- This topic has 35 replies, 22 voices, and was last updated 15 years, 2 months ago by
Paul O.
-
CreatorTopic
-
March 11, 2011 at 5:33 pm #13205
SQUADRA
this story is appearing on other cycling media. CRC apparently has encountered fraudulent activity on its customers purchasing via its website. http://www.singletrackworld.com/forum/topic/crc-security-issues/page/1
-
CreatorTopic
-
AuthorReplies
-
cat1commuter
madguern wrote:The fact is
madguern wrote:The fact is 90% of people on the web use the same account across the board. Do you use a different password for every site and service?Yes, I do. I use a long, randomly generated password for each site. Passwords 12 characters or shorter can be vulnerable if the encrypted form of the password (which is what is typically stored on web servers) is obtained. I use a password manager (Keychain on my Mac) to remember the random passwords. There are password managers available for Windows too, such as [url=http://keepass.info/]KeePass[/url], which includes a function which generates random passwords.
madguern
cat1commuter wrote:madguern
cat1commuter wrote:madguern wrote:Turns out forum I used stored my account details, I forgot to change password. Paypal is actually very easy to crack.Sorry, are you saying that you used the same password in an internet forum that you used for Paypal? That isn’t actually an attack on Paypal.
Probably misleading, paypal not easy to crack but easy to socially hack by getting user details from website that offer little to no security. whilst the password was not hacked they used my email address to generate a new password as they had hacked my mail account. I have since changed my mail account to foward all mail to a different account and not to be delivered to mailbox.
I cannot say directly that the account was hacked in this manner but was one of the reasons given to me by paypal. I only used paypal for payments to cycle firms however. Once a user gets into paypal however very simple to clean out an account if not using two-factor authentication. If your e-mail account is hacked it is also easy to get information as well. How many people use public wi-fi hotspots !
The fact is 90% of people on the web use the same account across the board. Do you use a different password for every site and service ?
End of story , be careful
dave atkinson
Quote:I feel that there is
I feel that there is something personal and slightly nasty about the abovei don’t really think that’s what he meant, Erneside, I think he was just saying he doesn’t have any particular axe to grind.
The anecdotal evidence from the STW forum looks like a pattern, but the only pattern is that cyclists went to CRC and after that their cards were used fraudulently. That doesn’t mean that CRC is to blame: their whole business model – and that of any online retailer – stands or falls on their reputation, and they go to great lengths to make sure their operations are secure.
Personal computers are much more likely to be compromised than the servers of big operations like CRC or Wiggle. If you get malware on your PC at home that scans keystrokes for likely credit card transactions, and you’re a keen cyclist, the chances are pretty good that the CC transaction will be at CRC, or Wiggle, or another big internet store.
Erneside
SQUADRA wrote:It makes no
SQUADRA wrote:It makes no difference to me, whether CRC website or business practices are correct, flawed or compromised.
I dont have any reason or inclination, to buy from their website.I feel that there is something personal and slightly
nasty about the above. CRC are probably the best bicycle
related company I have dealt with.cat1commuter
madguern wrote:Turns out
madguern wrote:Turns out forum I used stored my account details, I forgot to change password. Paypal is actually very easy to crack.Sorry, are you saying that you used the same password in an internet forum that you used for Paypal? That isn’t actually an attack on Paypal.
madguern
Sorry to dismiss paypal but
Sorry to dismiss paypal but my paypal account was hacked and taken for over $10,000. Paypal spotted the fact i started buying $1600 of online game credits every 30 secs and stopped payments. Had to go through 2 month investigation to prove I hadn’t done this. Turns out forum I used stored my account details, I forgot to change password. Paypal is actually very easy to crack. I have since signed up to Paypal’s additional security which is a two factor security card. Also if you use Visa sign up for 3d payment protection.
michophull
I’ve used CRC for several
I’ve used CRC for several years and not had any problems. Always had very good service from them too.I’d recommend using the Paypal option if you’re worried about DD payments. 😉
cat1commuter
tony_farrelly wrote:Not that
tony_farrelly wrote:Not that I think CRC would make any such connection – their reputation is obviously worth a great deal to them, as is Squadra’s to him – so maybe we should all calm down on that score too. He was entitled to start the thread.Sorry. I was too aggressive. I loved the picture of pavé on the front of Squadra’s website, and was disappointed when the rest of it appeared broken.
SQUADRA
an unfortunate coincidence
an unfortunate coincidence thenSQUADRA
it was a long thread on the
it was a long thread on the forum.
Tony Farrelly
If it was news we’d publish a
If it was news we’d publish a story, at the moment what we have here falls in to the category of gossip and supposition – the only actual facts are that some people have had unauthorised transactions on their credit cards and that there are a number of possible explanations one of which might, or might not, involve CRC.If that changes you’ll read about it on our news pages – whether CRC is an advertiser won’t be a consideration because our reputation is worth more to us than a bit of ad revenue. Not that I think CRC would make any such connection – their reputation is obviously worth a great deal to them, as is Squadra’s to him- so maybe we should all calm down on that score too. He was entitled to start the thread.
SQUADRA
the news item here is CRC.
it
the news item here is CRC.it was posted as a story which road.cc can report or not.
cat1commuter
SQUADRA wrote:It makes no
SQUADRA wrote:It makes no difference to me, whether CRC website or business practices are correct, flawed or compromised.
I dont have any reason or inclination, to buy from their website.After visiting your website, I certainly don’t have any inclination to buy from it. It appears to be filled with empty pages and broken links.
SQUADRA
It makes no difference to me,
It makes no difference to me, whether CRC website or business practices are correct, flawed or compromised.
I dont have any reason or inclination, to buy from their website.I felt the story was newsworthy on road.cc after all its a cycling news website, so figured its of relevance to its viewers.
Statistics can be stated to balance any degree of risk, or not, either way.
Similar to advertising budgets…handlebarcam
They should check their CCTV
They should check their CCTV for any dodgy characters hanging around their offices…[url=http://road.cc/content/news/31602-vitus-team-sean-kelly-again-2012-road-range]
[/url](I’m not so worried about Sean. The person behind the camera on the other hand…)
-
AuthorReplies
- You must be logged in to reply to this topic.