moviepack data unsecured?

October 31, 2006 8:51 PM
Related Categories: GRRR, video, Technology

I was doing a google search on my email address today, as I have seen some odd spam lately. On the second page of search results I came across this very odd page. (link removed just in case). Imagine a .csv file with about a thousand records.

Turns out it is a list of customers, their address, phone, comments, and some other junk. I don’t see anything like a credit card. I am not familiar enough with it to know if the data contains anything more than privacy / identity theft risk.

After a short bit of research it becomes clear that the data is from my account with Moviepacks.com back in 2003. Running from software made from this company.

From April to August of 2003 (give or take) I rented a few movies and video games. Nothing to exciting, and not worth the money so I stopped using the service. Looks like they still have me as an account, and know that my credit card is no longer good (got a better deal). Why is my data out in the public. What does this company think its doing leaving it output on a public server for google to index?

For your inquisitive pleasure here is my order history:

Title    Date Shipped    Date Returned
    Bourne Identity    2003-06-23    2003-08-19
    The Simpsons Skateboarding (PS2)    2003-07-01    2003-08-19
    Donnie Darko    2003-07-01    2003-08-19
    Fight Club    2003-06-06    2003-06-30
    Kingdom Hearts (PS2)    2003-06-06    2003-06-30
    Igby Goes Down    2003-06-06    2003-06-23
    8 Mile    2003-05-08    2003-06-05
    The Getaway (PS2)    2003-04-03    2003-06-05
    Barbershop    2003-03-17    2003-04-17
    Rules of Attraction    2003-03-17    2003-04-03
    .Hack: Mutation (PS2)    2003-03-17    2003-04-03

Update: I have decided to send them a note to let them know, just in case there is other even more unsecure info out there also exposed. We will see how long it takes. I don't think the link I made is very bad, since it is already on the google index, and is really just contact information. However I reserve the right to remove the link at some point if I change my mind.


Like this entry? Subscribe to my blog.

Comments (moderation on)

Sponsors


Savvy Content Manager