Canada Post online security breach

p2pnet news | Security:- Karin Bull, owner of a Canadian pet food mail-order business, says she was “devastated” when the Globe and Mail presented with her passwords it had gathered online
“These are passwords I use for other online applications like e-mail and banking,” the story has her declaring.
“I’m definitely going to think twice about repeated attempts to login anywhere online again.”
At the centre of the revelation is what’s been called a glitch on the Canada Post website which, ironically, has as its slogan ‘Anywhere to anyone’.
Login records for scores of small businesses that use Canada Post’s business shipping website are available online as a result of a Web server glitch, leaving sensitive information such as names, addresses and shipping details vulnerable, says the story, adding:
François Legault, a spokesman for Canada Post, could not specify the root cause of the security breach, but said the federal agency believes the available “out of date” usernames and passwords pose no threat to its customers. Mr. Legault said the federal agency - which farms out all of its IT services to third parties such as Innovapost and IBM - had addressed the problem.
But a Yahoo search of cached websites Friday revealed more Sell Online usernames and login attempts, says the Globe and Mail
“I’m just curious about these things so I tried it, and boom, there was somebody else’s name and somebody else’s data,” as well as social insurance numbers, driver’s licence numbers and addresses, said Jamie Laning.
He was talking about a massive security breach in Passport Canada online records which, says the agency, has now been resolved.
Also See:
Business data exposed on Canada Post website, December 17, 2007
Huge Canada Passport breach ‘resolved’, December 7, 2007
Want to help p2pnet stay online? Please click here.
Use free p2pnet newsfeeds for your site. It’s really easy!
Subscribe to p2pnet.net | | rss feed: http://p2pnet.net/p2p.rss | | Mobile - http://p2pnet.net/index-wml.php





p2pnet - rss feed: 
