PDA

View Full Version : Renewal security issues


perret318
07-30-2007, 11:31 AM
I'm an existing HostPC customer, renewing my plan with the Yareo billing system. I have three major problems with the signup process:

1. It's done completely over http (not https). I have to enter my password AND my billing info over this connection -- why is this not done over a secured connection? There's a note at the bottom of one of the pages that says something to the effect of "All data sent from this page is sent securely to protect you from fraud", but what else besides that little sentence do I have to tell me that it's a secure connection? IE and Firefox apparently don't recognize it as one.

2. My password was sent back to me in plaintext in a confirmation email. This is a pretty sloppy practice. It should at the very least hide part of the password.

3. I received three emails (Order Confirmation, Customer Invoice, and Welcome) before I even entered my payment info. The Customer Invoice stated that "Payment will be taken automatically on 07/30/2007 from your credit card on record with us." But I haven't entered my info yet! So is it still on file from my existing account? This is very confusing. I stopped at this point anyway because of the above security concerns.

Thanks for your help in addressing these issues.

admin
07-30-2007, 12:16 PM
I'm an existing HostPC customer, renewing my plan with the Yareo billing system. I have three major problems with the signup process:

1. It's done completely over http (not https). I have to enter my password AND my billing info over this connection -- why is this not done over a secured connection? There's a note at the bottom of one of the pages that says something to the effect of "All data sent from this page is sent securely to protect you from fraud", but what else besides that little sentence do I have to tell me that it's a secure connection? IE and Firefox apparently don't recognize it as one.

2. My password was sent back to me in plaintext in a confirmation email. This is a pretty sloppy practice. It should at the very least hide part of the password.

3. I received three emails (Order Confirmation, Customer Invoice, and Welcome) before I even entered my payment info. The Customer Invoice stated that "Payment will be taken automatically on 07/30/2007 from your credit card on record with us." But I haven't entered my info yet! So is it still on file from my existing account? This is very confusing. I stopped at this point anyway because of the above security concerns.

Thanks for your help in addressing these issues.

I'll address #2:
How would you prefer a password be sent? MOST, (>99%) of customers do not enter a password and let the system assign one ... how would they get it if not in plain text? Some email clients can't read a graphic or captcha - so they'd be SOL. This is a part of DA, not something we control - but if you have a suggestion, I'm sure they'd be happy to consider it.

For #1 and #3, please call our office at 518-641-1330 to provide secure cc information if you're suspicious about anything in the order process.

perret318
07-30-2007, 12:30 PM
I'll address #2:
How would you prefer a password be sent? MOST, (>99%) of customers do not enter a password and let the system assign one ... how would they get it if not in plain text? Some email clients can't read a graphic or captcha - so they'd be SOL. This is a part of DA, not something we control - but if you have a suggestion, I'm sure they'd be happy to consider it.

For #1 and #3, please call our office at 518-641-1330 to provide secure cc information if you're suspicious about anything in the order process.
I tried not putting one in, but it wouldn't let me proceed -- it said I must enter one.

If you're getting assigned one and haven't entered one, of course you'd need to get it in plaintext. But in my case, like I said, it wouldn't let me proceed.

Dauns
08-08-2007, 05:54 AM
I tried not putting one in, but it wouldn't let me proceed -- it said I must enter one.

If you're getting assigned one and haven't entered one, of course you'd need to get it in plaintext. But in my case, like I said, it wouldn't let me proceed.
:nod Excellent! That was correct
I support your point of view