>
>
>

Another TF Club / Fun Pub Security Update - cancel your card numbers and change your passwords!

Posted by Seibertron Feb 29, 2012 at 6:04pm CST 29,807 views
Here is another update from the Transformers Collectors' Club run by Fun Publications. Please read this information if you have been a member of the Club in the past few years or if you have ever used a credit card with their organization.

Transformers Collectors' Club wrote:As we continue to work on our systems, you will see some of our services go offline and then come back, so please be patient as we preserve data and clone servers and websites.

We are also taking this opportunity to remove all non-essential services from our ecomerce server. So in the short term in the next day or so, the club forums will be discontinued. It will be several days until we are ready to bring them back under an entierly new piece of software. I know alot of you have been asking for this so, we have decided to replace several of our systems with new packages. This means that you will not have access to the forum for a while at all. We do plan to make the old forum viewable (no posts) in the future.

Since we do not know exactly what data was taken, we are recommending that if your have used common logins or passwords with our system and any other system that your change your passwords in those systems immidiately (especially any financial sysstems)! We will be resetting all of the passwords in our system very soon. Please don't delay in changing your passwords in other locations.

In addition, we have found a few recent aticles concerning security issues with other vendors. If you use these services, these issues could possibly impact you. Please read the attached links:

http://www.huffingtonpost.com/2012/02/1 ... 68593.html?

http://www.greenpois0n.co/itunes-accoun ... redit.html

Thanks for your support in this difficult time. We will continue to work with our vendors to correct the issues and we apologize for any inconvenience this has caused any of our members.

Brian Savage

Image

If you have not cancelled your credit or debit cards that you have used in the past, you MUST cancel those numbers. It's a very simple process. You just need to call the phone number on the back of your card, explain what happened, and your bank or credit card company will send you a new card which you should received in 7 to 10 business days or sooner (I received one of mine in 4 business days). You MUST do this. It is inevitable that failure to do this will only result in your card being used for fraudulent purposes. Do NOT wait for you to get hit. The only way you can protect yourself is by cancelling your current card numbers and having new cards sent to you.

It is also strongly recommended that you immediately change your passwords if you use your password on TransformersClub.com on any other website or banking website. The passwords in their database are not encrypted and it should be assumed at this point that all of our account information was taken along with our payment information.

More Bots. More News. More Awesome.

Re: Another TF Club / Fun Pub Security Update - cancel your card numbers and change your passwords! (view post)
Comment by Mighty_Galvatron Feb 29, 2012
What?!

What kind of incompetents are running that place?! This is pure stupidity - unacceptable.
Re: Another TF Club / Fun Pub Security Update - cancel your card numbers and change your passwords! (view post)
Comment by DISCHARGE Feb 29, 2012
That's a pleasant surprise for everyone. HUZZAH!!
Re: Another TF Club / Fun Pub Security Update - cancel your card numbers and change your passwords! (view post)
Comment by AutobotCliffjumper Feb 29, 2012
FINALLY, NEW FORUM! Interestingly enough it took a HUGE fudge up to finally get the ball rolling on the right direction. Still not happy about the security/fraudulent charges on my account.
Re: Another TF Club / Fun Pub Security Update - cancel your card numbers and change your passwords! (view post)
Comment by Trikeboy Feb 29, 2012
Instead of continuing to proceed their career in credit reports, has the club actually said sorry and accepted full responsibility yet?
Re: Another TF Club / Fun Pub Security Update - cancel your card numbers and change your passwords! (view post)
Comment by Seibertron Feb 29, 2012
Trikeboy wrote:Instead of continuing to proceed their career in credit reports, has the club actually said sorry and accepted full responsibility yet?


They're apologized, not sure about accepting full responsibility. They might not be able to legally, I'm assuming that's the advice a lawyer would give them (which I hope they have consulted because this is all extremely serious and delicate stuff). Their latest apology is in the email that was quoted in the latest news story about this.

Transformers Collectors' Club wrote:As we continue to work on our systems, you will see some of our services go offline and then come back, so please be patient as we preserve data and clone servers and websites.

We are also taking this opportunity to remove all non-essential services from our ecomerce server. So in the short term in the next day or so, the club forums will be discontinued. It will be several days until we are ready to bring them back under an entierly new piece of software. I know alot of you have been asking for this so, we have decided to replace several of our systems with new packages. This means that you will not have access to the forum for a while at all. We do plan to make the old forum viewable (no posts) in the future.

Since we do not know exactly what data was taken, we are recommending that if your have used common logins or passwords with our system and any other system that your change your passwords in those systems immidiately (especially any financial sysstems)! We will be resetting all of the passwords in our system very soon. Please don't delay in changing your passwords in other locations.

In addition, we have found a few recent aticles concerning security issues with other vendors. If you use these services, these issues could possibly impact you. Please read the attached links:

http://www.huffingtonpost.com/2012/02/1 ... 68593.html?

http://www.greenpois0n.co/itunes-accoun ... redit.html

Thanks for your support in this difficult time. We will continue to work with our vendors to correct the issues and we apologize for any inconvenience this has caused any of our members.

Brian Savage
Re: Another TF Club / Fun Pub Security Update - cancel your card numbers and change your passwords! (view post)
Comment by mattwhite924 Feb 29, 2012
They didn't encrypt the passwords!? Who the heck is running that site, a 4 year-old?

There is absolutely NO excuse for not encrypting passwords.
Re: Another TF Club / Fun Pub Security Update - cancel your card numbers and change your passwords! (view post)
Comment by DevastaTTor Feb 29, 2012
Jeez, what's next?!? I guess tomorrow they'll be telling us all to change our names and enter the witness relocation program!
Re: Another TF Club / Fun Pub Security Update - cancel your card numbers and change your passwords! (view post)
Comment by Naked Magnus Feb 29, 2012
mattwhite924 wrote:They didn't encrypt the passwords!? Who the heck is running that site, a 4 year-old?

There is absolutely NO excuse for not encrypting passwords.

That is correct. I am a professional software developer and have a masters degree in computer science. The entire site is built like sites were literally 10 years ago. Either they do not want to invest the money to modernize or their own in-house developers are seriously behind the times. Their software is a complete hackjob by todays standards. Nobody uses Cold Fusion anymore. I used to, but that was in 2002.

I haven't done shopping cart sites in a long time, but I can't help but think there are off-the-shelf products out there that could easily be customized in a short period of time to replace this legacy piece of garbage.

It isn't hard to encrypt passwords. Either they are too lazy or their developers are compete idiots. It is completely trivial now'adays to encrypt passwords. Probably writing a migration script to encrypt the existing passwords is beyond their technical capabilities.

Seriously, we need to stop putting up with this crap. Another option for them is to outsource the online store to an entity that knows what it is doing.
Re: Another TF Club / Fun Pub Security Update - cancel your card numbers and change your passwords! (view post)
Comment by funeralthirst7 Feb 29, 2012
Using pictures of Swindle to accompany the article is great touch.
Re: Another TF Club / Fun Pub Security Update - cancel your card numbers and change your passwords! (view post)
Comment by Stormrider Feb 29, 2012
What has me must concerned is our personal information being taken. Name, address, etc. That's how my identity got stolen.
Re: Another TF Club / Fun Pub Security Update - cancel your card numbers and change your passwords! (view post)
Comment by shin_hibiki Feb 29, 2012
Highlighting the failures of other websites is a distraction and doesn't take away from your own flop. I'm sure anybody who got hit at iTunes is aware of it already.
Re: Another TF Club / Fun Pub Security Update - cancel your card numbers and change your passwords! (view post)
Comment by bvzxa Mar 1, 2012
Naked Magnus wrote:
mattwhite924 wrote:They didn't encrypt the passwords!? Who the heck is running that site, a 4 year-old?

There is absolutely NO excuse for not encrypting passwords.

That is correct. I am a professional software developer and have a masters degree in computer science. The entire site is built like sites were literally 10 years ago. Either they do not want to invest the money to modernize or their own in-house developers are seriously behind the times. Their software is a complete hackjob by todays standards. Nobody uses Cold Fusion anymore. I used to, but that was in 2002.

I haven't done shopping cart sites in a long time, but I can't help but think there are off-the-shelf products out there that could easily be customized in a short period of time to replace this legacy piece of garbage.

It isn't hard to encrypt passwords. Either they are too lazy or their developers are compete idiots. It is completely trivial now'adays to encrypt passwords. Probably writing a migration script to encrypt the existing passwords is beyond their technical capabilities.

Seriously, we need to stop putting up with this crap. Another option for them is to outsource the online store to an entity that knows what it is doing.


I have a degree in Network Security and management and I see so much is wrong with how the website was setup. I know that letting an outside company handle commerce can get expensive if you aren't making alot of sales to support the cost.

What I see is just a lack of security and thinking. They thought no one would hack them, which of course is foolish thinking. For some reason the way the ordering page was setup, it felt like I was ordering from a company back in the late 90's.

As far as them accepting full responsibility, they can't. technically because the breach is well known, and has caused problems for people they are on the hook. However FunPub is no Sony, this hack job could ruin them and probably for good. I just better get what I paid for before that happens.
Re: Another TF Club / Fun Pub Security Update - cancel your card numbers and change your passwords! (view post)
Comment by G1 Legacy Mar 1, 2012
:twisted: It's times like this when I wish we really did have Optimus Prime around to help us out occasionally. How awsome would it be to have 'ol Optimus pull up in Brian Savages driveway at midnight....clear his airbrakes line (pchooooooooooooo) blow his airhorn pissing off the neighborhood dogs (both inside and outdoors) for miles and setting off a car alarm or two as well, then Transforming and walking to the door just as Savage stumbles to it himself to see what all the comotion is about....just in time to see Prime leaning down on bended knee and simply proceeding to chastize him like a 7 year old child..."Do we have a problem with responsibilty Mr. Savage?"

Oh, how cool would that be? ;)^
Re: Another TF Club / Fun Pub Security Update - cancel your card numbers and change your passwords! (view post)
Comment by Banjo-Tron Mar 1, 2012
Wow, I knew the website looked old-fashioned but I really thought that at least the backend would be secure. :BANG_HEAD: Pre-dotcom bubble sites were more modern and secure than this one. This is the ultimate betrayal of trust, pure and simple. :-x

I will only forgive FunPub if they send me a free Punch/Counterpunch, with FREE shipping. (I'm only semi-joking about that)
Re: Another TF Club / Fun Pub Security Update - cancel your card numbers and change your passwords! (view post)
Comment by Autobot032 Mar 1, 2012
If you don't know business, don't run one. It's as simple as that.

I'm not trying to be mean, I'm really not, but I mean this is their umpteenth problem and it's costing people a LOT of money.

The CC companies must be losing dough with all the canceled charges, cards, etc. TFCC is lucky the companies don't file against them. They probably could.
Re: Another TF Club / Fun Pub Security Update - cancel your card numbers and change your passwords! (view post)
Comment by jbliss Mar 1, 2012
Naked Magnus wrote:Nobody uses Cold Fusion anymore.


Just 778,000 of us and growing. http://wwwimages.adobe.com/www.adobe.co ... st-kit.pdf
Re: Another TF Club / Fun Pub Security Update - cancel your card numbers and change your passwords! (view post)
Comment by Andrius Mar 1, 2012
Just got fraudulent charges today. Closed my CC account. Keep checking, guys.

On a related note, I'm still waiting for my exclusives to ship... Insult to injury and all that.
Re: Another TF Club / Fun Pub Security Update - cancel your card numbers and change your passwords! (view post)
Comment by mattwhite924 Mar 1, 2012
I got a new debt card number today. Time to go change my accounts to use it before they try to charge anything to the old number.

At this point I wish I wouldn't have joined the Transformers Club, no toy is worth this kind of crap.
Re: Another TF Club / Fun Pub Security Update - cancel your card numbers and change your passwords! (view post)
Comment by Kibble Mar 1, 2012
Andrius wrote:Just got fraudulent charges today. Closed my CC account. Keep checking, guys.

On a related note, I'm still waiting for my exclusives to ship... Insult to injury and all that.

Don't keep checking...cancel your cards NOW!
Patreon
Charge Our Energon Reserves. Join the Seibertron Elite.
Support SEIBERTRON™