Crystal Web slashes ADSL prices

You can tell me as many times as you like.
Answer me this, why then allow said company with alleged poor security access to the data in the first place, what about risk assessment, and security measure? Not knowing or being hoodwinked, are not good excuses.

CW were not the only ISP affected. There were more, and the truth will most definitely surface.
What ISP would you choose if all of the major players were also affected by this issue, but kept shtum?
 
You can tell me as many times as you like.

Answer me this, why then allow said company with alleged poor security access to the data in the first place, what about risk assessment, and security measure? Not knowing or being hoodwinked, are not good excuses.

It does not matter whose fault it is or was, as a customer I don't care. I signed up with the ISP for a service, that service was compromised due to a failing by a something that the ISP employed or let access to their system.

If you're going to let entities access or carry your 'stuff', you damn well make sure you've vetted and QA'd their processes so you can protect your IP. At the end of the day, if something happens it's your fault for letting it happen in the first place. You are the sum of your parts.
No its not your fault. But you may fall for it as you are the accountable one.


Tell me. Do you subscribe to any Sony sites? Or LinkedIn?
 
No its not your fault. But you may fall for it as you are the accountable one.


Tell me. Do you subscribe to any Sony sites? Or LinkedIn?

Nope, others yes, but I employ different ways of using credentials these days so I don't have to worry about having my stuff compromised.
 
Been using crystalweb for more than a year now no issues, will actually still pay 429 a month to ensure my service stays the same
 
So you give others the chance but not CW?

Ja I'll give others a chance until they also stuff up. Best they keep it quiet then.

I'm using CW as an example. We could all have a massive Kumbaya for how lucky we are they told us. Fact remains we need to hold companies accountable for their mistakes with our data, not just praise them for owning up.

I gave CW a few chances related not only to the leak but to the level of interaction with support and their tools. It was not up to the same standard as another provider I use.

I'm just waiting for my details to be compromised then I can move onto the next flavor of the week, eventually I'll run out of choices then you can lynch me for it. People who recommend Afrihost need their heads testing though.
 
Ja I'll give others a chance until they also stuff up. Best they keep it quiet then.

I'm using CW as an example. We could all have a massive Kumbaya for how lucky we are they told us. Fact remains we need to hold companies accountable for their mistakes with our data, not just praise them for owning up.

I gave CW a few chances related not only to the leak but to the level of interaction with support and their tools. It was not up to the same standard as another provider I use.

I'm just waiting for my details to be compromised then I can move onto the next flavor of the week, eventually I'll run out of choices then you can lynch me for it. People who recommend Afrihost need their heads testing though.
It kinda feels like you've painted yourself into a corner and now are unable to exit gracefully.

It's ok to simply admit that you may have overreacted - I've done so plenty of times... :embarrassed: - we're all human after all.

:)
 
I'm guessing Ubiquiti as I've heard they have very good software.

Ubiquiti would be super cool, as I have 3 Ubiquiti UniFi APs providing the wifi for my property.

You can tell me as many times as you like.

Answer me this, why then allow said company with alleged poor security access to the data in the first place, what about risk assessment, and security measure? Not knowing or being hoodwinked, are not good excuses.

It does not matter whose fault it is or was, as a customer I don't care. I signed up with the ISP for a service, that service was compromised due to a failing by a something that the ISP employed or let access to their system.

If you're going to let entities access or carry your 'stuff', you damn well make sure you've vetted and QA'd their processes so you can protect your IP. At the end of the day, if something happens it's your fault for letting it happen in the first place. You are the sum of your parts.

You can't be serious. It is impossible for any medium to small business to insist that all their business partners show them their inner workings to satisfy their security concerns. They'd sooner not do business with you. And CW already said that they were lied to by the provider concerned, so they did believe that the security being utilised was acceptable.

Loads of big companies have been hacked anyway. It doesn't matter what you do, you'll always be vulnerable to attack. The difference with CW is that they're honest and disclose what's going on. Don't think for a second that your current ISP hasn't hidden incidences to avoid bad publicity.
 
It kinda feels like you've painted yourself into a corner and now are unable to exit gracefully.

It's ok to simply admit that you may have overreacted - I've done so plenty of times... :embarrassed: - we're all human after all.

:)

Overreacted about what big boy?
I'm open minded and enjoy provoking controversy (mostly to see how Bryn reacts)
 
You can't be serious. It is impossible for any medium to small business to insist that all their business partners show them their inner workings to satisfy their security concerns.

Impossible? Says who? You? If you know any good IT security consultants you should call them, it might open your mind to the fact that it's hard but not impossible.

They'd sooner not do business with you. And CW already said that they were lied to by the provider concerned, so they did believe that the security being utilised was acceptable.

I pity the fool who goes around signing contracts with SPs believing every word they say. It would be hilarious if something like Banking software was based on that premise.

I'm trying to determine if you are normally so dismissive, or just messing around with meaningless baseless generalizations?
Enjoy school tomorrow. Hope it's
super cool
 
Meh

So you're a WUM and not to be interacted with seriously then.

Only applies to you. I got bored of reading your replies. Go back read your posts, each one makes an arrogant rude assumptions about the poster rather than address the facts presented. Reminds me of when I was wet behind the ears.
 
Only applies to you. I got bored of reading your replies. Go back read your posts, each one makes an arrogant rude assumptions about the poster rather than address the facts presented. Reminds me of when I was wet behind the ears.
Nope. I haven't been rude nor arrogant at all. In fact, I wished you a good weekend earlier and have interacted with you in good faith throughout.

Cheers
 
Overreacted about what big boy?
I'm open minded and enjoy provoking controversy (mostly to see how Bryn reacts)
Only applies to you. I got bored of reading your replies. Go back read your posts, each one makes an arrogant rude assumptions about the poster rather than address the facts presented. Reminds me of when I was wet behind the ears.

No, AfricanTech is right. To admit that you're just here to antagonise is the definition of a WUM.

Impossible? Says who? You? If you know any good IT security consultants you should call them, it might open your mind to the fact that it's hard but not impossible.

I pity the fool who goes around signing contracts with SPs believing every word they say. It would be hilarious if something like Banking software was based on that premise.

I'm trying to determine if you are normally so dismissive, or just messing around with meaningless baseless generalizations?
Enjoy school tomorrow. Hope it's

IT security consultants examine your own firm. I don't know why you'd think they can just waltz into any office that they please and poke around. And sure, you can pester your business partners for more information about their systems, but that won't be possible if you lack buying power or if they're proficient in the art of deception.

Crystal Web is only one of many ISPs who were affected by the leaked info. You have no idea who the others are, so you don't know who else to boycott. Considering the popularity of the upstream provider amongst their peers, CW had no reason to suspect that their security protocols were unprofessional. Now that they're aware, they've said a hundred times that they've taken drastic steps to minimise their dependence on other firms. You forget that CW is a new ISP - to have no dependence on upstream providers in their early days would have probably been impossible.

Comparing an ISP to a bank makes no sense. The CW leak had almost no impact on the lives of their customers. We changed our passwords and moved on. Banks hold much more sensitive information, not to mention your personal savings and investments. And anyway, guess what: R300m was stolen from Standard Bank customers earlier this year. No one is immune to cyber attacks.

You're holding Crystal Web solely accountable for a security breach that happened to many ISPs, and not on any of their own systems. Do you really think you're more secure for leaving the one ISP that disclosed what happened?
 
Yes passwords apparently were stored in clear text, yes there was a back door. But that isn't the issue in my mind. Even with hashing and salting, why would any company allow their account details to be stored in such a way that made it easy to associate the username/account with the password in the first place? I can only imagine it was stored together in notepad or some db table.

One with an incompetent IT security team, for sure. Ster-Kinekor is a good example. They still store user details on their ticketing website in plain text with no hashing, and getting access to those details is probably not that difficult. This may have also been a hack as a result of a disgruntled employee leaving the company and causing some sabotage, or they may have had some fault creep into the image they deploy for their network, and audting didn't catch it in time. Not every example of a vulnerability is a case of incompetence, which is something I'm sure you'll agree with.

Oddly enough, S-K's IT team was fast enough to patch for heartbleed the week the attack was made known on the net, but they still don't hash passwords.

Whoever is to blame for their poor security or due diligence matters not. There's only one company I signed up with and that's CW. It's their problem and their fault, and my cost, inconvenience, and time. A little more respect for customer details and privacy is needed, and maybe financial punishment for those that don't prepare....

Here I'd have to disagree. There are several legal hurdles that prevent what you envision from happening, and because so many companies on the net use closed-source software, getting access to that for auditing purposes basically doesn't happen unless by fluke or if the company provides a very valuable service to a significant number of corporate customers. I can't reasonably expect, as a ZA citizen, to get Google's authenticator audited to make sure that it's secure and more random than not, but I have to rely on the word of third-party security companies that Google uses to make those claims for them after forensic audits.

Blaming CW wholesale and not letting the issue rest doesn't make sense to me, certainly not as a network engineer, because they owned up to the problem, took services offline as quickly as possible, and made moves to patch it and protect the accounts of users. I mean, that's a really good response to the issue. You don't even get a "Sorry guys, our bad" from Sony or Blizzard.

Answer me this, why then allow said company with alleged poor security access to the data in the first place, what about risk assessment, and security measure? Not knowing or being hoodwinked, are not good excuses.

What's your response to the Linux Mint team being hacked and having malicious code slipstreamed into their ISO images? Or a seemingly innocent integer being deliberately put out of place in the Linux kernel network stack that actually opens up a vulnerability in SSL encryption that was only caught after Linus Torvalds saw it right before a planned beta merge? **** happens, even in open-source projects where the code is scrutinised every minute of every day. You can't be on top of security 110% of the time unless you're not an internet company and keep your network strictly off-limits except in special cases and have a "no portable media" policy.

At some point we have to accept that the nature of the beast means that someone, somewhere is going to screw up the process, and it's not always avoidable. I think Sony is unbelievably lax about security and should have been dragged over the coals before, but I still used their services after fixes were implemented to mitigate the effects of future attacks. Keeping grudges for extended periods of time is just exhausting.
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X