Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It looks like their customer service ticketing system is wide open too:

http://www.google.com/search?q=www.clkbank.com/viewTicket.ht...



First relevant result refers to the fact that customer's info is available for public viewing.

https://www.clkbank.com/viewTicket.htm?key=01.2C096591B7E11E...


And this customer support ticket shows a customer complaining about the fact that their order information is visible on the internet. This was back in 2011.

ClickBank has to have known about this hole for years and hasn't addressed it.

https://www.clkbank.com/viewTicket.htm?key=01.2C096591B7E11E...


Hello Sandy,

ClickBank.com is a secure site. The only way someone would be able to look up your order, which does not show any payment detail except your Credit Card type and last 4 digits on the card, is to know the exact order number and email address.

Closing this ticket, because new tickets for each order, requesting a vendor authorization for refunds have been opened. These orders are 116 days old and ClickBank.com is not able to issue a refund for order over 60 days old.

Best regards,

Jutta ClickBank.com Customer Support http://www.clickbank.com/help/


Can only hazard a guess that this must be some bizarre form of SEO or something, because this is a known issue that could be fixed in probably 30 minutes max, which they have received complaints for...


"ClickBank.com is a secure site. The only way someone would be able to look up your order, which does not show any payment detail except your Credit Card type and last 4 digits on the card, is to know the exact order number and email address."

Strange, because the link in the ticket to the order still works and is viewable without any of that information.


What a total breach of customer privacy. I can't imagine customers want it to be searchable that they purchased a "Customized Fat Loss Program"

https://www.clkbank.com/viewTicket.htm?key=01.71E027164BE509...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: