV | Infotainment | 3 | 06-20-2015 12:02 AM |
| In-Car Security Cameras? | Mr Kirmudget | Electronics | Audio | NAV | Infotainment | 6 | 08-27-2013 06:00 PM |
| Major Security Flaw! | DBacon1052 | Issues | Warranty | Recalls / TSB | 69 | 05-04-2013 06:19 PM |
| After market security | shiud | Electronics | Audio | NAV | Infotainment | 5 | 09-28-2012 04:59 PM |
| Security system: BRZ vs. FR-S | Sport-Tech | CANADA | 16 | 05-30-2012 02:02 AM |