(RESOLVED) Will it ever be implemented? HTTPS

(RESOLVED) Will it ever be implemented? HTTPS

Author
Discussion

AndrewEH1

4,917 posts

155 months

Wednesday 8th February 2017
quotequote all
Mattt said:
Can Haymarket confirm the data breach?
Link to sauce?

biglaugh

WinstonWolf

72,857 posts

241 months

Wednesday 8th February 2017
quotequote all
I think there needs to be an official statement.

Tonsko

6,299 posts

217 months

Wednesday 8th February 2017
quotequote all
Amusingly Haymarket Media Group run SC Magazine. For, um, computer security.

https://www.scmagazine.com/

SystemParanoia

14,343 posts

200 months

Wednesday 8th February 2017
quotequote all
laugh
Its unbeliveable

plasticpig

12,932 posts

227 months

Wednesday 8th February 2017
quotequote all
Tonsko said:
Amusingly Haymarket Media Group run SC Magazine. For, um, computer security.

https://www.scmagazine.com/
Yes good isn't it frown

Mattt

16,661 posts

220 months

Wednesday 8th February 2017
quotequote all
Anyone who is concerned should email datacontroller@haymarket.com

dmsims

6,601 posts

269 months

Wednesday 8th February 2017
quotequote all
Mattt said:
Anyone who is concerned should email datacontroller@haymarket.com
Don't bother

"10 SECURITY OF YOUR INFORMATION

We follow appropriate security procedures in the storage and disclosure of your Information so as to prevent unauthorised access by third parties."

They don't reply either - tossers

Silent1

19,761 posts

237 months

Wednesday 8th February 2017
quotequote all
I just want to make it clear, I'm in no way responsible for any data breaches that may have occurred.

Dan_1981

17,430 posts

201 months

Wednesday 8th February 2017
quotequote all
IS there a breach?

Or is this still a "it's possible" due to issues highlighted over the last 17 pages?

SystemParanoia

14,343 posts

200 months

Wednesday 8th February 2017
quotequote all
Silent1 said:
I just want to make it clear, I'm in no way responsible for any data breaches that may have occurred.
I love your website smile

Vaud

51,002 posts

157 months

Wednesday 8th February 2017
quotequote all
SystemParanoia said:
I love your website smile
It's even running Google Analytics.

Silent1

19,761 posts

237 months

Wednesday 8th February 2017
quotequote all
SystemParanoia said:
Silent1 said:
I just want to make it clear, I'm in no way responsible for any data breaches that may have occurred.
I love your website smile
There's still something hosted there?! hehe

PistonTechs

36 posts

156 months

PH Techies

PH TEAM

Thursday 9th February 2017
quotequote all
In reference to recent posts, we have conducted an investigation in the alleged breach. To our knowledge no data breach has occurred, and to this end no breach has been reported to the ICO. We do have written internal policies and procedures in place to alert us to and deal with a data breach if one occurs. None of our Data Breach protocols have been triggered.

I have been in contact with the PistonHeads technology team and they are continuing to work on implementing HTTPS on all pages that have personal data (e.g. login and registration) as a top priority and are close to being able to confirm a timeframe on when this work will be released. Once this is known they will be providing another update.

Haymarket Media Group Global Data Protection Officer

dmsims

6,601 posts

269 months

Thursday 9th February 2017
quotequote all
Maybe instead of spouting corporate speak (can someone translate that?) you should update this policy until it's fixed

"10 SECURITY OF YOUR INFORMATION

We follow appropriate security procedures in the storage and disclosure of your Information so as to prevent unauthorised access by third parties."

to

We allow anyone to see your password in plain text on any public wifi, we were alerted to this a long time and have done diddly squat about it


How long does it take 12 people to change a few lines of "code" ?

thebraketester

14,352 posts

140 months

Thursday 9th February 2017
quotequote all
PistonTechs said:
Haymarket Media Group Global Data Protection Officer
laugh

You guys are just making up job titles now aren't you?

Vaud

51,002 posts

157 months

Thursday 9th February 2017
quotequote all
PistonTechs said:
To our knowledge no data breach has occurred, and to this end no breach has been reported to the ICO. We do have written internal policies and procedures in place to alert us to and deal with a data breach if one occurs. None of our Data Breach protocols have been triggered.
I've seen some denial in corp information security in the last few years but that takes the biscuit.

You don't know what you don't know (to quote Rumsfeld). It is an arrogant position to hide behind policies and procedures, especially when dealing with a complex legacy estate like PH, which you openly admit does';t have some basic security in place.

If you can't do it yourself, then call in some experts. Your auditors may be able to do some advisory work. Or a niche company.

Or create a private forum on PH to discuss the issue and take some free (already offered) advice from some domain experts. I know some, but not all. There are some seriously smart people who love PH and don't want to see what is essentially OUR data compromised.

But you seem blind to it.

SystemParanoia

14,343 posts

200 months

Thursday 9th February 2017
quotequote all
Silent1 said:
SystemParanoia said:
Silent1 said:
I just want to make it clear, I'm in no way responsible for any data breaches that may have occurred.
I love your website smile
There's still something hosted there?! hehe
I feel it deserves the full 1995 web 1.0 treatment resplendent with frames, starfield gifs and embeded midi files. :biggrin:

TheExcession

11,669 posts

252 months

Thursday 9th February 2017
quotequote all
thebraketester said:
PistonTechs said:
Haymarket Media Group Global Data Protection Officer
laugh
You guys are just making up job titles now aren't you?
Yeah it made me laugh too - especially the 'Global' bit.

If anyone else remembers Cyberface and Silent1 back in the day?

SystemParanoia said:
I feel it deserves the full 1995 web 1.0 treatment resplendent with frames, starfield gifs and embeded midi files. :biggrin:
hehe

It's truly shocking - the alleged premier UK motoring site - rofl

dmsims

6,601 posts

269 months

Thursday 9th February 2017
quotequote all
FAO the Data protection officer:

"11 REPORTING OF SECURITY VULNERABILITIES

Haymarket Media Group Ltd is committed to the privacy, safety and security of our customers. If you discover a potential security vulnerability, we would appreciate it if you could report it just to us in a responsible manner. Please email us at data.protection@haymarket.com and we will respond to you as soon as possible. This provides us with an opportunity to work with you and quickly address and resolve any issue. Publicly disclosing a potential vulnerability could put the wider community at risk, and therefore we encourage you to come to us first. We’ll keep you informed as we move forward with our investigations."

Please change this to:

If you report a potential security vulnerability

1. We will completely ignore you
2. We will not inform you of anything (because there is no vulnerability) and our 12 strong development team have much more important things to do

rolleyes


NRS

22,318 posts

203 months

Thursday 9th February 2017
quotequote all
PistonTechs said:
I have been in contact with the PistonHeads technology team and they are continuing to work on implementing HTTPS on all pages that have personal data (e.g. login and registration) as a top priority and are close to being able to confirm a timeframe on when this work will be released. Once this is known they will be providing another update.

Haymarket Media Group Global Data Protection Officer
As a non-techie this seems to read as you have used over a year on a known problem to make a timeline on solving part 1 of the issue (which seems to be the easiest)?