No freakin’ excuse for ANY of these companies to be so cheap and Lame when it comes to keeping info confidential. And they wonder why people are Paranoid.
It just gets old quick.
Sorry for the rant, I know there is nothing we can do about it, but we don’t have to be happy or complacent about it.
FWIW, they’ve told me their sysadmin is working on it. I sent them information about the issue and what causes it and how to reproduce it and what the potential impact is and some ideas for fixing it, but it might take a little while since it’s not a trivial fix. There are some kludgy ways to work around it quickly, but a proper fix would require some pretty big changes.
It looks like they’ve made some good progress on the issue today. I would be surprised if anyone here can still abuse the site. The google results aren’t completely removed, and the fix isn’t quite complete yet, but it’s much better.
I’ve sent them new test results and a new measurement of the problem scope with instructions for how they can test any changes they make.
Looks like it’s still in the same state as last time I checked… still sort of broken but very very unlikely to be abused because it’s no longer vulnerable to any of the tools people actually use to browse the web. With a bit of info about how to do it, one could still look up anyone’s full order history and such, and it might still be possible to edit the site’s data but I haven’t tried. However, the way in is no longer trivial or easy to notice.
I’m not sure if they’re planning to fix it further, since the rest of the work required for a proper fix might be somewhat expensive and the web dev company who made the site doesn’t seem to fully understand what they did wrong. Regardless, I still sent them a suggestion for a low-tech solution which could be implemented in an afternoon if they knew what they were doing.
Just checked a moment ago and it doesn’t look like it has changed. I think they’ve done everything they’re going to do, even though I sent them instructions and a log of how the site security can be bypassed.
However, the issue is at least greatly minimized. It used to be easy and obvious; now it’s much more obscure.