The Official Forum  

Go Back   The Official Forum > Basketball
Register FAQ Community Calendar Today's Posts Search

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
  #1 (permalink)  
Old Thu Jan 08, 2015, 10:00pm
Official Forum Member
 
Join Date: Nov 2002
Posts: 15,015
Thumbs down ArbiterPay Security Flaw

This has now happened to me twice and I wanted to let as many of my fellow officials now about this so that you may take steps to protect yourself from possible theft.

I sent the email below as a response to ArbiterPay upon receiving the email generated by their system.

If/when I hear back from the people at ArbiterPay, I will update this thread.


==================================================
To Whom It May Concern with the ArbiterPay Support Team:

I need to bring a programming issue to your immediate attention on behalf of all of your customers.

I called and spoke with a customer service representative during the Fall of 2014 about this issue and it still has not been fixed. The problem is that when an individual changes his/her password, your system generates an automated email notifying the person of the change AND INCLUDES THE NEW PASSWORD!

Obviously, email is NOT secure and this process presents a serious breach in the security of your payment system. Any cyber-criminal who hacks into an individual's email account could obtain the login & password information for an official and then transfer any funds in his/her ArbiterPay account to themselves. This would leave the person who earned the money without pay.

Below is a copy of the email which I received today from your system with my personal password redacted as I do not wish to perpetuate the error of your system.

I ask that you immediately have someone from your programming team correct this issue such that the notification of change emails which are sent out no longer include this information. Please contact me to confirm that you received this email and will be correcting the issue.

(My real name)


> Date: Thu, 8 Jan 2015 20:43:55 -0500
> Subject: Modified login details for ArbiterPay
> To: (my email was here)
> From: [email protected]
>
> Your login details have been modified. Contact us immediately at [email protected] if you did not initiate this change.
>
> Username: (my email was here)
> Password: [my new password was listed here]
>
> Regards,
>
> ArbiterPay Support Team
>
>
Reply With Quote
  #2 (permalink)  
Old Thu Jan 08, 2015, 11:35pm
Administrator
 
Join Date: Sep 1999
Location: Toledo, Ohio, U.S.A.
Posts: 8,124
Quote:
Originally Posted by Nevadaref View Post
This has now happened to me twice and I wanted to let as many of my fellow officials now about this so that you may take steps to protect yourself from possible theft.

I sent the email below as a response to ArbiterPay upon receiving the email generated by their system.

If/when I hear back from the people at ArbiterPay, I will update this thread.


==================================================
To Whom It May Concern with the ArbiterPay Support Team:

I need to bring a programming issue to your immediate attention on behalf of all of your customers.

I called and spoke with a customer service representative during the Fall of 2014 about this issue and it still has not been fixed. The problem is that when an individual changes his/her password, your system generates an automated email notifying the person of the change AND INCLUDES THE NEW PASSWORD!

Obviously, email is NOT secure and this process presents a serious breach in the security of your payment system. Any cyber-criminal who hacks into an individual's email account could obtain the login & password information for an official and then transfer any funds in his/her ArbiterPay account to themselves. This would leave the person who earned the money without pay.

Below is a copy of the email which I received today from your system with my personal password redacted as I do not wish to perpetuate the error of your system.

I ask that you immediately have someone from your programming team correct this issue such that the notification of change emails which are sent out no longer include this information. Please contact me to confirm that you received this email and will be correcting the issue.

(My real name)


> Date: Thu, 8 Jan 2015 20:43:55 -0500
> Subject: Modified login details for ArbiterPay
> To: (my email was here)
> From: [email protected]
>
> Your login details have been modified. Contact us immediately at [email protected] if you did not initiate this change.
>
> Username: (my email was here)
> Password: [my new password was listed here]
>
> Regards,
>
> ArbiterPay Support Team
>
>


Nevada:

I understand the seriousness of your post because Mark, Jr., and I have JrHSs and HSs in Michigan that use RefPay for the JrHS and HS sports we officiate in that state up North, and Mark, Jr., will receive his college softball fees through RefPay.

But you leaving your personal information in the email above reminded my of that great Mel Brooks movie, Blazing Saddles. Therefore:

Hedly Lamarr: "State after me: I, state your name."

Criminals and Scroundrals: "I, state your name."

Time for me to go to bed now. Night all.

MTD, Sr.
__________________
Mark T. DeNucci, Sr.
Trumbull Co. (Warren, Ohio) Bkb. Off. Assn.
Wood Co. (Bowling Green, Ohio) Bkb. Off. Assn.
Ohio Assn. of Basketball Officials
International Assn. of Approved Bkb. Officials
Ohio High School Athletic Association
Toledo, Ohio
Reply With Quote
  #3 (permalink)  
Old Fri Jan 09, 2015, 12:47am
Official Forum Member
 
Join Date: Oct 2007
Posts: 785
If they can include the password in the e-mail, that means they are also storing it in plain text. Another no-no.
Reply With Quote
  #4 (permalink)  
Old Fri Jan 09, 2015, 02:15am
Archaic Power Monger
 
Join Date: Mar 2007
Location: Houston, TX
Posts: 5,983
Quote:
Originally Posted by Altor View Post
If they can include the password in the e-mail, that means they are also storing it in plain text. Another no-no.
This. That's a pretty serious issue that needs to be rectified immediately.
__________________
Even if you’re on the right track, you’ll get run over if you just sit there. - Will Rogers
Reply With Quote
  #5 (permalink)  
Old Fri Jan 09, 2015, 07:59am
Official Forum Member
 
Join Date: Oct 2014
Location: FL
Posts: 169
Nevada,

Thank you for sharing. That is not an acceptable security level. I have sent an email as well.
Reply With Quote
  #6 (permalink)  
Old Fri Jan 09, 2015, 09:17am
Official Forum Member
 
Join Date: Oct 2007
Posts: 785
Just checking on other things Arbiter. I went to https://nfhs.arbitersports.com and clicked the "forgot password" link. That took me to a site that looks like it is a single authentication point for all Arbiter sites. I typed my address in the box. They sent me my current password!

It's not just ArbiterPay. If you have an Arbiter account of any kind, this affects you.

If you are one of those people that has the same password everywhere, I suggest you change it everywhere. And when you change your Arbiter password, use a different password.

Even better: Don't use the same password twice. Instead use a password database like KeePass or LastPass.

Last edited by Altor; Fri Jan 09, 2015 at 09:19am.
Reply With Quote
  #7 (permalink)  
Old Fri Apr 10, 2015, 04:47pm
Official Forum Member
 
Join Date: Jan 2015
Posts: 40
Quote:
Originally Posted by Nevadaref View Post
This has now happened to me twice and I wanted to let as many of my fellow officials now about this so that you may take steps to protect yourself from possible theft.

I sent the email below as a response to ArbiterPay upon receiving the email generated by their system.

If/when I hear back from the people at ArbiterPay, I will update this thread.


==================================================
To Whom It May Concern with the ArbiterPay Support Team:

I need to bring a programming issue to your immediate attention on behalf of all of your customers.

I called and spoke with a customer service representative during the Fall of 2014 about this issue and it still has not been fixed. The problem is that when an individual changes his/her password, your system generates an automated email notifying the person of the change AND INCLUDES THE NEW PASSWORD!

Obviously, email is NOT secure and this process presents a serious breach in the security of your payment system. Any cyber-criminal who hacks into an individual's email account could obtain the login & password information for an official and then transfer any funds in his/her ArbiterPay account to themselves. This would leave the person who earned the money without pay.

Below is a copy of the email which I received today from your system with my personal password redacted as I do not wish to perpetuate the error of your system.

I ask that you immediately have someone from your programming team correct this issue such that the notification of change emails which are sent out no longer include this information. Please contact me to confirm that you received this email and will be correcting the issue.

(My real name)


> Date: Thu, 8 Jan 2015 20:43:55 -0500
> Subject: Modified login details for ArbiterPay
> To: (my email was here)
> From: [email protected]
>
> Your login details have been modified. Contact us immediately at [email protected] if you did not initiate this change.
>
> Username: (my email was here)
> Password: [my new password was listed here]
>
> Regards,
>
> ArbiterPay Support Team
>
>

Um, this is unacceptable in the IT/Finance world. Major, major no no. Passwords are NEVER to be sent via email.
Reply With Quote
  #8 (permalink)  
Old Sat Apr 11, 2015, 11:23pm
Official Forum Member
 
Join Date: Mar 2004
Posts: 2,193
Quote:
I was told there wouldn't be any math.
I was told there was going to be refreshments served!

Now, wait a minute: what does encryption mean?? (J/K)

Reminds me a little of law school. During our Estates and Trusts class, there was some math to figure out who inherits what. One of the guys in my class had a math PhD from a previous life and offered to tutor anyone who didn't understand the math involved. I told him I would help (decent math background, but no math degree), and we spent a good afternoon going over this stuff with about 15 people. I think about 8 actually got it.

Last edited by Texas Aggie; Sat Apr 11, 2015 at 11:27pm.
Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Flaw in rules? largeone59 Football 17 Sun Jan 15, 2006 09:28pm
Flaw in new loss of down rule! ljudge Football 12 Tue Sep 06, 2005 02:21pm


All times are GMT -5. The time now is 03:44am.



Search Engine Friendly URLs by vBSEO 3.3.0 RC1