Welcome guest, is this your first visit? Click the "Create Account" button now to join.

To disable ads, please log-in.

Shop at TeamEstrogen.com for women's cycling apparel.

Results 1 to 15 of 39

Hybrid View

  1. #1
    Join Date
    Jul 2007
    Location
    way down South
    Posts
    1,114
    That's good to know. That's one reason I wanted to post the warning but was also scared to post the details. The lady TOLD me that she had removed my credit card from their account, but I was still scared it was there.

    I was able to see the name, address, phone and email. That is correct.
    "Chisel praise in stone; write criticism in sand."

  2. #2
    Join Date
    Oct 2004
    Location
    Sacramento, CA
    Posts
    747
    Thank you for sharing this, Sandra. That is such monumentally crappy security/programming that it is enough to make me not trust anything else about Nashbar's shopping cart/account system. No way would I enter my credit card over there now after reading this.

    This isn't "user error." This is a company that doesn't know or care enough to protect their users' privacy and financial info.

  3. #3
    Join Date
    Sep 2006
    Location
    Georgia on my mind
    Posts
    131
    I wonder if the info is in a "cookie" on your system? It's a pain to delete all your cookies in IE, but it would confirm if it's on your computer vs. Nashbar. I have ordered from them, and have not seen this issue "so far".
    It's all about the journey (my reason for riding slower)

  4. #4
    Join Date
    Oct 2004
    Location
    Sacramento, CA
    Posts
    747
    No, it wouldn't be a cookie stored in your system -- that would be the RIGHT way to do this. Instead, Nashbar is including the info in a non-encrypted page on their website, so that anyone with the right link can see your account information -- even without logging in as you. That is the only way this could have happened.

    And it's really bad. It's beyond stupid. Websites that store much less sensitive information than addresses and phone numbers and possibly credit card numbers do a better job of hiding private information. See, for instance, Team Estrogen -- if I send you a link to a page in this forum, when you follow the link, you are still logged in (or not) to your own account; you don't see the page the way I see it when I'm logged into my own account. That's the proper way to do things, and I don't even understand how someone at Nashbar.com could have screwed it up so badly. Somebody needs firin'.

 

 

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •