ISP Closes Webmail After Spammers Get Addresses 142
An anonymous reader writes "Error prone British ISP PlusNet, who you might remember for accidentally deleting 700GB of customer's e-mail last year, have done it again with a major security gaffe.
Their webmail service was compromised this week, and spammers got hold of customers' e-mail addresses who they've been happily spamming away ever since. They've since made the decision to close their webmail service, in the ultimate admission of incompetence for the now BT owned ISP.
In an e-mail to their customers, Network director Phil Webb goes on to recommend that their customers install security software, along with telling them that they shouldn't call up to complain. One might suggest that they need to practice what they preach."
Erm ? (Score:3, Funny)
Re:Erm ? (Score:5, Funny)
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Re: (Score:1)
Not surprising (Score:4, Informative)
Re: (Score:2, Informative)
The same Freedom2Surf that were bought by PIPEX? (Score:4, Informative)
PIPEX are looking to be bought out. Maybe by tiscali. [freedom2support.net]
Get a real ISP, like Black Cat Networks [blackcatnetworks.co.uk] or Andrews and Arnold Ltd [aaisp.net]. Alternatively, UKFSN [ukfsn.org] (an Enta.net reseller) are pretty good, if you're tighter around the pocket.
[Captcha: protests]
Captcha (Score:2)
What does that mean? Does Slashdot require some users to pass "captcha" tests before posting?
Re: (Score:3)
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Both have decent news feeds too.
Re: (Score:2)
Re: (Score:2)
It's a shame, because a few years back when I joined them they were an excellent "techie" ISP...but then the binary newsgroups were dropped, next the traffic shaping started (so they could reserve bandwidth for their VoIP
Re: (Score:2)
FWIW, I shifted to Zen when I left Plus a few months ago, with a very similar story to yours. Aside from a few teething troubles getting it set up, most of which turned out to be BT's fault rather than Zen's, the technical service has been fine.
The customer service at Zen is appalling, however. They don't have a 24-hour tech support number, for one thing, so there is no "quiet" time to call. After sitting on hold for 45 minutes during one of those teething troubles, my first question of the technical advi
Couldn't find a UK host, but I sure tried hard. (Score:1, Interesting)
I had a client that *required* a use a host within the UK and I never did manage. It was a nightmare. In the U.S. I use Dreamhost http://www.dreamhost.com/r.cgi?134994 [dreamhost.com] in L.A., Even though I'm in Amsterdam using Drupal which requires much server interaction, I'm very pleased with my subscription for nearly 2 years already. I've seen and heard of simi
Mod parent down (Score:1)
You'd have more credibility if you were pimping out a higher quality host. DH oversells their capacity, and is about average for bargain basement junk. I tried their $10/yr promo a while back to run a small image g2 gallery. I'd say it wasn't worth $10. Their MySQL server was unreliable (lots of downtime), the httpd server I was on was quite slow, and even after canceling the account I get spam from them.
Re: (Score:1)
So in my defense, I claim no scam.
but this is off-topic. I'm sti
Re: (Score:2)
Re: (Score:2)
They are a buch of cowboys, and they make many horrendously stupid security mistakes.
Re: (Score:2)
My isp sucks worse than yours. I have to use hughes net over satellite. The laws of physics demand that I have a min ping time of 500ms.
Re: (Score:1)
Re: (Score:1)
Re:Pipex? I think of the Hoff (Score:1)
THE HOFF - King of the Internet
http://www.youtube.com/watch?v=Jphpzjar2y4 [youtube.com]
Re: (Score:1)
I keep my Demon account open purely because I have used the TAM account for a long, long time and a large number of people know that as my contact email. Recently they wrote to me to say I hadn't paid for
Try Andrews and Arnold (Score:2, Informative)
Re: (Score:2)
No, not surprising at all (Score:2)
I was with Plus for many years, but their service deteriorated dramatically around a year to 18 months ago.
At the time, they made it unreasonably difficult to get a transfer authorisation for my BT line to move to another ADSL ISP, and the rules requiring all ISPs to give transfer authorisations within a reasonable time hadn't yet come into force, so I would have lost connection for probably a month during the move. Since I knew I would be moving house fairly soon, I put up with them until then, when I co
Re: (Score:3, Informative)
Re: (Score:2)
Currently I'm with Tiscali, 5GB is what they actually mean (you get FUP'd here) latency is often 180ms and above and between 16:30 and 23:30 they shut down all
Re: (Score:2)
Now, they're filtering all encrypted traffic to catch the RC4-based torrent encryption to 30KB/s - on an 8Mbs line. They won't even tell people what the limits are, though it's reckoned to be no more than 30-40GB a month.
They al
Re: (Score:2, Informative)
--
Dear Sir or Madam
You may have noticed that we have not fully charged you for your Pipex services to date. This means your account has an outstanding balance of £46.88, which we plan to take payment for through debiting your credit card on or around 25th May 2007.
We're really sorry for this mistake, which was caused by a problem with our internal systems not identifying
Re: (Score:1)
Re: (Score:2)
Most importantly, you can get through to a real techie in about 30 seconds typically if you have a real prob
Re: (Score:2)
Their ratings aren't exactly top either:
thinkbroadband.com - Service Provider Comparison [thinkbroadband.com]
Waiter, Can I have the bill please? (Score:4, Insightful)
Nothing completely short of complete incompetence!
Re: (Score:1)
Re:I'm one of the victims... (Score:2, Informative)
This time PlusNet waited days to tell us what had happened. (I assumed a close
Re: (Score:2)
Re: (Score:2)
Seems so appropriate [sheldoncomics.com]
They sent an email to their customers?! (Score:5, Insightful)
It's unlikely they'll actually be able to read this email given the fact that they're now drowning in spam...
Re: (Score:2)
Lost emails (Score:5, Insightful)
Re: (Score:1)
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
This is why I don't leave any mail on my ISP's server. Everything gets downloaded to my home desktop as soon as possible. This machine is automatically backed-up to a separate partition on the same disk on a daily basis. Once a week the latest of these daily backups is copied to a normally powered down external disk attached to my laptop. Finally, that disk is backed up regularly to another one that normally is not even on-site. The day that all of these things fail at the same time, I more than likely am
Re: (Score:1)
Re: (Score:2)
You're right, the second and third level backups are done manually. But it's not a lot of work, as each just involves a single file copy operation. My off-site disk is stored in a location that I need to pass by very frequently anyway. I just pick up the disk when I'm there and bring it back the next day or the day after.
Regarding lazyness, it's all a matter of trade-off. Are you willing to loose your digital history or not? I sure as hell am not, so I make sure to have my backups under control. OTOH, w
Re: (Score:2)
I use mac's so it's Apple Mail, but thunderbird works just fine. Set your gmail account to leave messages on the server. when you connect with thunderbird you download all messages that you already haven't gotten.
you can archive stuff with gmail, and your local client will download those too.
It is a great saftey net because it is unlikely both will fail at the same time. Plus once it is on your machine you can back it up as you like.
Re: (Score:1)
Re: (Score:2)
Even a DLT VS4 drive and half a dozen tapes is cheaper over a two year period than Amazon S3.
Re: (Score:2)
Re: (Score:2)
units, people, watch your units. (Score:4, Insightful)
Reminds me of the Russian cartoon for kids, where different animals measure their sizes relative to the sizes of other animals, and in the end the Python says "I am much longer in Kakadoo than in Elephants".
Re: (Score:1)
Re: (Score:2)
You lose data, I'm gone. (Score:2)
If I'm trusting you with my data, that means I've decided you'll probably be at least as careful with it as I would be, and it will probably save me some time from having to do my own backups and such. In the case of email, it would mean that I'm sick of running my own mailserver, worrying about whether I'm online or not, etc etc...
If your service goes down for a bit, I might be able to understand, especially if it's a
Security software (Score:4, Insightful)
Re: (Score:2)
Obviously not. Assuming they used security software, this ISP certainly learned the difference.
Re: (Score:2, Insightful)
Re: (Score:2)
On the plus side they are activating their spam filtering for free, which was previously a paid for service.
As a Plus.Net customer I have not actually been effected, as I ditch all email addressed directly to the account, as I have a domain hosted with them, and that does not appear to have bee
Re: (Score:2)
Obviously this is not desireable, but it can happen to any software... The real reason they turned it off, is because due to the webmail system being proprietary, they can't fix this problem so it will only get compromised repeatedly.
Also, most of the webmail systems i've seen don't hold any data or authentication details themselves, they just hook over an imap server, so by hacking the webmail system you can only compromise the use
Re: (Score:2)
On the contrary. The software they chose to use was bug-ridden — and I don't mean subtle, occasional bugs, I mean "incapable of even performing its basic functions correctly" — and this was abundantly clear to anyone who had tried to use it for more than a few minutes and received a couple of HTML e-mails. It doesn't require a 45th level geek to appreci
Enough (Score:2)
I can only blame myself for staying for so long. My previous ISP provided an excellent service but was far more expensive. As always, you get what you pay for.
Re: (Score:2)
Re: (Score:2)
At one point PN where probably the best ISP in the UK - sadly after floating on the stock market those days soon came to an end at the alter of shareholder profits and sod the customer
Anyway even while a good ISP one thing PN had going for it was the customer forums - usually had a lot of knowledgable people on so even if you ran some odd software/os/hardware combination or wanted to do something beyond a simple mail form on your website you'd get alot of community help.
I
This is *not* a solution! (Score:2, Insightful)
In the meantime, if you use Webmail to check your PlusNet email from your own PC, you might find it more convenient to use an email program which runs on your PC instead.
So let me get this straight: PlusNet's closing down the WebMail service, but leaves the main e-mail server running, so
(1) the spam still comes in to the e-mail addresses
(2) users now cannot access via their Internet Browser and must use an e-mail client which may not filter spam as well (or sometimes at all)
B
Re: (Score:2)
Re: (Score:2)
In what way is this worse than accessing it via a browser, where you rely on PlusNet's own spam filtering, which is proven not to work well (or at all)?
I can always install Thunderbird and use its built-in filtering. Or I can even setup my own mailserver (I like bogofilter and IMAP) and use fetchmail to collect my email. But I cannot do anything about the shitty or no
Crossovers (Score:1)
and that, my friends, is worse than failure
Re: (Score:2)
I understand other BT costumers aren't happy... (Score:3, Funny)
Data Protection Act? (Score:5, Insightful)
in particular, the sections:
"Personal data should be securely kept, and not transferred to any other country without adequate protection."
and
"Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data."
( http://en.wikipedia.org/wiki/Data_Protection_Act [wikipedia.org] )
Re: (Score:2, Informative)
let me get this straight... (Score:1)
Re: (Score:2)
It sure doesnt go down well but there is very little option at times.
Re: (Score:1)
Re: (Score:1)
Re: (Score:1)
Re: (Score:2)
You're doing better than I was. At the time I left them, there was no way at all to get through the phone menu system to speak to a real person. I'm pretty sure about this, because I tried all the remotely plausible paths through the menus, as my phone bill will testify.
Re:let me get this straight... (Score:5, Interesting)
It is LO-CALL rate, which is a revenue sharing service. It is charged at the same cost local rate calls used to be in the early 90s, and it is always charged by the minute regardless of your phone service plan. Also, inclusive minutes usually don't count for calls to 0845 numbers.
BT charge a flat rate of 5p for a 1 hour national landline call at evenings and weekends on their lowest call plan, a 1 hour evening or weekend call to an 0845 number would cost 120p evenings and 60p weekends. BT's higher calling plans (options 2 and 3) charge you nothing for the first 60 minutes to a national number at evenings or weekends (again 0845 arent included) and in the case of option 3, also during the day.
What's worse is, a share of the call revenue goes to the company operating the number (which is why BT can't offer free calls to 0845) which gives these companies an incentive to keep you on hold.
In essence, 0845 really is premium rate. It may be a lower per-minute cost than 09 premium rate numbers, but it works in just the same way.
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
0845 is never the same as local, do BT even have a local rate anymore anyway?
On the cheapest BT plan, daytime calls could be charged at the same rate as 0845, but i do believe theyre actually 1p/min cheaper... Anywhere else (more expensive BT plans, voip phones, mobiles) 0845 is always more expensive than regular 01/02 landline calls.
And what with the prevelence of mobiles nowadays, the idea of "local" is pretty meaningless.
Re: (Score:1)
Plus Net were one of the few that had a "normal" 'phone number staffed by tech-savvy people who could usually help you in seconds. As this was obviously a net drain on resources, they decided to turn tech support into a net earner by hiring a premium rate call cantre, then giving them a "script" to work from d
We can just blame this on sysadmins ... (Score:2)
We can just blame this on sysadmins that don't want to work at underpaying jobs with bad managers that don't give any respect and corporate executives that don't really give a damn about quality of service.
So who else uses @mail? (Score:2)
The bigger question is who is el
Re: (Score:2)
This has a little bit about the situation:
http://www.thinkbroadband.com/news/i/3088.html [thinkbroadband.com]
Talk to Mumbai (Score:2)
Re: (Score:2)
You have to admire the British (Score:2)
Personally, I think the British have an admirable demeanor in the face of adversity or even outright defeat, as compared to the US for example. Stiff upper lip, all that stuff. Surely it's better to admit incompetence than not? Then again, maybe it's just our (American) culture of denial that annoys me.
Useless bunch of idiots (Score:1)
say what now? (Score:2)
Aside from the grammatical problems, what does the author mean by "spammers got hold of customers' e-mail addresses"? Do they actually mean that spammers aquired login access to email accounts?
oh, and no, I don't feel like reading the fine article.
How your post reads - at a first glance (Score:2, Funny)
While their Great Leader, shelleytherepublican.com, was in power, we could trust our oldest allies to loyally support our victory against the Iraqis, but alas, no more. I believe the only real solution is to liberate
Re: (Score:1, Redundant)
(who marked this troll? sort out your humour dude)