Showing posts with label hack. Show all posts
Showing posts with label hack. Show all posts

Friday, May 1, 2009

DebtGoal: How big can a 'glitch' be and still be a 'glitch?'

Today I was shocked to learn that in the past month I've made zero progress towards paying off the balance on my Target Visa card, which sits at a whopping 20% interest rate.

Mostly, I was surprised because I've never had a Target card. I've also never had a credit card with a 20% interest rate. I'm sure you can imagine my shock!

That said, I'm sure someone else was even more surprised when they opened their DebtGoal statement and discovered that they owe USAA the cost of roughly one month in Africa plus airfare for three. (Sometimes I still surprise myself).

As it turns out, a "glitch" occurred in DebtGoal's system that mistakenly sent someone else's statements to "a limited number of users."

Thankfully, DebtGoal doesn't actually collect account numbers, and I didn't receive any identifying information about the person whose statement I received. I communicated with DebtGoal and was told it was an error, which affected only some of their users, and a few hours later received an accurate statement.

It did get me reconsidering though. I leave all of my organizing to the Web. I'm responsible for little file storage or organization of actual "paper" some free Web service is out there for everything. My digital photos are all stored online (presuming this to be FAR more reliable than my hard drive or a DVD my kids are likely to turn into a school construction project).

According to an article from TechCrunch in April, Facebook, Twitter and Google Documents have all recently had similar breaches. I myself have experienced mis-directed Twitter tweets, and even some people have complained of trying to view my profile and getting someone elses' (usually SPAM-intense or otherwise offensive) profile.

Just how much faith should we have in the cloud? What can our providers do to ensure that we won't have our personal information or bank account balances eventually being tied to our google profiles because of some security "glitch."

Which brings me to my last point...someone must distinguish the lines between a security "anomaly," "glitch," "error," "leak," and an all-out "hemorrhage."

Don't be mistaken, I'm not unhappy with DebtGoal, they didn't release sensitive information to me, mostly just confusing. I don't think they even store sensitive data (their structure wouldn't require it). That said, other sites I use regularly do. Sometimes I use a favorite site like Amazon, Paypal or other to see what my credit card number actually is--as I shredded it a few months ago. If they're the only ones that still know my credit card number, I really want to make sure its safe. Exactly how much should we be trusting "the cloud?"

Update: DebtGoal responds to security breach

Jessica Ward is a freelance writer from Seattle. She writes on personal finance, technology and family. To learn more, visit www.jessicaward.me or follow her on Twitter at @jessc098

Saturday, March 8, 2008

Hacker: Prosper security 'above average'

The hacker who exploited cross-site scripting (XSS) vulnerabilities on Prosper called their security "above average" in a post on prospers.org. Although their security is better than most financial sites, the XSS vulnerability is significant and could allow a site visitor to download unexpected images with malicious code among other things he said.

One Prosper lender showed he was able to change the displayed credit grade and DTI ratio of a borrower listing by introducing a style sheet in the listing description.

In other cases, XSS vulnerabilities have been used to:

  • allow an attacker to run code on a user's machine without their knowledge after visiting the infected page
  • trick the user into sending their username and password to the attacker by altering the original webpage
  • allow the attacker to steal the user's cookie which could enable the attacker to login as the user

According to Prosper, "there are no known cases of hackers exploiting these vulnerabilities to date." Prosper will release a patch this weekend to fix the vulnerability.

Friday, March 7, 2008

'Ninja' hacks Prosper

According to GhettoWebmaster.com, Prosper's listing feature is open to XSS attacks and other hacks. GettoWebmaster demonstrated the potential by changing the background color of his own humorous borrower listing: Ninjas need funding for anti-pirate propaganda campaign.


According to a message he sent to Prosper, "Your member profile and listing pages are likely open to cross site scripting (XSS) attacks and other hacks at the moment. You can take a look at my profile and current listing to see that I did some light CSS tweaking to customize those pages. I didn’t test any potentially malicious stuff since this is a financial site."

Previously GettoWebmaster found vulnerabilities in the popular HotOrNot dating site. At that time he reported the vulnerabilities on HotOrNot could:

  1. Auto-redirect all visitors to my profile to the url of my choosing.
  2. Render the entire page blank.
  3. Replace the entire profile with an image of the profile which was linked to the url of my choosing. etc, etc, etc…

When borrowers create a new listing they have the option to edit the source html of the loan description as shown below. This is where the vulnerabilities were apparently introduced.


A discussion about the ninja listing can be found on the prospsers.org forums. It looks like Prosper needs that new software engineer ASAP.

A Great New Idea in Online Investing