Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Clickbank order details in plain view (google.com)
111 points by Auserget on June 19, 2013 | hide | past | favorite | 76 comments


Hi, this is Matt Hulett the CEO of ClickBank.

ClickBank was recently made aware of a situation in which customers were posting their information using social bookmarking sites, which are indexed by Google. As a result, ClickBank is taking steps to limit the information that a consumer can inadvertently share through such services. We take customer privacy very seriously and believe that all individuals share responsibility for maintaining the security of personal information that is posted online. At no time is customer payment information disclosed.


Thanks, Matt... But it's pretty evident from your customer support tickets that your customers were alerting you to this issue (and their privacy concerns) since at least 2011... But you've clearly done nothing to fix it since then.

It's hard to believe you take customer privacy very seriously when you've made evidence to the contrary so easily searchable in Google.


How was customer payment information NOT disclosed?! It is on Google!! The URLs should be protected by authentication! It should be impossible for Google or anyone else to access it without a login. It does not matter that some customers shared it on social sites. Saying there is no problem if the social sharing doesn't occur is security through obscurity.


I've been through this before. Online receipts identified with long, random URLs. Users posting them online with no regard for security. Requiring a login for purchase was deemed infeasible since it adds friction to the checkout process. The only thing keeping the online receipt from google was robots.txt.


Except there are neither long URLs nor unindexed (no meta tags, no nothing!)


"...believe that all individuals share responsibility for maintaining the security of personal information that is posted online."

You (CLICKBANK) posted this information online--not your customers. Are you seriously trying to blame them for the fact that your development team seems to have no concern for security and privacy?


I'm puzzled. How is taking customer privacy seriously compatible with leaving private information indexable, let alone accessible through unrestricted urls?


Direct search link: https://www.google.com/search?q=site%3Aclkbank.com%2ForderDe...

Well, this is pretty egregious and makes me rather happy I don't use them. From the looks of things you can also change the email associated with an order and send yourself the info all over again. This means for some things, like online services or say application licenses, you can resend the info to yourself and probably steal the actual customers product.

Additionally, I'm willing to bet quite a few of these people have used the listed email and last 4 for other things online and/or for verification of identify places.

Also, how is this PCI compliant?


There's no payment card information besides what's acceptable to show (last four and card type). Full name and email address is PII, but not necessarily in breech of PCI. I don't believe SOX has anything specifically mentioning full name and email PII either. If that's the case, the only thing that would make it a PCI or SOX violation is if the company says in their data privacy policy that they will protect this PII. I work information security but I am not on my company's compliance team, so I'm familiar with PCI/SOX but not steeped in it. I believe the above is true, but I'm not an auditor.

As far as trying to gain a copy of the information in the email, it might be possible if you were willing to put your own email on record as being part of this data breech. It's also possible that the only thing contained in the email is purchase confirmation (aka, what is shown in the printable invoice).


Looks like some of these are showing a customer's physical address too. I sure hope that wouldn't be PCI compliant.

https://www.clkbank.com/orderDetail.htm?rcpt=504d78866YCRFEF... (Click on View Details under Tracking Number)


PCI is designed to protect credit card fraud, not customer's address information. Banks don't care about the risk of identify theft, but rather credit card fraud.


Cardholders name is PCI data. So in most cases the customer?s name and the cardholders name would fall under the auspices of PCIDSS. This is definitely a breach.


Correct. From the DSS, 'Cardholder data includes: Primary Account Number (PAN), Cardholder Name, Expiration Date, Service Code'


This is not true, I used to work in the industry and you can use a hosted credit card solution (where you transfer customers to a secure payment page) without needing PCI compliance.

If it were correct, and the card holder name needed to be secure, the company I worked at would not have received level 1 PCI compliance. The solution sends back the truncated card number, expiry date and the full card holder name.

Of course I'm assuming the banks wouldn't want you to make that data public, but you are allowed to store it without needing to be PCI compliant.

CVV code is another matter, under no circumstances are you allowed to store it, unless you're a level 1 compliant payment processor.


Phew! At least we can all take comfort in the fact that ClickBank is a Level 1 compliant payment processor.

http://www.clickbank.com/press/clickbank-achieves-level-1-pa...


You can also (re)download the super expensive scammy ebooks.

And there is a bit more details in the URL (ZIP code): http://hypnosiscertified.com/nlp/july152010.php?item=18&cbre...


It's not all expensive scammy ebooks, but "most" is probably an accurate assumption. I've actually purchased some useful software from a company using clickbank, but for the most part it's a strange part-pyramid scam type of thing with ebooks that tell you how to make your own part-pyramid scam business.


True, I did one - "Mastering the skill of Blah Blah.."


Does not beat "How to pull your ex (Female version)"


I interviewed for a hedge fund once where my job interview was to write a program that exploited a security flaw like this to make a real time model of what people were paying for diamonds.


Did you get the job?


No. It was a week long, paid interview. After a couple of days I decided not to come back. Mainly because the main project seemed illegal (which I'll admit held some criminal mastermind allure) and I had another job lined up in Japan. In retrospect, I wish I would have done it as the job in Japan was terrible and I've not come across a similar opportunity since.


The NSA has a contractor position open in Honolulu.


I graduated from high school and am pretty good at powerpoint, so I am assuming I am overqualified.


Contact them again?


I don't think they exist anymore.


No worries, it's certified by TRUSTe http://clicktoverify.truste.com/pvr.php?page=validate&url=ww...

edit: not that TRUSTe claims to test this sort of exposure, to my knowledge. But simply to contrast the feeling of trust a label like that gives you, against the reality.


Clickbank is a joke! I remember year ago you could put in Google product name and "thank you" and you would find thank you page with direct download link.

EDIT: Someone even made CB product to protect thank you page: Fix My Thank You Page http://fixmythankyoupage.com/ only $97 LOL!


I guess Google really started taking advantage of "today's digital internet"

> Adding "no follow" tags to your Robots.txt file is a smart step but it's simply not enough on today's digital internet.


On the old analog internet it worked great.


I hate LMGTFY. It's slow and condescending, especially for something like this where slow and condescending don't add anything. Is it not possible to just submit a Google search link? Or use a text-only post?


Looks like a mod has changed it.


Yeah--I think HN blocks Google URLs from being submitted.


Hope no one is clicking on the "Resend Receipt Email" button. Imagine a customer receiving the receipt email for something they bought 3 years ago..


The founder sure knows about technology:

"As a research scientist for the NSA, Dr. Tim Barber was..."


I wonder if their new CFO that started today wants to take back what he said about ClickBank's "strong digital platform."

http://www.prweb.com/releases/2013/6/prweb10846812.htm


What exactly is Clickbank? It looks like a platform to help people resell their knowledge?


Affiliate marketing scumware. Like how to Make $5000/month at home crap. (Spolier Alert: Sell pamplets on Clickbank)


That is what the current marketing sells it as. Basically it is mainly a platform for leads based affiliate marketing with some sales stuff as well. So stuff like generate a credit card lead for $50/$100 down to get an email address for some mailing list for a $1.


That's a charitable interpretation, but sure.


Apart from various ebooks and what not, it seems they also help people sell:

Backup software subscription: https://www.clkbank.com/orderDetail.htm?rcpt=4fb75aa1LPBHFEH...

and ...

Phone lookups (they work?): https://www.clkbank.com/orderDetail.htm?rcpt=514323c6WDJ2F3C...


> Phone lookups (they work?)

Perhaps not?

(https://www.clkbank.com/viewTicket.htm?key=01.BF205EF24EE6D9...)

> Reason: I never received my product.


Wow. People pay a lot of money for snake oil.


I smell a startup!! Quick, to Sand Hill road!


Hard work getting people to pay money for junk, that's why you outsource it to thousands of affiliates on clickbank.


And you can edit the email address without being logged in


That was the first thing I tried too. I expected the window to popup and say something along the lines of "You need to be logged in...". Nope. Insta-update.


Since the vaunted FAA Sec 702 orders are being used for cybersecurity as well as (if not more than) terrorism, look for the FBI at your door with CFAA charges soon.


Are we all violating the Computer Fraud and Abuse Act of 1986 by exploiting this weakness? By following a link?


Does Google pull links from Gmail and attempt to index them? I am wondering how they knew to index these pages with random URLs (the "security through obscurity" employed by ClickBank and defended in the support ticket referenced in the comments here).


I'm fairly certain they do, from experiences in the past where otherwise completely private (but unprotected) URLs have ended up indexed.


If you're browsing with chrome or a browser with the google toolbar urls will be submitted to google automatically.


At least they could have added a meta robots noindex to the page. That would have kept it out of search although not eliminated the security hole.


They took this part of the site down, but you can just open the google cache and all details are there...


Heh, Power4Home System ordered by "I.hate.niggers@microsoft.com" ...

https://www.clkbank.com/orderDetail.htm?rcpt=504d78866YCRFEF...


Why is this racist juvenility the top rated comment in this thread?


I don't think it's funny because it's racist, I think it's funny because it reveals what kind of embarrassing data a security hole like this brings out.


Except anyone can edit the emails, even now.


I had a look at a few of them, and they are mostly scam payments. Like $30 membership for a website where you "get paid to answer surveys".


The problem was that some average developer was lazy and do whatever that worked, with no concern about potential security implications.


No, not lazy. Being lazy would have been doing a simple session check and then redirecting to a login page if the session user id did not match the user id in the order. The developer had no idea what he/she was doing. Brutal.


You have me listening. What would be the correct course of action while not lazy and knowing what you're doing? I know that "knowing what you're doing" and this question doesn't go together, but still anything better than a check/redirect?


It looks like their customer service ticketing system is wide open too:

http://www.google.com/search?q=www.clkbank.com/viewTicket.ht...


First relevant result refers to the fact that customer's info is available for public viewing.

https://www.clkbank.com/viewTicket.htm?key=01.2C096591B7E11E...


And this customer support ticket shows a customer complaining about the fact that their order information is visible on the internet. This was back in 2011.

ClickBank has to have known about this hole for years and hasn't addressed it.

https://www.clkbank.com/viewTicket.htm?key=01.2C096591B7E11E...


Hello Sandy,

ClickBank.com is a secure site. The only way someone would be able to look up your order, which does not show any payment detail except your Credit Card type and last 4 digits on the card, is to know the exact order number and email address.

Closing this ticket, because new tickets for each order, requesting a vendor authorization for refunds have been opened. These orders are 116 days old and ClickBank.com is not able to issue a refund for order over 60 days old.

Best regards,

Jutta ClickBank.com Customer Support http://www.clickbank.com/help/


Can only hazard a guess that this must be some bizarre form of SEO or something, because this is a known issue that could be fixed in probably 30 minutes max, which they have received complaints for...


"ClickBank.com is a secure site. The only way someone would be able to look up your order, which does not show any payment detail except your Credit Card type and last 4 digits on the card, is to know the exact order number and email address."

Strange, because the link in the ticket to the order still works and is viewable without any of that information.


What a total breach of customer privacy. I can't imagine customers want it to be searchable that they purchased a "Customized Fat Loss Program"

https://www.clkbank.com/viewTicket.htm?key=01.71E027164BE509...


Has anyone realized all of this has to do with clkbank.com NOT ClickBank.com

Looks like a fake site all together...


It's pretty common to have multiple domains, especially affiliate marketing websites. ClickBooth has clickboothlnk.com, NeverBlue has many random alphanumeric domains.

This certainly is Clickbank.com


All signs point to the fact that clkbank.com is ClickBank.com. The website, WHOIS as well as the fact that their CEO just chimed in.


We're all going to get rich!


this is horrible! I can even download ebooks (probably there is "Download Now" button for digital products) from certain orders :(


But it has a TRUSTe online privacy certification...


WTF is a .htm file, I'm feeling all nostalgic, I haven't seen one of those in a decade. I wonder what version of CGI those developers are using.

Seriously though, wow! that's really awful.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: