Nando's Firestarters website exposes user data

Bradley Prior

MyBroadband Journalist
Staff member
Super Moderator
Joined
Oct 16, 2018
Messages
5,009
Reaction score
1,581
Nando's Firestarters website exposes user data

Nando's has shut down its FireStarters website following a data breach which resulted in user details being exposed online.

The FireStarters website prompted visitors to fill out a survey containing their personal details - including their full name, email, and cellphone number - to join the community and stand a chance to win prizes.
 
I'm sure POPIA protects us. Oh wait ...:rolleyes:

Any idea why we are one of the most cyber targeted counties in the world, where even a loss of R1m is not considered big enough by SAPS to launch an investigation?

:sleep::sleep::sleep::sleep:
 
I'm sure POPIA protects us. Oh wait ...:rolleyes:

Any idea why we are one of the most cyber targeted counties in the world, where even a loss of R1m is not considered big enough by SAPS to launch an investigation?

:sleep::sleep::sleep::sleep:
Maybe because SAPS doesn't have the capacity/skills? Same apply to the Hawks and NPA.
 
I'm sure POPIA protects us. Oh wait ...:rolleyes:

Any idea why we are one of the most cyber targeted counties in the world, where even a loss of R1m is not considered big enough by SAPS to launch an investigation?

:sleep::sleep::sleep::sleep:

Looks like a case of negligence from nandos rather than popia failure... The urge to blame government for everything is just irresponsible
 
Looks like a case of negligence from nandos rather than popia failure...
Still slow I see. Let me join the neuron dots for you.

Fines are a great tool to ensure accountability and responsibility. You only have to look what happening in other countries. Educate yourself on the GDPR. Yet in South Africa any crappy programmer that knows half a keyboard and zero cybersecurity sense is it. Once the risk of punitive damages increases, affecting shareholdings, suddenly CFOs start taking notice. They actually start insisting that marketeers and suppliers have sufficient verifiable skills.

But that won't happen atm. Because POPIA has been rapidly not been happening - since pa fell off the wagon ... and into the firepool.

In the meantime our information gets stolen, abused and traded. Yet what real cyber crime protection do we have? Remember debit order fraud? Ever heard about BEC? Atm you are on the internet highway posting here, but nobody is really in control of the cars. There are laws, but nobody is in a position to enforce them. The closest we come to it is SAPS. Yet the Cyber Crimes Bill, despite all it's flaws, is still a low priority. In the meantime we're one of the top cyber crime targeted countries in the world. Yet it doesn't exist as per SAPS. Do you want to argue? Show me our cyber crime stats.

Now, just to go and make yourself feel good, look at https://m-net.dstv.com/show/carte-blanche/videos/cyber-impersonation-scam/video

Not only this, but other types of cyber crime are forcing businesses to close, people to loose jobs.

Why are we here in this fsck'ed up situation? I think I've now given you enough clues to go join those dots.

The urge to blame government for everything is just irresponsible
The urge to deny and understand where the failures are if you have no understanding, is not irresponsible, it's pure recklessness. You're on my terrain here. See me as that secretary bird, Mamba.
 
Next time someone asks you for your email details, use a gmail or hotmail or outlook account and use the . notation to add something related to the site you're signing up for.
E.g. if your email address is [email protected], submit [email protected]
Then set up a flag in gmail or outlook or whatever for any messages that arrive with [email protected] in the address. You'll then quickly be able to see who's stolen your address or handed it out in future. Not going to help preventing anything, but it's an interesting exercise.
I think you mean +, not?
. has no significance in GMail: joe.soap122212121221221@google = joesoap122212121221221@google

Anything after a plus has no routing value, great for mail filters:
joesoap122212121221221+mybb@google = joesoap122212121221221@google

joesoap1222121212.21221@google != joesoap1222121212@google

https://gmail.googleblog.com/2008/03/2-hidden-ways-to-get-more-from-your.html

So it should be [email protected]
 
Update – Nando’s has stated that this security issue is not the result of a data breach, but was instead caused by the circulation of a cached survey page.

Nando's usually hit the mark with their ads, but they didn't hit that mark here. It is a data breach because they were vulnerable and they were vulnerable due to whoever is responsible at Nando's.

Ask Nando’s why the page was cached, and yes, the article does state that they are investigating, but really now, there is not much investigation to do in order to establish by who and why the page was cached leaving them vulnerable.

This line,

“Our investigation is looking into how one old page was cached, we have already requested that Google remove any cached pages, and will confirm once we are clear this has taken place.”

Gives me the idea that they themselves don’t know how many 'vulnerable' pages were cached.
 
Nando's usually hit the mark with their ads, but they didn't hit that mark here. It is a data breach because they were vulnerable and they were vulnerable due to whoever is responsible at Nando's.

Ask Nando’s why the page was cached, and yes, the article does state that they are investigating, but really now, there is not much investigation to do in order to establish by who and why the page was cached leaving them vulnerable.

This line,

Gives me the idea that they themselves don’t know how many 'vulnerable' pages were cached.
The one I found easily was not the party listed. :unsure:
 

Very stupid.

https://www.businessinsider.co.za/n...-website-data-leak-consumers-fast-food-2019-7

Business Insider previously incorrectly reported that the Firestarters website was de-activated: while the Firestarters.co.za page is not functional, the main portal page Firestarters.co.za/hub was working.

“Nando’s South Africa is aware of a potential online breach on their Firestarters survey platform," a spokesperson said.

"After extensive work it appears that only two people have been affected and we have been in touch with them as part of our full investigation. We have increased further security measures to prevent possible exposure of personal details and will update our fans on further steps to be taken once our investigation is concluded.

There is no evidence that there was any negligence on Nando's side, a spokesperson told Business Insider.

Nando's says that at this stage it looks like the problem was due to "user error".

Do they even know how web crawling work? Blamed the user, terrible practice.
 
Nando's usually hit the mark with their ads, but they didn't hit that mark here. It is a data breach because they were vulnerable and they were vulnerable due to whoever is responsible at Nando's.

Ask Nando’s why the page was cached, and yes, the article does state that they are investigating, but really now, there is not much investigation to do in order to establish by who and why the page was cached leaving them vulnerable.

This line,



Gives me the idea that they themselves don’t know how many 'vulnerable' pages were cached.
True. I call BS on Nando's too.
Plain and simple, they cocked up not google. Excuse the pun... (bun)
 
Top
Sign up to the MyBroadband newsletter
X