Crystal Web suffers ADSL security breach

They were notified, they fixed it and let everyone know about it - this was also done in a timely manner. Anyone who's been on here for a decent period of time can just imagine how any other ISP would have handled this, and whether they would have actually told their clients about it.
 
They were notified, they fixed it and let everyone know about it - this was also done in a timely manner. Anyone who's been on here for a decent period of time can just imagine how any other ISP would have handled this, and whether they would have actually told their clients about it.

^Agreed.

/points at AH
 
If another ISP handled the matter in the same manner as CW, I doubt the response would be the same!
 
If another ISP handled the matter in the same manner as CW, I doubt the response would be the same!

Why? Because of Shaun being a member of this forum?

In some way you are right, because other ISPs has been in the game for a longer period of time. They are larger companies with more money to spend. So, more are expected there. Although, this does not clear CW of any wrongdoing though.
 
Why? Because of Shaun being a member of this forum?

In some way you are right, because other ISPs has been in the game for a longer period of time. They are larger companies with more money to spend. So, more are expected there. Although, this does not clear CW of any wrongdoing though.

Nah, CW has alot fan-boyism in this forum....
 
Nah, CW has alot fan-boyism in this forum....

So does a number of other providers, just look around :)

I think what makes CW different in this regard, is that Shaun has been around for some time and has done quite a bit of good on this forum and outside. He will naturally have quite a bit of people who will support his business from this forum. No problems with that. But, again, look at some comments here, members who have been here for some time and sign up with CW have some harsh words...
 
Nah, CW has alot fan-boyism in this forum....

Give credit where it is due.

And as ShaunSA said, if they cock up then there will be hell to pay. I have come to understand that this community isn't very forgiving.
 
Got my password reset email.

Not pleased with this happening in the first place, but I can't say that C hasn't handled this properly.

DJ... posted in the CW feedback thread and I received an email with the details of the issue shortly after.

That portal has been a huge headache with not much benefit to date. I hope it's sorted out soon.
 
Jealous because your internet is ****ed probably.

Not really, I have mentioned numerous times that If I switched providers, CW would be my first choice.

Pointing out that there is an element of fan-boyism does not mean my internet is ****ed...
 
Usernames can be anything before the realm name (@crystalweb.co.za for example). It's passwords that are unique and should not be 1122, for example.

So once we realised some passwords for DSL accounts had been disclosed, we changed them to prevent any potential issues and shut the door on this being able to happen again. For us it's really just a case of saying there was a list available on the portal, and we don't consider accessing it as hacking as it's our fault, and proactively solving the problem before it becomes one...

Mr. Kaplan
I think it would be in your interests to hire someone, on a consultant basis, to have a gloss over your systems from an infosec standpoint. I can recommend some good people.
 
Necro Warning.

Crystal Web CEO Shaun Kaplan said the “old DSL username and password list” was intended for admins and developers to test portal connectivity with.

@DJ... how can you justify allowing admins and developers to have access to a list of real clear text customer passwords? Passwords should always be hashed (preferably multiple times) and never stored in clear text.

Do not do your testing in a production environment with production data, build a separate test environment with separate test databases.
 
Top
Sign up to the MyBroadband newsletter
X