(Mis)Uses of Technology

(Mis)Uses of Technology

by Mike Masnick




When Friends Give Your Info To Commercial Websites With Security Holes

from the hmm... dept

We've posted a few stories wondering why people aren't upset that their friends and acquaintances are providing their private contact info to a random company named Plaxo. Of course, people might get a little more concerned if they knew that Plaxo's security wasn't so hot. Jeremy Wagstaff points out that Plaxo was recently alerted to a huge security hole that revealed everyone's contact list info. Once again, you have to wonder: why are we okay that someone we know is giving all of our info to a company who can't even keep it private? And, if they reveal all the info, who is the responsible party? Plaxo, or our "friends" who gave our info to Plaxo?

2 Comments | Leave a Comment..

 
 

Reader Comments

(Flattened / Threaded)

    Mar 17th, 2004 @ 10:33pm
  • You Can't Win

    by beck


    I started a new email address for personal correspondence only. No Internet signups, don't give the address to anyone but friends and family.


    Two weeks later my grandmother sends me an online greeting card from some fly-by-night outfit.


    Thanks Grandma.

    (reply to this comment) (link to this comment)

  • Mar 17th, 2004 @ 11:23pm
  • Plaxo Security

    Mike,

    We acknowledge the recent vulnerabilities that were reported and in both cases, Plaxo reacted very quickly to the reports and fixed the problems within hours of receiving each report.

    While I'm not attempting to diminish the seriousness of the vulnerabilities, their reach was limited since the vulnerabilities only applied to the smaller population of Plaxo Web users, and they could only be implemented by targetting individual users. In revewing the behavior of both vulnerabilities, we do not believe any user's data was compromised beyond those who reported the problems. But nevertheless, since late last week, we've made a number of additional changes and enhancements to the service in order to minimize the occurance of these types of problems again.

    We appreciate the Internet community and our users in assisting us and enhancing our service by making us aware of these problems. We would like to thank our users for their continued support.

    Shortly, we will be adding to our web site a Privacy and Security area to better inform our users of potential security problems and fixes, in addition to best practices, FAQs, articles, and discussion forums on security and privacy issues regarding the usage of Plaxo. Questions on security, privacy, or abuse can be directed to my attention by contacting us at privacy-at-plaxo.com.

    (reply to this comment) (link to this comment)

Add Your Comment

Have a Techdirt Account? Sign in now.
Get Techdirt’s Daily Email
Plain Text HTML
Save me a cookie
  • Plain Text: A CRLF will be replaced by break <br> tag, all other allowable HTML is intact
  • HTML: No formatting of any kind is done without explicitly being written in
  • Allowed HTML Tags: <b> <i> <p> <a> <em> <br> <strong> <blockquote> <hr> <tt>
Close
Have a Techdirt Account? Sign in now.
Get Techdirt’s Daily Email
Plain Text HTML Save me a cookie

Search Techdirt
And now, a word from our Sponsors..



Subscribe to Techdirt's Daily Email Newsletter

Techdirt's Daily Email Newsletter

Related Stories
Close
E-mail It