Page 2 of 4 FirstFirst 1234 LastLast
Results 11 to 20 of 35

Thread: Plus Net Compromised.

  1. #11
    rebmeM roineS enilnOitnA steve.milner's Avatar
    Join Date
    Jul 2003
    Posts
    1,021
    Just got one Moira.

    Are you paying them anything??

    Steve
    IT, e-commerce, Retail, Programme & Project Management, EPoS, Supply Chain and Logistic Services. Yorkshire. http://www.bigi.uk.com

  2. #12
    Agony Aunty-Online Moira's Avatar
    Join Date
    Jun 2003
    Posts
    1,063
    Like hell am I paying them! What would I want to pay PlusNet for ?? They aren't my ISP.
    77 111 105 114 97

    My PGP signature

  3. #13
    rebmeM roineS enilnOitnA steve.milner's Avatar
    Join Date
    Jul 2003
    Posts
    1,021
    It's all a bit wierd really.

    Steve
    IT, e-commerce, Retail, Programme & Project Management, EPoS, Supply Chain and Logistic Services. Yorkshire. http://www.bigi.uk.com

  4. #14
    Agony Aunty-Online Moira's Avatar
    Join Date
    Jun 2003
    Posts
    1,063
    Very. It makes me glad I'm not a PlusNet customer if this is an example of their efficiency. They certainly don't provide me with any service, nor do I pay them so it's rather strange to be the recipient of all these emails. When I was considering switching to them it was several years ago too.
    77 111 105 114 97

    My PGP signature

  5. #15
    Senior Member nihil's Avatar
    Join Date
    Jul 2003
    Location
    United Kingdom: Bridlington
    Posts
    17,188
    OK I have been giving this one a bit more thought and have the following suggestion. It is pure speculation on my part but seems to fit what we know so far?

    1. PlusNet obviously have a contacts database of everyone who has ever contacted them for any reason. We all know how anally retentive marketing types can be when they get a "live" e-mail addy? This would explain why Moira is getting the warnings even though she never did business with them.

    2. I would suspect that the contacts database is not considered important and has been compromised in its entirety. I would expect that the customer accounts database is secure or at least relatively so. If it had been compromised, Steve would get the e-mail but Moira wouldn't.

    Basically PlusNet have been holding personal details of people who are not their customers. I know that this is done whilst you are negotiating with a potential customer, but I would have thought that it was common practice to delete these records after 6 months or so.

    This raises a couple of questions in my mind:

    1. What are PlusNet going to do for people like Moira, who has been compromised by their incompetence but is not a user of their services?

    2. What other personal information was on that database and has also been compromised?

    EDIT: The plot thickens:

    http://www.theregister.co.uk/2007/05..._webmail_shut/
    Last edited by nihil; May 19th, 2007 at 12:41 AM.

  6. #16
    Agony Aunty-Online Moira's Avatar
    Join Date
    Jun 2003
    Posts
    1,063
    Quote Originally Posted by nihil
    2. I would suspect that the contacts database is not considered important and has been compromised in its entirety. I would expect that the customer accounts database is secure or at least relatively so. If it had been compromised, Steve would get the e-mail but Moira wouldn't.
    Or else we'd both get an email if both databases had been compromised.

    Basically PlusNet have been holding personal details of people who are not their customers. I know that this is done whilst you are negotiating with a potential customer, but I would have thought that it was common practice to delete these records after 6 months or so.
    Quite. It was so long ago that I contacted PlusNet that I'm concerned they still hold my details. It makes you realise just what information is held about you by various organisations and the idea that this is deleted when it no longer serves a purpose, clearly isn't being done at all.

    1. What are PlusNet going to do for people like Moira, who has been compromised by their incompetence but is not a user of their services?
    Well, they say I've been compromised, but I'm hard pushed to see any damage tbh. I'd like to think I could demand financial compensation but I don't think I've probably got much of a case!

    Anyway, I'll wait and see what transpires. They may be forced into compensating people with enough pressure.
    77 111 105 114 97

    My PGP signature

  7. #17
    Senior Member nihil's Avatar
    Join Date
    Jul 2003
    Location
    United Kingdom: Bridlington
    Posts
    17,188
    I don't think that the customer account database has been compromised, as they would have to warn people about that, given that it would contain credit card and banking details.

    You will probably OK as I would expect spammers to check the record dates and delete old ones. Obsolete spam lists are of no value?

  8. #18
    Agony Aunty-Online Moira's Avatar
    Join Date
    Jun 2003
    Posts
    1,063
    Well since to my knowledge I don't even have a PlusNet email account, it follows that it can't be receiving spam. Either way, I haven't been receiving spam to anything but my normal accounts (Yahoo and Gmail attract spam like a magnet!)
    77 111 105 114 97

    My PGP signature

  9. #19
    Senior Member nihil's Avatar
    Join Date
    Jul 2003
    Location
    United Kingdom: Bridlington
    Posts
    17,188
    Hi Moira,

    They are sending you e-mails, so that is the account that is on their database and has been compromised.

    I presume that it is their marketing mailing database that has been compromised. I guess that will contain all existing customers, past customers and contacts such as yourself.


  10. #20
    Agony Aunty-Online Moira's Avatar
    Join Date
    Jun 2003
    Posts
    1,063
    Yes ..... I'm just surprised they think I ever had a PlusNet email address, that's all, since I never actually got round to signing up with them.
    77 111 105 114 97

    My PGP signature

Similar Threads

  1. Cisco.com compromised
    By sweet_angel in forum Security News
    Replies: 6
    Last Post: August 5th, 2005, 08:37 PM
  2. Study: Unpatched PCs compromised in 20 minutes
    By SDK in forum Miscellaneous Security Discussions
    Replies: 10
    Last Post: August 18th, 2004, 05:13 AM
  3. Stanford compromised.
    By MrLinus in forum Miscellaneous Security Discussions
    Replies: 7
    Last Post: May 17th, 2004, 04:34 PM
  4. Gentoo Servers compromised (For Shrekkie)
    By gore in forum *nix Security Discussions
    Replies: 3
    Last Post: December 5th, 2003, 10:58 AM
  5. Evidence collection from compromised hosts
    By Striek in forum Network Security Discussions
    Replies: 5
    Last Post: November 28th, 2003, 12:12 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •