MoviePass Exposed Thousands of Unencrypted Customer Card Numbers (techcrunch.com) 14
New submitter sizzlinkitty writes: Movie ticket subscription service MoviePass has exposed tens of thousands of customer card numbers and personal credit cards because a critical server was not protected with a password. Mossab Hussein, a security researcher at Dubai-based cybersecurity firm SpiderSilk, found an exposed database on one of the company's many subdomains. The database was massive, containing 161 million records at the time of writing and growing in real time. Many of the records were normal computer-generated logging messages used to ensure the running of the service -- but many also included sensitive user information, such as MoviePass customer card numbers. These MoviePass customer cards are like normal debit cards: they're issued by Mastercard and store a cash balance, which users who sign up to the subscription service can use to pay to watch a catalog of movies.
Reset passwords (Score:1)
Re: (Score:1)
Yes, your "123dontHackMe" was too easy to guess.
Re: (Score:2)
I use Acerose password vault, (Score:2)
it's got a serious security problem in that all it's back-ups are in plain text. But it's what I started with and allows me to use a different password for each site.
Re: (Score:1)
Move to KeePass. You will be glad you did.
No, no they dont (Score:3)
They carried no balance until you checked-in to a movie.
Re: (Score:1)
Worse than password reset scenarios (Score:3, Insightful)
Re: (Score:1)
Re: (Score:2)
I know I've done that with websites before and immediately thought "oh shit, I hope these dumbasses aren't logging bad passwords".
I know everyone on Slashdot hates Paypal, but I try to pay with paypal anywhere online rather than a credit card. I cringe when I can't. With paypal I'll know sooner of any unauthorized payment because I have the e-mails automatically generated; and I can keep online stuff separate from in-person payments.
Value-limited, single-vendor virtual credit cards (Score:3)
https://www.creditkarma.com/cr... [creditkarma.com]
Plans... (Score:4)
I guess their security plan was written by the same guy that wrote their business plan...
Re: (Score:2)
My main question is the "guy" here.
My money is on "monkey".