Affiliate Marketing
Forum Search

Reply
 
LinkBack Thread Tools Display Modes

  #1 (permalink)  
Old 11-09-06
Banned
 
Join Date: Nov 2003
Location: Bucharest, Romania
Posts: 2,684
Thanks: 0
Thanked 0 Times in 0 Posts
Lee_Owen is an unknown quantity at this point
  Login Changed

Dig your passwords out.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 11-09-06
graeme's Avatar
Registered User
 
Join Date: Aug 2003
Posts: 243
Thanks: 0
Thanked 6 Times in 5 Posts
graeme is an unknown quantity at this point
Quote:
Originally Posted by Lee_Owen
Dig your passwords out.
Yes, today we moved to using a SSL encryption for the login process.

We recently (in the last few days) had an isolated case where an Affiliate account was accessed by someone who changed both the account and payment information to themselves. They then requested payment (this was not made). We believe they accessed the account by guessing the password (it was a weak password). There has recently also been a thread elsewhere in this forum about this happening with other network. So we have taken proactive measures starting today.

Now with Paid On Results your Affiliate ID and password are never sent in clear text at any stage of the login process. But what about when we email them to you when you signup, or forget the details - well yes that is plain text, however you can change your password via the interface, and this is over SSL too so if you do have to get it via email then change it straight away after.

Some Affiliate accounts are like banks - containing large sums of money, plus important details such as keywords used to make sales, where sales are made and more - if you gained access to an account to a major affiliate imagine what you could do with that information.

Now we know SSL encryption won't prevent this on its own, but this is one of many things we are working on to improve the security and to protect the integrity of our system. More will be announced within the next few days.

And remember if you use your children's name, pets name or girlfriend/boyfriends name, add a number to the mix as it's these passwords that are the easiest things to break.

Graeme
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 11-09-06
Banned
 
Join Date: Nov 2003
Location: Bucharest, Romania
Posts: 2,684
Thanks: 0
Thanked 0 Times in 0 Posts
Lee_Owen is an unknown quantity at this point
I only read a bit of the above but from doing a bit of domaining to help with a learning curve, you could go one step further with your security.

If an affiliate signs up with a certain domain, gets newsletters on that account and then doesn't renew the domain for a reason, new owner gets emails from your site, and is a bit dodgy, he can then simply put the email address into your system and get username and password and he's in, no problem, you need the 'question security' as well or at least something else.

It would be rare but you'd be surprised how many people are signed up to myspace and a few other sites and leave their old domains as the regd email and it continues to get the newsletters, I know as I have several like that, luckily I aint dodgy... much.

Your system is nice and easy to get a reminder username and password from but a little too easy, for me as a user it's good but for the thief even better.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 12-09-06
Supercod's Avatar
Super Moderator
 
Join Date: Jul 2003
Location: Scotland, UK.
Posts: 3,619
Thanks: 6
Thanked 4 Times in 3 Posts
Supercod is a jewel in the roughSupercod is a jewel in the roughSupercod is a jewel in the roughSupercod is a jewel in the rough
Hi, we are one step ahead of you on that one, we already thought about this (only not based on the example you give, as lets face it someone can't be too bright if they lost the domain name that is your main one for all the Networks and so on) but it is to do with the whole if you did get access to a username and password theme, as to be honest it is easy enough to key log someone’s machine (folk that can’t renew important domains for example LOL).

Anyway expect to hear more from us shortly. It’s all about enhancing security without making the system a nightmare to access for legitimate users.
__________________
Clarke

Check out my Blog at www.affiliatemarketingblog.co.uk

Last edited by Supercod; 12-09-06 at 01:24 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Problem with DGMPRO login will 68 DGM Affiliates 9 05-09-05 04:11 PM
auto login at CJ changed?? Matthew Wood Commission Junction - CJ UK 4 11-04-05 08:48 PM
login in ... again and again unclewilco Commission Junction - CJ UK 4 21-04-04 02:31 PM
Login Problems TD Nick TradeDoubler 0 07-01-04 06:59 PM
Login not working sterlingrockUK TradeDoubler 10 15-04-03 04:25 PM


Affiliate Marketing RSS Feeds - Contact Us - Affiliate Marketing - Archive - Privacy Statement - Top

Content Relevant URLs by vBSEO 3.2.0 RC7