Bugtraq mailing list archives

Authorize.net follow up.


From: John Hennessy <johnh () CHARM NET>
Date: Fri, 25 Aug 2000 12:57:58 -0400

Just wanted to let everyone know how the situation with authorizenet went.
After the post here I contacted them again to try to get some action
taken. They still ignored me. On August 14th an article about this problem
appeared on the frontpage of the technolocy section of the baltimore sun.
The day friday before the article was to be released authorizenet finaly
fixed the problem.

Here's the article that was in the baltimore sun.
http://www.sunspot.net/content/news/story?section=news-pluggedin&pagename=story&storyid=1150420204148

As of today authorize.net has NOT put up a notice on their webpage telling
customers about this problem. Since people were not informed about this,
they problem still exists for the 83,500 customers that used the page
before the problem was fixed. Their history files still contain the plain
text login and password.

A week ago I contacted authorize.net again and asked that they please put
up a notice on their webpage. As of yet they have not responded to me. The
guy who did the article also called them and suggested they put up a
notice.

I also wanted to mention rfp's policy on contact companies about problems
like this. I read it and I think was very well written and is fair.

I'd like to say thanks to dave dittrich for his help on this also.


-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
John C. Hennessy                        johnh () charm net
Systems Administrator                   410-558-3579
Charm Net, Inc.                         http://www.charm.net

"Do just once what others say you can't do, and you will never pay
attention to their limitations again." - James R. Cook
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-


Current thread: