![]() |
Epassporte now too. WTF!
Ok I think it is becoming more obvious that someone is really trying to break into my accounts. I have had a few password reminder emails from sponsors over the past week.
Now I get sent an email from epassporte that is the following. Dear David, Thank You for your email. In regards to your concern, please be informed that we have removed your security question and reset your password and you can view it along with your user ID addressed to you in your external email address which you registered with ePassporte. I hope this has answered your query. If you have any further concerns, please do not hesitate to contact our Customer Service from the details listed below. Best Regards, Kushal.C ePassporte Account Holder Services [email protected] Fax: +1.310.564.1751 Phone: +1.310.301.2001 ----- guess this is the mail they are quoting--------- > Some one change my Security Questions and my password pllease help me as > soon as possible and i will attach u all my docs Then of course I get mailed a new password in a separate mail. I am not an idiot and there was no links to even click aside from mail to: ones anyways. So I head over to epassporte in a new browser window and yes indeed my old password no longer works. When I do get inside, yup all of my previous extra opt in security questions and image etc has been reset. Seriously WTF is the point of this added layer of security if someone can get it reset via an email and obviously a spoofed email at that. Only thing I am even glad of is that it seems the client support at epassporte at least do not hit the reply to button on the email and did send to the proper email on file. I have sent in a request asking for the headers of the email. Also left Michael a message too. |
That's just scary.
|
not good
|
PS when they reset your password it goes to a letter and a few numbers. Better than a random word but still fairly fucking stupid.
Still trying to wrap head around why they would just reset shit from an email though. I need to send them DNA data to get a withdraw increase yet some ass clown can get them to reset all of my data with a fake email. |
Your gonna get anally raped
|
please send $10 000 from your epass account to my epass account to make sure that its still working properly
|
Quote:
Just wish whoever decided to target me would pick another fucking target. It is getting annoying as hell. |
That would be fucking annoying. Glad they didnt get access to your account ASM.
|
Quote:
An email should not be able to get a password and all security questions reset. If so what is the point of having security questions in the first place. This extra layer of security they added was due to hacked accounts, and seeing how easy it is to bypass is just fucking wrong. |
that's not good
|
:mad::mad::mad:
|
Quote:
|
not good, not good at all :( :(
|
Ouch.... any words from epass?
|
And then people are suprised when i say how epassporte still have bad security.
|
It seems that they don't even try to help for real, huh?
|
Quote:
|
ASM
I am emailing you now. |
that's fucked up
|
: / ...
|
damn, scary shit :(
|
So basically you're saying their security measures WORK and that they have effect.
They emailed the email address they had on file(instead of just replying) to make sure you actually were the one that requested the change and if not, you had a chance to intervene. SO WHY FUCKING COMPLAIN? |
It amazes me that people continue to risk their income with this company...how many 100's of threads have we all seen like this about epass?..its a daily occurrence and these are just the situations we DO hear about.
Michael O deserves kudos for his customer service skills and in my opinion is the only reason epass has survived to date, that being said there will come a day when this company is going to crash and burn, they are going to take a lot of people with them and Michael O won't be able to save anyones day... |
So much for secure accounts :2 cents:
or should I say a secure system..... |
Quote:
They only happened to email me to let me know they had followed "my" request, which by that time it was to late to intervene. If I had not been up around when it happened it only was now secure by a few numbers and a letter. Though I am currently dealing with Michael as per the emails. He is waiting for some details, yet says protocol would of required a phone call and answering 4-6 security questions. Which I find very hard to believe really happened at this point, however I am not saying it is impossible at this moment. Though I will say epassporte has more information about me than nearly all other sponsors out there combined. So if they really did ask some questions it better have been some serious ones from documents that they had made special requests for. Oddly the quoted email also does not mention a phone call at all though either. |
Quote:
|
Thats fucked
|
I'd be happy to see a policy change for this.
My question is, since they obviously know your email - do they have access to it? That's why I like not using any free email hosts for anything that needs some sense of security. |
Quote:
Technically if I did not use a public mail, my ISP mail would be just as easy if not easier to crack since it is web accessable as well. Servers would just as likely stand same chance of them being gotten into. Really see no extra security in using any other mail type. |
Quote:
|
Quote:
Why they go "personal" with AMP is the case that someone got his personal information from somewhere, along with documents (or can forge them in a good manner) and they are trying to cash in on that (they mention in the email they would send the proper docs). So they got your personal info (name, address, phone etc etc) from somewhere. |
Quote:
|
Quote:
I am almost 100% certain that my personal information was not used to access the account. Aside from epassporte who demands your personal information and documents, sponsors for instance just have company name, tax id number, and such. If a company just relies on simple personal data (name, address, phone) then they have serious problems anyways. Every content provider would already be compromised in that instance due to 2257 (phone aside). Yet hell that still would be common whois information if one did not keep domains private. So again unless they left shit out of the email and email quote. I do not see a request for a phone call, or a in reference to our phone call your info has been reset. Nor do I see a we received your documents, or after reviewing your documents we reset your information. The email is pretty cut and dry - please help - ok your reset. |
You are too suspicious!
|
Quote:
|
that's pretty shitty :(
|
Quote:
Highly unlikely, but it's also unlikely that I'm going to let Vietfraud send me joins on stolen cards because they use the name "Joseph Smith" for their affiliate account. :thumbsup |
Quote:
Quote:
|
Quote:
|
Quote:
I get a copy of an email I did not send requesting a full reset which was granted and I am being to suspicious? |
Quote:
|
Quote:
Though I am still waiting on what Michael comes up with assuming full protocol was indeed used. Which would mean they would need to be able to answer as he put it 4-6 security questions. I know my previous and now new questions on epassporte are not questions used elsewhere. I am pretty careful about not repeating those things. Which leaves info epass could have to ask about, which could be DL #, last 4 of some of the load cards, maybe middle name from ID, so forth. I just do not have that info sitting with other sponsors or such where it could get shared. Exceptions being middle name maybe, address, phone number. I do not use middle name anywhere really but I am sure it can be found online. Of course I have also checked and constantly check my computer for key loggers, virus, spy ware, etc. |
Quote:
|
Quote:
Here's one scenario from the top of my head. You run a porn site. They hack in there, get your personal info from the database, maybe even personal pictures and shit if you keep it on server (many people keep personal things), find out your epass username, and the game begins... You can be sure they have something, what, i dont know, but they have some info that they were gona use to persuade epass to send them the new login (after it got reset). |
Quote:
As for your scenario, again highly unlikely. I know what info I have outside and what I do not. For instance aside from maybe 5-10 pictures on Fubar that have me in them, or silly fucking general pictures of crap, I do not keep anything online. Hell I do not even email friend and family pictures. Databases should just contain business info which is different than what epass has. I really am leaning more towards it just being pure human error with client services and the proper protocols were not followed, but we shall see. Even if I have to eat crow and say yes indeed something was compromised of mine and what it was I will keep this updated as I feel it could effect others and is the only reason I am doing this thread along with private communications with epassporte. If it can happen to someone who is as careful about security as I am, then it is very important to find out the how's and whys as I know many if not most people are not as tight with their security. |
I was under the impression that the only way you can contact epassporte support is through their message center after you log in. If this is really the case, then they should know which member sent them that email?
|
Quote:
|
Quote:
Or if you are an affiliate of someone, in those databases you usually put your name, surname, address, birthdate, ip, email ..... They might be trying with that aswell. |
Quote:
In those I put my company name - for payouts etc. Yes my address, and email (see above) and birthdays are not to damn hard to find out publicly again. I still am leaning to the most obvious and likely reason, well ahead of any super strange and even harder to explain could of been reasons. After all perhaps I taunted the wrong person in some supernatural thread and they indeed are psychic or a ghost did tell them the answers. May as well go there too, instead of first thinking it was just human error at client support? Though feel free to keep posting the what if's and could of been's. According to epassporte I should have some answers by Monday and we will see who was right or where to go from there. |
Quote:
It's human error. |
All times are GMT -7. The time now is 08:15 AM. |
Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123