follow ft86club on our blog, twitter or facebook.
FT86CLUB
Ft86Club
Delicious Tuning
Register Garage Community Calendar Today's Posts Search

Go Back   Toyota GR86, 86, FR-S and Subaru BRZ Forum & Owners Community - FT86CLUB > 1st Gens: Scion FR-S / Toyota 86 / Subaru BRZ > BRZ First-Gen (2012+) — General Topics

BRZ First-Gen (2012+) — General Topics All discussions about the first-gen Subaru BRZ coupe

Register and become an FT86Club.com member. You will see fewer ads

User Tag List
go_a_way1, MisterSheep

Reply
 
Thread Tools Search this Thread
Old 01-12-2016, 09:51 PM   #15
PandaSPUR
PandaPandaPandaPandaPanda
 
PandaSPUR's Avatar
 
Join Date: May 2014
Drives: 2015 BRZ Limited CWP
Location: New York City, NY
Posts: 1,432
Thanks: 776
Thanked 697 Times in 438 Posts
Mentioned: 12 Post(s)
Tagged: 1 Thread(s)
Quote:
Originally Posted by Ashikabi View Post
Ft86 speed factory probably didn't know until the claims started rolling in
This. A lot of breaches go unnoticed until one of the credit reporting agencies, or the credit card companies notice that a bunch of people making fraudulent charge claims have made purchases at one common retailer.

At that point, the retailer gets notified and has a certain amount of time to investigate and remediate (usually hiring a third party consulting firm) as per PCI standards. They have to identify all affected customers, and then notify them AFTER they're confident they have all the names. At that point they also get fined based on how many card numbers were compromised.

Usually they're not allowed to, or are advised against, sending mass notifications that their site is breached immediately since that tips off the attackers as well and makes investigations harder.
PandaSPUR is offline   Reply With Quote
The Following 3 Users Say Thank You to PandaSPUR For This Useful Post:
DAEMANO (01-13-2016), ScoobsMcGee (01-12-2016), soulreapersteve (01-12-2016)
Old 01-12-2016, 10:08 PM   #16
ScoobsMcGee
Junior Senior with Cheese
 
ScoobsMcGee's Avatar
 
Join Date: Aug 2014
Drives: 15 BRZ
Location: York, PA
Posts: 3,006
Thanks: 6,837
Thanked 7,049 Times in 2,345 Posts
Mentioned: 13 Post(s)
Tagged: 2 Thread(s)
Quote:
Originally Posted by PandaSPUR View Post
This. A lot of breaches go unnoticed until one of the credit reporting agencies, or the credit card companies notice that a bunch of people making fraudulent charge claims have made purchases at one common retailer.

At that point, the retailer gets notified and has a certain amount of time to investigate and remediate (usually hiring a third party consulting firm) as per PCI standards. They have to identify all affected customers, and then notify them AFTER they're confident they have all the names. At that point they also get fined based on how many card numbers were compromised.

Usually they're not allowed to, or are advised against, sending mass notifications that their site is breached immediately since that tips off the attackers as well and makes investigations harder.
Sums up most of what I wanted to say. It is possible that they'll still respond to a post or two now that the word is out, but there are legal obligations to sending notification to the affected customers first. As for snail mail versus email, in addition to possibly compromising any investigation, street addresses are generally more reliable. Fake email addresses and junk mail filters can get in the way. The credit card companies have a valid mailing address or PO box.
ScoobsMcGee is offline   Reply With Quote
Old 01-12-2016, 10:12 PM   #17
N1rve
Senior Member
 
N1rve's Avatar
 
Join Date: Oct 2013
Drives: 2019 BMW ///M4
Location: Los Angeles, CA
Posts: 2,332
Thanks: 102
Thanked 1,167 Times in 714 Posts
Mentioned: 28 Post(s)
Tagged: 0 Thread(s)
Good thing I use a proxy card
__________________
N1rve

2019 BMW ///M4 - Alpine White | Sakhir Orange/Black Leather | M-DCT | Executive Package | 19" Black 437M Wheels | Carbon Fiber Trim | Sunroof | Active Blind Spot | Heated Steering Wheel | Adaptive M Suspension
N1rve is offline   Reply With Quote
Old 01-12-2016, 10:18 PM   #18
Teseo
Senior Member
 
Join Date: Jun 2014
Drives: frs
Location: Gunsai
Posts: 4,954
Thanks: 7,467
Thanked 2,980 Times in 1,802 Posts
Mentioned: 23 Post(s)
Tagged: 2 Thread(s)
Call me old school but i still use money order for that kind of crap
Teseo is offline   Reply With Quote
Old 01-12-2016, 11:13 PM   #19
KR-S
Sporadic Member
 
KR-S's Avatar
 
Join Date: Nov 2015
Drives: 2016 Halo FR-S M/T
Location: Earth
Posts: 3,145
Thanks: 5,221
Thanked 3,552 Times in 1,746 Posts
Mentioned: 50 Post(s)
Tagged: 33 Thread(s)
I just now got my letter. Good thing I already have a new card.
KR-S is offline   Reply With Quote
Old 01-12-2016, 11:45 PM   #20
soulreapersteve
Contract? /人◕ ‿‿ ◕人\
 
soulreapersteve's Avatar
 
Join Date: Apr 2015
Drives: An orange cone with flappy paddles
Location: Seattle
Posts: 5,029
Thanks: 11,347
Thanked 5,170 Times in 2,703 Posts
Mentioned: 126 Post(s)
Tagged: 5 Thread(s)
Received the letter yesterday and went to the CU to request for a new card right after reading it.

That explains the weird call I received few months back that there was suspicious activity originating from France (even though these guys had a Russian IP address) regarding my first card - after 5 years of green pastures.

Will I stop buying from them? Things may have changed since I initially was looking into cyber security but the mantra goes: "places are more secure after an attack than before".

However, I'm done with major purchases for the car besides consumables.
__________________
Quote:
Originally Posted by Tcoat View Post
Hey, you're the one asking me to shove a turbo engine in my pants.
The Twins make me smile
soulreapersteve is offline   Reply With Quote
Old 01-13-2016, 12:48 AM   #21
N1rve
Senior Member
 
N1rve's Avatar
 
Join Date: Oct 2013
Drives: 2019 BMW ///M4
Location: Los Angeles, CA
Posts: 2,332
Thanks: 102
Thanked 1,167 Times in 714 Posts
Mentioned: 28 Post(s)
Tagged: 0 Thread(s)
Quote:
Originally Posted by soulreapersteve View Post
Received the letter yesterday and went to the CU to request for a new card right after reading it.

That explains the weird call I received few months back that there was suspicious activity originating from France (even though these guys had a Russian IP address) regarding my first card - after 5 years of green pastures.

Will I stop buying from them? Things may have changed since I initially was looking into cyber security but the mantra goes: "places are more secure after an attack than before".

However, I'm done with major purchases for the car besides consumables.
I think that's the illusion that places are more secure after an attack. If you look at Lockheed Martin's Cyber Kill Chain, the first step is reconnaissance. We don't know how much information that the cracker (Black Hat) collected. There could me even more attack vectors that they are unaware of and unexploited until later. Same goes for Chase, Target, Home Depot, Sony, etc.

Most cyber attacks are because of human error. That means opening E-mail attachments or clicking links. You can even be hacked by being sent a picture.

Besides, for a company like ft86speedfactory, they don't own their webserver which means they don't own the security of their site. Their web hosting is provided by 1and1.

Domain Name: FT86SPEEDFACTORY.COM
Registrar: 1 & 1 INTERNET AG
Sponsoring Registrar IANA ID: 83
Whois Server: whois.1and1.com
Referral URL: http://1and1.com
Name Server: NS-US.1AND1-DNS.COM
Name Server: NS-US.1AND1-DNS.DE
Name Server: NS-US.1AND1-DNS.ORG
Name Server: NS-US.1AND1-DNS.US
Status: ok http://www.icann.org/epp#OK
Updated Date: 21-mar-2015
Creation Date: 21-mar-2012
Expiration Date: 21-mar-2016

And I hope your password to this forum is different from your bank accounts. When you log in, it's using HTTP and NOT HTTPS, which means your password is NOT ENCRYPTED and can be viewed PLAIN TEXT.
__________________
N1rve

2019 BMW ///M4 - Alpine White | Sakhir Orange/Black Leather | M-DCT | Executive Package | 19" Black 437M Wheels | Carbon Fiber Trim | Sunroof | Active Blind Spot | Heated Steering Wheel | Adaptive M Suspension
N1rve is offline   Reply With Quote
The Following 3 Users Say Thank You to N1rve For This Useful Post:
nisti (01-14-2016), soulreapersteve (01-13-2016), Toyarzee (01-13-2016)
Old 01-13-2016, 12:51 AM   #22
whataboutbob
AutoX-10/10ths every run
 
Join Date: Jun 2012
Drives: 2013 Scion FR-S AT Firestorm
Location: San Marcos, CA, USA
Posts: 2,611
Thanks: 4,851
Thanked 1,882 Times in 1,025 Posts
Mentioned: 79 Post(s)
Tagged: 0 Thread(s)
Garage
"And I hope your password to this forum is different from your bank accounts. When you log in, it's using HTTP and NOT HTTPS, which means your password is NOT ENCRYPTED and can be viewed PLAIN TEXT."

^this.
__________________

Build thread:Here
whataboutbob is offline   Reply With Quote
Old 01-13-2016, 12:59 AM   #23
KR-S
Sporadic Member
 
KR-S's Avatar
 
Join Date: Nov 2015
Drives: 2016 Halo FR-S M/T
Location: Earth
Posts: 3,145
Thanks: 5,221
Thanked 3,552 Times in 1,746 Posts
Mentioned: 50 Post(s)
Tagged: 33 Thread(s)
Quote:
Originally Posted by whataboutbob View Post
"And I hope your password to this forum is different from your bank accounts. When you log in, it's using HTTP and NOT HTTPS, which means your password is NOT ENCRYPTED and can be viewed PLAIN TEXT."

^this.
The question is, why are the passwords not encrypted in the first place? Is this a vBulletin issue?

And regarding the issue that FT86SF and possibly its sister site Subispeed don't own their own security, does that apply to their checkout page as well? If that's the case, then there probably wasn't much if at all that they could have been done on their end to prevent this.
KR-S is offline   Reply With Quote
Old 01-13-2016, 01:09 AM   #24
Ultramaroon
not playing cards
 
Ultramaroon's Avatar
 
Join Date: Sep 2014
Drives: a 13 e8h frs
Location: vantucky, wa
Posts: 32,395
Thanks: 53,053
Thanked 37,228 Times in 19,308 Posts
Mentioned: 1118 Post(s)
Tagged: 9 Thread(s)
Quote:
Originally Posted by N1rve View Post
your password is NOT ENCRYPTED.
How did you get my password?! Damn!
__________________
Ultramaroon is offline   Reply With Quote
Old 01-13-2016, 01:15 AM   #25
PandaSPUR
PandaPandaPandaPandaPanda
 
PandaSPUR's Avatar
 
Join Date: May 2014
Drives: 2015 BRZ Limited CWP
Location: New York City, NY
Posts: 1,432
Thanks: 776
Thanked 697 Times in 438 Posts
Mentioned: 12 Post(s)
Tagged: 1 Thread(s)
lol alright.. calm down guys.

It is weird that passwords arent sent over HTTPS. Doesn't mean that they're not encrypted when stored in the forum's database though. Transferring data over HTTP makes it interceptable if you're on an unsecured network like public wifi hotspots. It is recommended to use separate passwords for your more sensitive accounts though. (i.e. some rando miles away cannot just intercept your password that was sent over HTTP)

And just because the webserver itself is hosted by another company, doesn't mean that FT86SpeedFactory doesn't have any control over the security. More often than not, the security vulnerabilities come from unpatched software being used.

1and1 provides all kinds of web hosting services ranging from turn-key pre-built websites to "here's a server with port 443 and 80 open, deploy whatever you want". I'm assuming a site like FT86SpeedFactory would go with the latter option, meaning they would have full control over their security posture. Even if they did not, I'm sure whatever third-party service they hired to fix this breach would have recommended it.

Shit like this isnt 100% preventable, which is why credit cards have such good fraud protection and you can usually dispute and drop a charge instantly with a phone call. The company will likely get fined for whatever mistakes they made and be required to fix it. Nothing else we can do.
PandaSPUR is offline   Reply With Quote
The Following User Says Thank You to PandaSPUR For This Useful Post:
Sarlacc (01-14-2016)
Old 01-13-2016, 01:17 AM   #26
N1rve
Senior Member
 
N1rve's Avatar
 
Join Date: Oct 2013
Drives: 2019 BMW ///M4
Location: Los Angeles, CA
Posts: 2,332
Thanks: 102
Thanked 1,167 Times in 714 Posts
Mentioned: 28 Post(s)
Tagged: 0 Thread(s)
Quote:
Originally Posted by KR-S 86 View Post
The question is, why are the passwords not encrypted in the first place? Is this a vBulletin issue?

And regarding the issue that FT86SF and possibly its sister site Subispeed don't own their own security, does that apply to their checkout page as well? If that's the case, then there probably wasn't much if at all that they could have been done on their end to prevent this.
I'm not sure how exactly vBulletin works, but it's most likely because they don't own a SSL certificate.

Also, their sister site is hosted by GoDaddy.

D
Domain Name: SUBIESPEED.COM
Registrar: GODADDY.COM, LLC
Sponsoring Registrar IANA ID: 146
Whois Server: whois.godaddy.com
Referral URL: http://registrar.godaddy.com
Name Server: NS1.MEDIATEMPLE.NET
Name Server: NS2.MEDIATEMPLE.NET
Status: clientDeleteProhibited http://www.icann.org/epp#clientDeleteProhibited
Status: clientRenewProhibited http://www.icann.org/epp#clientRenewProhibited
Status: clientTransferProhibited http://www.icann.org/epp#clientTransferProhibited
Status: clientUpdateProhibited http://www.icann.org/epp#clientUpdateProhibited
Updated Date: 17-sep-2015
Creation Date: 09-oct-2011
Expiration Date: 09-oct-2016

Quote:
Originally Posted by Ultramaroon View Post
How did you get my password?! Damn!
It wasn't me!!
__________________
N1rve

2019 BMW ///M4 - Alpine White | Sakhir Orange/Black Leather | M-DCT | Executive Package | 19" Black 437M Wheels | Carbon Fiber Trim | Sunroof | Active Blind Spot | Heated Steering Wheel | Adaptive M Suspension
N1rve is offline   Reply With Quote
The Following User Says Thank You to N1rve For This Useful Post:
KR-S (01-13-2016)
Old 01-13-2016, 01:24 AM   #27
PandaSPUR
PandaPandaPandaPandaPanda
 
PandaSPUR's Avatar
 
Join Date: May 2014
Drives: 2015 BRZ Limited CWP
Location: New York City, NY
Posts: 1,432
Thanks: 776
Thanked 697 Times in 438 Posts
Mentioned: 12 Post(s)
Tagged: 1 Thread(s)
Quote:
Originally Posted by N1rve View Post
I'm not sure how exactly vBulletin works, but it's most likely because they don't own a SSL certificate.

Also, their sister site is hosted by GoDaddy.

D
Domain Name: SUBIESPEED.COM
Registrar: GODADDY.COM, LLC
Sponsoring Registrar IANA ID: 146
Whois Server: whois.godaddy.com
Referral URL: http://registrar.godaddy.com
Name Server: NS1.MEDIATEMPLE.NET
Name Server: NS2.MEDIATEMPLE.NET
Status: clientDeleteProhibited http://www.icann.org/epp#clientDeleteProhibited
Status: clientRenewProhibited http://www.icann.org/epp#clientRenewProhibited
Status: clientTransferProhibited http://www.icann.org/epp#clientTransferProhibited
Status: clientUpdateProhibited http://www.icann.org/epp#clientUpdateProhibited
Updated Date: 17-sep-2015
Creation Date: 09-oct-2011
Expiration Date: 09-oct-2016



It wasn't me!!
I just looked at both sites. The WHOIS information is taken from DNS registrars. Looks like they're just using 1and1 and godaddy for the domain name. The servers are hosted by singlehop, which is a IaaS provider. So FT86SF has full control over their servers.

EDIT:

Example for those who care:
Info for ft86speedfactory.com: http://www.tcpiputils.com/browse/dom...eedfactory.com
DNS info points to 1and1, IP is 65.60.44.147

Info for 65.60.44.147: http://www.tcpiputils.com/browse/ip-...s/65.60.44.147
ISP is SingleHop, Inc., WHOIS info for the IP itself points to SingleHop. The IP is also part of a whole block assigned to SingleHop. That page also states that "server2.subispeed.com" also resolves to this IP.

Blah blah blah light recon stuff.
PandaSPUR is offline   Reply With Quote
Old 01-13-2016, 02:08 AM   #28
wtfrs
Member
 
Join Date: Sep 2015
Drives: 2014 Monogram
Location: Nevada
Posts: 72
Thanks: 2
Thanked 18 Times in 14 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
i was literally about to order some parts from them :/
wtfrs is offline   Reply With Quote
 
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Security Camera? tazz786 Electronics | Audio | NAV | Infotainment 3 06-20-2015 12:02 AM
In-Car Security Cameras? Mr Kirmudget Electronics | Audio | NAV | Infotainment 6 08-27-2013 06:00 PM
Major Security Flaw! DBacon1052 Issues | Warranty | Recalls / TSB 69 05-04-2013 06:19 PM
After market security shiud Electronics | Audio | NAV | Infotainment 5 09-28-2012 04:59 PM
Security system: BRZ vs. FR-S Sport-Tech CANADA 16 05-30-2012 02:02 AM


All times are GMT -4. The time now is 07:58 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
User Alert System provided by Advanced User Tagging v3.3.0 (Lite) - vBulletin Mods & Addons Copyright © 2026 DragonByte Technologies Ltd.

Garage vBulletin Plugins by Drive Thru Online, Inc.