Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie

Airtricity Data Breach

Options

Comments

  • Posts: 0 [Deleted User]


    It's terrifying when you realize just how vulnerable everything is online! Remember when the boards.ie database got hacked? That caused havok! Thankfully they probably wouldn't have stolen things like financial records, but it still is eye-opening!


  • Registered Users Posts: 7,265 ✭✭✭RangeR


    Airtricity takes the security of customer information and our obligations to protect it very seriously
    I laugh at companies who say this AND put live customer database on the internet.

    And no, it's not the first time. It's also not the second time, either. Airtricity seem to have a data breach every year or two. I left them soon after the first [that I'm aware of] breach. They couldn't answer my questions as to why un-encrypted text file containing customer details were sitting on their webserver.

    Once is an an accident. Twice is an oopsie daisy. THREE times is gross negligence and DPC should come down VERY hard.


  • Closed Accounts Posts: 129 ✭✭Galia


    or they should use someone other than http://www.oracle.com/ie/index.html


  • Registered Users Posts: 7,265 ✭✭✭RangeR


    I don't blame Oracle. Oracle didn't put a production database on a webserver. Databases should NEVER be put on a webserver. That was a bad [negligent?] design choice on Airtricity's part. DB should ALWAYS be on the LAN with something like sanatised web services as the middle man between data and website.

    The first one was pure incompetence. Placing a non encrypted text file with customer data [this was during a sign up drive] on a public facing web server. Again, negligent. How many **** ups must a company have before they even get a slap on the wrist?


  • Registered Users Posts: 742 ✭✭✭goose06


    RangeR wrote: »
    The first one was pure incompetence. Placing a non encrypted text file with customer data [this was during a sign up drive] on a public facing web server. Again, negligent. How many **** ups must a company have before they even get a slap on the wrist?

    Judging by the lack of media coverage I'd be surprised if anything is done about it all.


  • Advertisement
Advertisement