Afrihost's insecure client portal

:wtf: :wtf: :wtf: :wtf:

You must be joking. This is ridiculous.

And conack the barbarian doesn't know what he's talking about - every other sane site in the world asks you for your password, even if it gives you a link. It's non-negotiable. You wouldn't want the ATM to remember your pin number automatically, no matter who uses it, unless you're mental.
 
A few very valid points have been raised, and we are aware of the concerns that have also been raised.

Many of our users are not as technology savvy as most of the users on MyBB, and for them being able to access their Clientzone directly from their email notifications is not only a significant convenience, but also a way for them to load top-ups quickly and easily.

This notifications emails can be disabled in the Clientzone, if you do not feel comfortable receiving these notifications I would recommend disabling them. If anyone has any safety and security concerns, you are more than welcome to send me a PM so that we can discuss these concerns.
 
Why should I assume anyone would email a link that gives direct access to secure area on their website without requesting the password - who does that?

On the second note - changing the password helps nothing, I've just changed the password and the link still gets me in to my account without requiring a password! What makes you think changing the password helps?

Not personal, but ooi - this is serious guys. How do I deactivate that URL? Some of my staff could have malware on their laptops and that URL could be doing the rounds by now.
How did cybersmart put this... who would log into another one's isp account? to do what? pay for their topup? lol?
 
:wtf: :wtf: :wtf: :wtf:

You must be joking. This is ridiculous.

And conack the barbarian doesn't know what he's talking about - every other sane site in the world asks you for your password, even if it gives you a link. It's non-negotiable. You wouldn't want the ATM to remember your pin number automatically, no matter who uses it, unless you're mental.

If someone else has access to your emails, then it's no less secure than simply going to all your websites and using "Forgot password".
Comparing it to an ATM remembering your password is absurd and you know it, so kindly get off your high horse.

The Afrihost clientzone doesn't allow you access to spend money on anyone other than yourself, and only for Afrihost services.
Sure, the "hacker" could change the email address - but in such an extreme case I'm pretty sure Afrihost could reverse the charges of whatever ADSL/3g bundles the hacker subscribed you to :wtf:

I'm not saying it's best security practice, but there's no reason to flip tables or compare it to an open/public ATM with your pin - as it most definitely is NOT.
 
The Notification Emails are sent using our Secure Mail System, ensuring that your details remain safe and confidential at all points until the delivery is completed.

I call BS. My e-mails are received through an international forwarder and there is no technology outside of end to end encryption that can prevent the e-mail from being read at every mail hop along the way.

Please post a link to how this Secure Mail System technology works so I can evaluate it's strength.
 
On a second note, afrihost displays your identity number in the client zone. Yay enabling identity theft.
 
If someone else has access to your emails, then it's no less secure than simply going to all your websites and using "Forgot password".
Comparing it to an ATM remembering your password is absurd and you know it, so kindly get off your high horse.

The Afrihost clientzone doesn't allow you access to spend money on anyone other than yourself, and only for Afrihost services.
Sure, the "hacker" could change the email address - but in such an extreme case I'm pretty sure Afrihost could reverse the charges of whatever ADSL/3g bundles the hacker subscribed you to :wtf:

I'm not saying it's best security practice, but there's no reason to flip tables or compare it to an open/public ATM with your pin - as it most definitely is NOT.

Your ignorance is like a shining beacon of light. :wtf:

They can view your banking details.

They can change your ADSL package to something you can't afford.

They can change your password so that you cannot access your ADSL any more.

If you can't see the problem here, you're beyond help.
 
Your ignorance is like a shining beacon of light. :wtf:

They can view your banking details.

They can change your ADSL package to something you can't afford.

They can change your password so that you cannot access your ADSL any more.

If you can't see the problem here, you're beyond help.

Your card details are starred out.
Oh no! Unaffordable internet, not that - please no! NO!!!!
:wtf:
 
Your card details are starred out.
Oh no! Unaffordable internet, not that - please no! NO!!!!
:wtf:

Your level of fail is immeasurable. Your bank details aren't blanked out, perhaps check again.

And if people changing your packages is not a problem to you, good for you. For the rest of us, it is.

I don't care if you agree, it still is.
 
Your level of fail is immeasurable. Your bank details aren't blanked out, perhaps check again.

And if people changing your packages is not a problem to you, good for you. For the rest of us, it is.

I don't care if you agree, it still is.

It's blanked out.
It's pointless arguing with the likes of you, please - stop spamming the thread with your idiocy.
I see you have no retort for the rest of my post, which points out if someone can access your email then they could simply go to Afrihost's or ANY other website and "Forgot password".
Done and dusted.
 
It's blanked out.
It's pointless arguing with the likes of you, please - stop spamming the thread with your idiocy.
I see you have no retort for the rest of my post, which points out if someone can access your email then they could simply go to Afrihost's or ANY other website and "Forgot password".
Done and dusted.

Wow, everything's really going over the top of your head. Maybe you need some food or something to get some nutrients back into your skull.

Also, if your banking details are blank, that means you haven't entered any, and are paying by EFT. Mine's definitely there. ;)

Any more false claims you wanna throw at us tonight? Maybe I need some popcorn, this could take a while.
 
I had not know this, had never clicked on that email Client Zone link.

On a second note, afrihost displays your identity number in the client zone. Yay enabling identity theft.

ID number contact details... with the banking details info as well, almost a one stop shop with that link in the email... just a click and straight in.

<Snip> Your bank details aren't blanked out, perhaps check again.<snip>

Yup ... can see everything... Name, card number, bank, branch etc.

Ja I think they should disable this by default and make it opt in.

^^ This.


I would like this silly insecure email hyperlink thing disabled please ASAP.
 
Ja I think they should disable this by default and make it opt in.

I agree with this but then again I'm not in the habit of sending emails that are addressed to me to my whole company.
 
I agree with this but then again I'm not in the habit of sending emails that are addressed to me to my whole company.

Then we may as well do away with passwords and let all sites, banking etc. just send us email links instead of using the current logins.

Me, I prefer double the security, thanks.
 
Many of our users are not as technology savvy as most of the users on MyBB, and for them being able to access their Clientzone directly from their email notifications is not only a significant convenience, but also a way for them to load top-ups quickly and easily.

Opinion incoming:

This goes to the extreme far side of the convenience versus security scale and you can move the liability you have now on to the customer instead, better for Afrihost, more secure for the user. You simply disable this direct link, always require a password and in that email explain to users how to click OK when the browser asks them if it should save the password. Almost the same level of convenience, the user now just needs to do one extra click to get past the login page. And like others have pointed out, making tech unsavvy people believe security is that easy isn't doing anyone any favours.
 
Dear Afrihost - I read your responses with complete shock. Sending out links which provide automatically a login is insecure and goes against anything in the security industry. There is no excuse for it (such as "we do this for the convenience for our not-so-tech-savvy users") - this is really BS and has nothing to do with convenience, but only about your IT team having absolutely no clue about safe-guarding customer information.

I would really hope that you fix asap. In the meantime I will tweet it out, as you could just not be bothered...
 
Your ignorance is like a shining beacon of light. :wtf:

They can view your banking details.

They can change your ADSL package to something you can't afford.

They can change your password so that you cannot access your ADSL any more.

If you can't see the problem here, you're beyond help.

They can even change your account to an 'unshaped capped' profile, thus no more gaming or youtube without buffering.
 
They can even change your account to an 'unshaped capped' profile, thus no more gaming or youtube without buffering.

Valid point, I just checked all my settings in the hope that my crap Afrihost throughput would be due to some hacker downgrading my account, but unfortunately not :-( still sitting with problems....
 
Top
Sign up to the MyBroadband newsletter
X