Talking Carlton Index Lochie O'Brien Kerryn Harrington Lochie O'Brien Kerryn Harrington CFC Home CFC Membership CFC Shop CFC Fixture Blueseum
It is currently Mon Jul 21, 2025 12:03 am

All times are UTC + 10 hours




Post new topic Reply to topic  [ 19 posts ] 
Author Message
PostPosted: Mon Nov 13, 2006 11:21 am 
Offline
Rod Ashman
User avatar

Joined: Mon Feb 28, 2005 8:36 pm
Posts: 2960
Location: Oak Park
Just listening to SEN. The first story is about privacy issues with membership renewals on the site login. With a default password of 'Carlton', by inputting any membership number (if valid) you can access all details of the member online. The number sequences are fairly straightforward so by changing the number sequence and using the Carlton password you can go through dozens of members. You are able to change the password but all the member details are on there and large numbers of members wouldn't use the site for membership issues.

This is a huge concern. The clubs respose is that they believe it is an AFL problem. But as Schibecci said, the members are providing the details to Carlton so it is their responsibility to look after personal details. I tend to agree.

Perhaps all should go on there and change the password in the meantime.

_________________
C'mon Blueboys!


Top
 Profile  
 
 Post subject:
PostPosted: Mon Nov 13, 2006 11:24 am 
Offline
Bruce Doull
User avatar

Joined: Mon Feb 28, 2005 12:41 pm
Posts: 63509
I just went to do that now, and saw this:
Quote:
*The links to the membership renewal page are temporarily unavailable due to technical problems. We apologise for any inconvenience

_________________
And so while others miserably pledge themselves to the pursuit of ambition and brief power, I will be stretched out in the shade, singing.


Top
 Profile  
 
 Post subject:
PostPosted: Mon Nov 13, 2006 11:25 am 
Offline
Stephen Silvagni
User avatar

Joined: Tue Mar 01, 2005 10:04 am
Posts: 28377
Location: *Currently banned*
:shock: That's very very bad. I don't think the club should be looking for someone to blame, they should be fixing the problem ASAP.


Top
 Profile  
 
 Post subject:
PostPosted: Mon Nov 13, 2006 11:28 am 
Offline
Rod Ashman
User avatar

Joined: Mon Feb 28, 2005 8:36 pm
Posts: 2960
Location: Oak Park
Kaptain Kouta wrote:
I just went to do that now, and saw this:
Quote:
*The links to the membership renewal page are temporarily unavailable due to technical problems. We apologise for any inconvenience


They club have removed access to the link temporarily. Huge cock-up! :roll:

_________________
C'mon Blueboys!


Top
 Profile  
 
 Post subject:
PostPosted: Mon Nov 13, 2006 11:51 am 
Offline
Harry Vallence
User avatar

Joined: Tue Mar 01, 2005 11:23 am
Posts: 1797
Location: Half Back Flanker...
Let's face it - they should have removed the whole website....!!

_________________
"...that's the thing about opinion - you don't have to know anything to have one..." Andre Agassi commenting on Pat Cash 2004
"...the less you know - the more you believe..." - Bono 2006


Top
 Profile  
 
 Post subject:
PostPosted: Mon Nov 13, 2006 12:22 pm 
Offline
Bruce Comben

Joined: Tue Jul 18, 2006 5:48 pm
Posts: 49
I am glad that many people also see this as big an issue as I saw it when I first came across it on Thursday. I do have a IT background, but it surely doesn't take a genius to realise that if you know the password, you can change the username (being numeric it's easy) and gain access to other peoples' information.

I did speak to SEN about this yesterday, but it was a matter of last resort. I made three calls to the Club on Thursday, to the Shop (who referred me to the Membership Department), the Membership Department who claimed it wasn't a real issue of concern, and finally Ian Coutts who agreed it was an issue of concern, and was going to contact the AFL on Thursday. Come Sunday with no change, I had the opportunity to mention this to Tony from SEN.

I know there are some who will think that my decision was not wise - it attacks the club, embarrasses them and leaves them open for ridicule. However, they had two business days in which to correct this. No action was taken. Finally, after the media has picked up the story, the club is forced into action.

HOWEVER - let me stress - they have not corrected the problem. From the Carlton website, if you click on the Carlton Shop link, and then click Login along the top of the shop website, you can still enter in membership numbers and passwords. In this respect - nothing has changed. The flaw is still there and you are still able to obtain the personal information of other members.

I do NOT advocate that you do this. I brought this to the attention of SEN only to force the club to act on this issue. My information was available, your information is available. It's not acceptable.

I am concerned SEN released the password over the radio (despite the fact it was actually on the website) and I will mention this to Tony next opportunity I get.

I am not associated with the Board in any respects, nor any camp for or against any "tickets". I am a member of Carlton, and have been since 2000. I came across this whilst renewing my membership for next year. I encourage you to call the club and ask to speak to Ian Coutts until this issue is corrected. Removing links to the membership page doesn't remove the links and flaws in the Online Shop.

P.S. I spoke to someone I know who is a Collingwood fan, cause I wanted to see if they had done the same thing. Unfortunately, they hadn't. I would have used Collingwood as an example if they had! :)


Top
 Profile  
 
 Post subject:
PostPosted: Mon Nov 13, 2006 12:28 pm 
Offline
Geoff Southby
User avatar

Joined: Tue Mar 01, 2005 7:43 am
Posts: 5175
Location: Corner of Queen and Collins
I wouldn't apologise Buzz. This is a real issue and a real flaw and it needed prompt attention. If you've given the Club some time to fix it and they didn't - then you've taken other action then I don't see a problem with your actions.

For too long Carlton seems to have had a 'give it time, it'll fix itself' mentality and sometimes a good hard jolt is needed to ensure action.

I'd suggest that this sort of problem falls between the extremely large cracks in an under-resourced administration. Ian Coutts could hardly be on top of the IT side of the site - it shouldn't be his job. We've recently uncovered a huge technical problem in the Club's email that was stopping emails being received by a key division of the Club from interested sponsors.

Issues like this bring out the lack of resources the Club has in all manner of areas. That doesn't excuse it, merely highlights what strugglers we are.

M


Top
 Profile  
 
 Post subject:
PostPosted: Mon Nov 13, 2006 12:51 pm 
Offline
Laurie Kerr
User avatar

Joined: Tue Jul 05, 2005 7:25 pm
Posts: 125
Meh, My private details (name, address, phone numbers) are on the internet already, and most likely yours too, try here, www.whitepages.com.au

_________________
http://www.talkingcarlton.com/phpBB2/vi ... e9f08ec27b


Top
 Profile  
 
 Post subject:
PostPosted: Mon Nov 13, 2006 1:01 pm 
Offline
Alex Jesaulenko
User avatar

Joined: Sun Feb 27, 2005 6:31 pm
Posts: 24457
Location: Heartbroken
Good get Buzz. There was always something about internet membership renewal that didn't seem right.

_________________
Richard Pratt - A Carlton legend.


Top
 Profile  
 
 Post subject:
PostPosted: Mon Nov 13, 2006 1:04 pm 
Offline
Trevor Keogh

Joined: Mon Feb 28, 2005 8:55 pm
Posts: 776
Location: UK
Thanks for the heads up. I've changed my password.

Yet another example of the club just not really getting it I guess. Resources/money can be an excuse for some things, but when it comes to the basics, like privacy then I don't think there can be excuses.


Top
 Profile  
 
 Post subject:
PostPosted: Mon Nov 13, 2006 1:05 pm 
Offline
Wayne Johnston
User avatar

Joined: Tue Oct 25, 2005 1:20 am
Posts: 8172
Location: PMQ
heres something negative about the club.....



*prepares for avalanche of posts from synbad and chuck wood, sorry, i mean Effes*

_________________
Back like a raging case of pubic lice


Top
 Profile  
 
 Post subject:
PostPosted: Mon Nov 13, 2006 1:15 pm 
Offline
Robert Walls
User avatar

Joined: Mon Feb 28, 2005 5:06 pm
Posts: 3366
@#$%&! - that's the wrongest thing in wrongland.

Whoever mentioned the white pages obviously didn't realise that member's email addresses are on there as well.

Don't ask me how I know that ...

_________________
"In better news for Blues fans, Jarrad Waite was not named on the club's injury list."


Top
 Profile  
 
 Post subject:
PostPosted: Mon Nov 13, 2006 4:14 pm 
Offline
Wayne Johnston
User avatar

Joined: Mon Feb 28, 2005 9:34 am
Posts: 8888
Location: 8888
molsey wrote:
I wouldn't apologise Buzz. This is a real issue and a real flaw and it needed prompt attention. If you've given the Club some time to fix it and they didn't - then you've taken other action then I don't see a problem with your actions.

For too long Carlton seems to have had a 'give it time, it'll fix itself' mentality and sometimes a good hard jolt is needed to ensure action.

I'd suggest that this sort of problem falls between the extremely large cracks in an under-resourced administration. Ian Coutts could hardly be on top of the IT side of the site - it shouldn't be his job. We've recently uncovered a huge technical problem in the Club's email that was stopping emails being received by a key division of the Club from interested sponsors.

Issues like this bring out the lack of resources the Club has in all manner of areas. That doesn't excuse it, merely highlights what strugglers we are.

M


Thats what happens when you use externally hosted spam solutions. If they can spend around $2k on on Web Filtering software, they could of faulked out $1k on its sister product to bring email filtering inhouse. Don't ask me how i know that :wink:

_________________
Mjonc signing off at 8888


Top
 Profile  
 
 Post subject:
PostPosted: Mon Nov 13, 2006 6:25 pm 
Offline
Bruce Comben

Joined: Tue Jul 18, 2006 5:48 pm
Posts: 49
It's with some relief that I say it looks like the problem has actually been corrected at the source - the database with the information appears to have had the default passwords changed to something else. This is the move that has been needed. I thank the club (or the AFL or Telstra or whomever is responsible) for finally fixing the problem.

I presume the club will be able to inform Carlton members on how to obtain their new passwords. This should have been avoided easily by using the same system the ClubLifestyle website uses, username is CFCMembershipNo and your password is your surname. This at least requires both pieces of information.


Top
 Profile  
 
 Post subject:
PostPosted: Mon Nov 13, 2006 8:46 pm 
Offline
Ken Hands
User avatar

Joined: Tue Jun 07, 2005 10:39 pm
Posts: 487
Bloody Pagan, how many things is he going to ruin??

In 2002, he kept talking up how we had picks 1+2 in the draft to the media and look what happened.

He destroyed Kouta's career, the man who played, to quote leigh matthews "the best year of football by anyone".

He's ruined the careers of the youngsters we had on our list that were on the verge of tearing the competition to pieces - Wiggins, Sporn, Livingston.

He made us leave Optus Oval because the extra 10 minutes in the car didn't suit him.

We only got $10 million from the government to upgrade Princes Park, my mail has told me that if Pagan wasn't there it would have been $50 million.

If Pagan wasn't there Walker would have won a Brownlow by now and Fevola would be kicking how many goals a year? 120? 150? I'm guessing the latter.

We've been winning a premiership every 8 years, we were due in 2003 and Pagan could only deliver 10 wins, pathetic.

Pagan's now delivered two wooden spoons when the club is already full of talent, we don't need first draft picks, the talent is there in abundance already.

and finally to top it all off he's [REDACTED] the website!!! the nerve of this clown, the sooner he is gone the better!

_________________
"Davies could eventually become a player of Judd's ability" - Paganite03 Click here to see for yourself!


Top
 Profile  
 
 Post subject:
PostPosted: Tue Nov 14, 2006 9:33 am 
Offline
Harry Vallence
User avatar

Joined: Thu Sep 07, 2006 11:15 am
Posts: 1196
Location: Terra Australis
not to mention CG that he has stopped it raining so it doesnt affect his morning wlaks...

_________________
Ich bein ein Carltonian


Top
 Profile  
 
 Post subject:
PostPosted: Tue Nov 14, 2006 11:42 pm 
Offline
Rod Ashman
User avatar

Joined: Sun May 01, 2005 8:24 pm
Posts: 2821
Location: In The Boot Of Brendan Fevola Car
Fevola25 wrote:
Meh, My private details (name, address, phone numbers) are on the internet already, and most likely yours too, try here, www.whitepages.com.au


Exactly,it's not like your details of how much you make,had sex with are on it,lol.


Top
 Profile  
 
 Post subject:
PostPosted: Tue Nov 14, 2006 11:47 pm 
Offline
Rod Ashman
User avatar

Joined: Sun May 01, 2005 8:24 pm
Posts: 2821
Location: In The Boot Of Brendan Fevola Car
HTP wrote:
F@%&#! - that's the wrongest thing in wrongland.

Whoever mentioned the white pages obviously didn't realise that member's email addresses are on there as well.

Don't ask me how I know that ...


email addresses on White pages?,well there you go,the government with their sensus.


Top
 Profile  
 
 Post subject:
PostPosted: Wed Nov 15, 2006 7:46 am 
Offline
Stephen Kernahan
User avatar

Joined: Mon Feb 28, 2005 11:53 am
Posts: 17563
Location: Left Cuckistan
Rambo Stallone wrote:
HTP wrote:
F@%&#! - that's the wrongest thing in wrongland.

Whoever mentioned the white pages obviously didn't realise that member's email addresses are on there as well.

Don't ask me how I know that ...


email addresses on White pages?,well there you go,the government with their sensus.


Yeah nice comprehension there Mensa.

_________________
The only way for some people to understand is for them to be on the receiving end

Left wing moralists
In self serving denial
They shit me no end


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 19 posts ] 

All times are UTC + 10 hours


Who is online

Users browsing this forum: No registered users and 51 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
cron
Powered by phpBB® Forum Software © phpBB Group