User comments on ISPs
  >> PlusNet plc


Register (or login) on our website and you will not see this ad.


These posts have been archived and can no longer be replied to or modified.
Pages in this thread: 1 | 2 | 3 | 4 | 5 | [6] | (show all)   Print Thread
Standard User deleted
(deleted) Tue 15-May-07 15:53:57
Print Post

Re: Reading between the lines


[re: deleted] [link to this post]
 
Dave,

And a further thing having just read the service status announcement it would appear that my account may have been compromised so I also now have to watch my bank for possible fraud.

Mark
Standard User blewit
(committed) Tue 15-May-07 15:55:49
Print Post

Re: Reading between the lines


[re: rsharma] [link to this post]
 
Excellent - well spotted rsharma. It appears that the latest service status post from Phil is more like what I was expecting.

From what PlusNet has said I should get 2 emails - I await them

Edited by blewit (Tue 15-May-07 16:20:29)

Standard User deleted
(deleted) Tue 15-May-07 16:19:10
Print Post

Re: Reading between the lines


[re: xela] [link to this post]
 
"Haven't they already checked a few other things and improved security in other areas? Do you think they aren't taking this seriously?"

remember at least two things
1. This is not by any manner of means the first time
2. It was pointed out by customers, they did not find it. A trojan was sitting on them and they had no checks in place to ensure that this did not happen.


Register (or login) on our website and you will not see this ad.

Standard User ScaryMonkey
(knowledge is power) Tue 15-May-07 17:19:34
Print Post

Re: Reading between the lines


[re: deleted] [link to this post]
 
Dave

I'm not sure if it is still the case, but some of the original older accounts didn't have Spam and AV facilites (it was an extra cost option). If it is still the case, could this now be allowed on all accounts regardless of whether they originally qualified or not please.

Vince

15 year olds racing cars - Sponsors needed for 2007 and 2008 - MVRacing.co.uk
Standard User deleted
(deleted) Tue 15-May-07 20:15:27
Print Post

Re: Reading between the lines


[re: ScaryMonkey] [link to this post]
 
I've asked about that, will let you know the answer when I get it.
Standard User h0tblack
(fountain of knowledge) Tue 15-May-07 21:22:08
Print Post

Re: Reading between the lines


[re: deleted] [link to this post]
 
Will you also be providing clear instructions or assistance for people to aid them moving to new email addresses? I don't mean to another provider as I can understand that not beiing something the company would encourage, but to new PlusNet addresses that have not been harvested? Just another thought of something practical that could be done to alleviate future problems for customers.

And possibly revisit some of the longstanding requests regarding security improvements such as adding SSL as an option for all communications with the mail servers.
Standard User OIMO
(fountain of knowledge) Tue 15-May-07 21:37:49
Print Post

Re: Reading between the lines


[re: h0tblack] [link to this post]
 
So reading the latest announcement:

"This list was obtained from our Webmail platform and includes accounts that customers have used to login to Webmail, as well as some email addresses contained in customers' online address books, and addresses customers have sent to using our Webmail service.

and

One of six @Mail servers was attacked and it is possible that customers connected to this server during the incident, may have had their login details observed. Purely as a precaution we advise customers to change their account password by visiting our website..."

So not only is my address compromised but potentially some of my friends and colleagues 'private' addresses and my account details too, oh this goes from bad to worse!

What are the chances they also copied message contents while they were on there?

OIMO
Standard User h0tblack
(fountain of knowledge) Tue 15-May-07 21:51:16
Print Post

Re: Reading between the lines


[re: OIMO] [link to this post]
 
This is something I've been concerned about too.
I suspect (but obviously have no proof) that whomever is behind this grabbed the entire database and has since filtered through it for email strings. I guess the alternative is they did the leg work on PlusNet's own servers and ran a query for all email address strings on the mail server itself, then dumped and outputted just those. For the sake of PlusNet and it's customers I hope they used the more elegant solution. But brute force often wins out...
Pages in this thread: 1 | 2 | 3 | 4 | 5 | [6] | (show all)   Print Thread

Jump to