You're receiving this email because of your relationship with Web Hosting Talk. Please add webhostingtalk@newsletter.myinet.com to your Safe List in order to continue receiving our emails.

       

April 14th, 2009   

Hello fellow WHTers!

An insecure event can instill peace.

Dennis Johnson (aka SoftWareRevue)

I don't have a problem admitting that the events on WebHostingTalk.com over the past few weeks have been hard on me, emotionally and physically. But I see so much good that's come out of it, it's easy to focus on that.

We (the WHT community) have had a hard lesson in backups, PCI compliance, and security in general. To me, the fact that WebHostingTalk.com was affected is secondary to the extraordinary message that was sent. "We need to remain vigilant to remain free." I am confident that WebHostingTalk.com is secure.

In our continuing pursuit of disseminating information, I'm going to include iNET Interactive's President and CEO, Troy Augustine's post to the community made on April 9, 2009.

=======================================================

Status of credit card data breach

While Dennis has been keeping all of you up-to-date, there has been a team of seven iNET staff members working on the issue to try to minimize the impact to you, our valued members and advertisers. Here's a quick overview of what's going on behind the scenes. Keep in mind that this is a fluid situation. I am sharing the facts as I know them right now.

Once we became aware that credit card data had been breached, we have been following Visa's guidelines for addressing data breaches. Servers were shut down to preserve evidence, and we assessed the number of credit cards impacted by the data breach. Our merchant bank was notified. The credit card brands (Visa, Mastercard, etc) were notified. Further, we have taken proactive steps to directly notify those individuals impacted or potentially impacted.

As previously described, we believe the scope of the breach is a billing system accessed externally at http://my.inetinteractive.com/. The system was built in the 2004 timeframe, and it was in the process of being phased out. At one point, it processed all transactions associated with WHT. In 2006, premium memberships were transitioned to a new system. In late 2007, display advertising was transitioned to a new system. The only remaining functionality was the payment processing of self-service sticky post purchases. As already reported, 318 active credit cards were compromised. The database server in which this data was contained also stored about 7,300 additional credit card numbers. While we don't have any evidence that this data was compromised, we are proactively notifying those card holders that the possibility exists.

In order to prevent this situation from happening again, we have removed credit card storage and processing from my.iNETinteractive.com. Future self-service sticky post purchases will be processed via Paypal. Any stored credit card data has been deleted.

We are working with our merchant bank to hire a PCI-certified outside consultant to complete forensic analysis of the incident as well as a PCI compliance audit. We will be implementing any recommendations that come out of the audit.

Dennis is part of our daily status meetings. He has the full support of the iNET team, and he will continue to keep you up-to-date and answer questions we are able to answer.

Once again, we sincerely regret the compromise of your data. We are working hard to minimize the impact to you, and we are working hard to ensure any weaknesses in our systems are addressed.

=======================================================

You can always get the latest in news and happenings by visiting our Forum Announcements, Feedback, and Questions forum.

Don't forget to follow us on Twitter @WebHostingTalk for fast breaking updates.

What has happened is bad. What has been learned is priceless.

I wasn't going to mention Lovey Dovey (the bird), but some people have asked. And there are some parallels. It's been 5 weeks since the dove flew into our window. She likely could have been gone by now, but through our caring for her, she lost some tail feathers. We think her broken wing has healed. But her tail feathers still have a few weeks to go before they're ready. The point is, we assumed responsibility for her care when she was first knocked out. While cleaning her cage she escaped in our basement. When we got her back into the cage we noticed she'd lost her tail feathers in the incident. So we implemented a more secure system for when we're cage cleaning. It doesn't matter so much that we may have impeded her recovery. What matters is that we're diligent in seeing her recovery through. A mistake happened. We learned how to make her environment better. We move on. I'll surely update you when she flies away!

Thanks for listening. And, see you on the forums!

Dennis Johnson (aka SoftWareRevue)
iNET Community Coordinator

Got suggestions? Send me an e-email:
suggestions@webhostingtalk.com


Hot threads in the community

  Ever had your site attacked? evilc0d3r enlists member's help for a A very powerful ddos attack,help plz in our Technical & Security Issues forum.

  Just starting out? Then you might be interested in reading MH-Andy's thread, How long did it take till you break even?, in our Running a Web Hosting Business forum.

  What is cloud computing? If you've asked yourself that question, then HP-Kevin's thread of the same name is the place for you. You'll find this discussion and more in our Cloud computing forum.

  Our Green Hosting forum features a thread started by andrew_t that asks the question, How do you go 'Green'?. A good read if you're considering going green.

  Have you wondered What percentage of your new customers do renew their accounts after 1 year? The question is asked by kishforums in our Reseller Hosting Forum.

This is a small sampling of great discussions going on now at WebHostingTalk.com. We can't possibly fit them all in this newsletter, so get in there and get involved!


WHT Premium Memberships Sign up for a WHT Premium Membership and get a free subscription to Search Marketing Standard magazine

A Lifeboat for Turbulent Economic Waters

Times may be tough financially, but that's no reason to jump ship! Web Hosting Talk is here to help out. WHT Premium Memberships can help you get more out of your marketing budget and efforts with a FREE subscription to Search Marketing Standard magazine ($29.95 value) AND a 15% match on HostingCatalog.com advertising!

In addition to the above benefits, be distinct and enhance your forum experience with:
  • Privileged Access to the Premium Member Forums
  • Unique Member Badge and Username Color - Stand Out!
  • Reduced Wait Time Between Posts and Searches
  • Gigantic Private Inbox
Sign up for a WHT Premium Membership and get a free subscription to Search Marketing Standard magazine

Web Hosting Wiki Spotlight

Backups

There are many reasons to have good backups: Hard drives fail, system administrators make mistakes, users accidentally delete files, hackers break into systems and cause damage, et cetera. There are hundreds of ways to create backups, and it's often difficult to compare different backup systems without actually trying them out. However, backup systems can generally be summarized according to the following qualitative characteristics:

  1. Incrementality
  2. Granuality
  3. Encryption
  4. Service

Read the rest of Backups.

See WHTwiki's featured article list.

There are over 200 community-authored articles about the web hosting industry in the Web Hosting Talk community wiki. Lend your experience and expertise in the wiki today!


Get to know the Community

bear bear
Community Leader
Member since 10/5/2002
View profile
Forum Posts: 9,267
Wiki Activity: 0

In this issue...

An insecure event can instill peace.

A lifeboat for turbulent economic waters.



Follow WHT on

Follow WHT on LinkedIn
Follow WHT on Twitter @ http://twitter.com/WebHostingTalk

Spread the Word!

Do you know someone who might be interested in receiving this newsletter?
Forward this newsletter

Did you miss an issue of the Insider?

Don't worry.
Visit our Newsletter Archive section of WHT for past issues of the Insider.
View the newsletter archive to get past issues

WHT Quick Links

Web Hosting Discussion

Web Hosting Wiki

Web Hosting Providers

Industry News

RSS Feeds

Web Hosting Talk offers several newsletter options to suit your needs.
Subscribe to all of our newsletters to get the most from your experience at WHT.