Forgot Password
Pentax Camera Forums Home
 

Reply
Show Printable Version 4 Likes Search this Thread
03-30-2017, 03:06 PM - 1 Like   #1
Veteran Member
mysterick's Avatar

Join Date: Oct 2006
Location: 44266
Photos: Gallery | Albums
Posts: 568
Encryption at Precision

I just sent a 40mm lens to Precision in CT on 3/24. I used my credit card to expedite the order. My bank called today and said that my card has been compromised . Not having used my card for anything lately and looking at their website's address, it looks like it is not encrypted. Just wondering if this has happened to anyone else? I contacted Precision, but we all know that works(?)!

03-30-2017, 03:21 PM - 1 Like   #2
Administrator
Site Webmaster
Adam's Avatar

Join Date: Sep 2006
Location: Arizona
Photos: Gallery | Albums
Posts: 51,608
I just looked, and the repair service form is not secure. Anyone on your local network, at the same coffee shop, or on Precision's network could have intercepted your submission in the clear, not to mention ISPs, security companies, and so on. If you don't have a password on your home network, anyone nearby can connect and track your traffic.

Never submit any credit card or personal information unless you see "https" and a green lock in the address bar.

Adam
PentaxForums.com Webmaster (Site Usage Guide | Site Help | My Photography)



PentaxForums.com server and development costs are user-supported. You can help cover these costs by donating or purchasing one of our Pentax eBooks. Or, buy your photo gear from our affiliates, Adorama, B&H Photo, KEH, or Topaz Labs, and get FREE Marketplace access - click here to see how! Trusted Pentax retailers:
03-30-2017, 03:37 PM   #3
a5m
Veteran Member
a5m's Avatar

Join Date: Oct 2015
Photos: Gallery | Albums
Posts: 576
Wow....

About a month ago my Amazon Visa was compromised. For the life of me I couldn't figure out how it could have happened since I rarely use it. I figured someone scanned it or something through my wallet when I was out and about. Now I'm pretty sure it was through Precision Camera's website. I've only sent gear to Precision for repair under warranty and I always used that card. But it never got charged so there wasn't any trail for me to link it to Precision.

Thank you for this post. It solved what had become a mystery to me. I'm almost 100% sure it was Precision's website. But Precision has stepped up ther game lately. Bringing this security issue to their attention might actually get it resolved.

I hope everything gets sorted on your end. Credit card companies are pretty good nowadays with fraud protection.
03-30-2017, 03:42 PM - 1 Like   #4
Administrator
Site Webmaster
Adam's Avatar

Join Date: Sep 2006
Location: Arizona
Photos: Gallery | Albums
Posts: 51,608
I am forwarding this to Ricoh's corporate office...


Adam
PentaxForums.com Webmaster (Site Usage Guide | Site Help | My Photography)



PentaxForums.com server and development costs are user-supported. You can help cover these costs by donating or purchasing one of our Pentax eBooks. Or, buy your photo gear from our affiliates, Adorama, B&H Photo, KEH, or Topaz Labs, and get FREE Marketplace access - click here to see how! Trusted Pentax retailers:
03-30-2017, 03:55 PM   #5
Site Supporter
Site Supporter
geomez's Avatar

Join Date: Mar 2013
Location: Roanoke, Virginia, USA
Photos: Gallery
Posts: 1,760
Wow! I'm following this thread. Too big an issue to not stay updated. I'm sorry to hear of those who's cards were compromised.
03-30-2017, 04:03 PM - 1 Like   #6
Veteran Member
ripper2860's Avatar

Join Date: Mar 2014
Location: Dallas, TX
Posts: 890
HTTPS only encrypts over-the-wire as it is transmitted. Other questions come to mind ...

Do they retain CC info on their server? If so, is it encrypted or stored as clear text?

The server may be compromised and if not encrypted, CC information could be harvested and sent to who knows where. If they take security seriously, they'll thoroughly assess their server for a breach. If they didn't think enough to secure their form site, odds are their server security is lacking.
03-30-2017, 04:54 PM   #7
Veteran Member
lightbox's Avatar

Join Date: Mar 2015
Posts: 599
Excellent advice posted. The enforcement of HTTPS that browsers are starting to push these days is a very good thing for consumer safety. Some more common sense tips:

- Always confirm the address is as you expect. No typos in the address bar.
- Don't follow links. Always type the address manually.
- Check the site's certificate to ensure that a) the domain is correct and b) it's signed by a well-known issuer (i.e., DigiCert). The green lock icon is a visual indication of authenticity.
- If you must use public or unsecured WiFi, look into a VPN service to secure your private traffic from snoops and eavesdroppers.
- Don't ever use any public or untrusted computer / browser to transmit sensitive information.
- Keep a dedicated CC for online use and find one that has very good fraud protection and refunds you in case of unauthorized charges.
- Don't use the same password on all of your accounts, especially financial ones or sites storing sensitive information about you. Change them often, and make them unique and strong passwords. Possibly use a credential management system like LastPass or KeePass.

03-30-2017, 07:11 PM   #8
Forum Member
GuitarGuru76's Avatar

Join Date: Jan 2013
Location: Wisconsin
Photos: Gallery | Albums
Posts: 95
This solved a recent issue I had recently, my card info was compromised and someone made 2 purchases thru Expedia recently. My only recent use of that card was with Precision, for my K-01 repair. It was never charged for the repair, (Ricoh covered the repair).
What a sad situation. Ricoh's corporate office should be notified.
03-30-2017, 07:13 PM   #9
Loyal Site Supporter
Loyal Site Supporter
UncleVanya's Avatar

Join Date: Jul 2014
Photos: Gallery | Albums
Posts: 28,467
I fully expect those of you with compromised cards are right - but do understand the card can get stolen over 12 months ago and only surface now. The aggregators of this data sell in chunks and stolen card numbers are often quite disconnected in time from the time the theft attempts are made.
03-30-2017, 07:18 PM   #10
Otis Memorial Pentaxian
Otis FanOtis FanOtis FanOtis FanOtis FanOtis Fan
Loyal Site Supporter
clackers's Avatar

Join Date: Jul 2013
Location: Melbourne
Photos: Albums
Posts: 16,397
QuoteOriginally posted by Adam Quote
I just looked, and the repair service form is not secure.
Amateur hour!

These guys presumably have a contract to deliver an enterprise standard service.
03-30-2017, 07:29 PM   #11
Forum Member
GuitarGuru76's Avatar

Join Date: Jan 2013
Location: Wisconsin
Photos: Gallery | Albums
Posts: 95
QuoteOriginally posted by UncleVanya Quote
I fully expect those of you with compromised cards are right - but do understand the card can get stolen over 12 months ago and only surface now. The aggregators of this data sell in chunks and stolen card numbers are often quite disconnected in time from the time the theft attempts are made.
Yes, this would have been October of last year for me.
03-30-2017, 08:30 PM   #12
Administrator
Site Webmaster
Adam's Avatar

Join Date: Sep 2006
Location: Arizona
Photos: Gallery | Albums
Posts: 51,608
QuoteOriginally posted by clackers Quote
Amateur hour!

These guys presumably have a contract to deliver an enterprise standard service.
They're living in the 90's still, it seems.

Adam
PentaxForums.com Webmaster (Site Usage Guide | Site Help | My Photography)



PentaxForums.com server and development costs are user-supported. You can help cover these costs by donating or purchasing one of our Pentax eBooks. Or, buy your photo gear from our affiliates, Adorama, B&H Photo, KEH, or Topaz Labs, and get FREE Marketplace access - click here to see how! Trusted Pentax retailers:
03-30-2017, 11:24 PM   #13
Pentaxian
SpecialK's Avatar

Join Date: Dec 2006
Location: So California
Photos: Gallery
Posts: 16,482
Some years ago, my former and now-defunct employer was required by the bank to change the whole credit card processing procedure. Encrypting, shredding anything showing the CC # (once the transaction was finished), not being able to see the entire number when the order was looked up, putting the server in a locked room, etc. It was a hassle for the IT people I'm sure, and a major inconvenience in my job (processing orders and refunds, and looking for fraud).
03-31-2017, 05:58 AM   #14
Veteran Member
wissink's Avatar

Join Date: May 2014
Location: S-ON
Photos: Gallery
Posts: 609
Is it possible the CC company says its compromised simply because Precision does not meet security requirements?
03-31-2017, 07:49 AM   #15
Loyal Site Supporter
Loyal Site Supporter
UncleVanya's Avatar

Join Date: Jul 2014
Photos: Gallery | Albums
Posts: 28,467
PCI compliance requires better than this.
Reply

Bookmarks
  • Submit Thread to Facebook Facebook
  • Submit Thread to Twitter Twitter
  • Submit Thread to Digg Digg
Tags - Make this thread easier to find by adding keywords to it!
card, encypted repair site., pentax service, precision, repair, service, warranty

Similar Threads
Thread Thread Starter Forum Replies Last Post
What is your experience with Precision Camera Repair in Enfield, CT (Poll) mee Repairs and Warranty Service 103 09-21-2017 06:31 PM
Call For Encryption MadMathMind Photographic Industry and Professionals 23 12-15-2016 01:14 PM
Super Ultra Fast Warranty Repair at Precision!! dcpropilot Repairs and Warranty Service 8 04-13-2016 12:57 PM
Precision repairs April.H Pentax K-3 & K-3 II 35 06-11-2015 09:05 AM



All times are GMT -7. The time now is 10:50 AM. | See also: NikonForums.com, CanonForums.com part of our network of photo forums!
  • Red (Default)
  • Green
  • Gray
  • Dark
  • Dark Yellow
  • Dark Blue
  • Old Red
  • Old Green
  • Old Gray
  • Dial-Up Style
Hello! It's great to see you back on the forum! Have you considered joining the community?
register
Creating a FREE ACCOUNT takes under a minute, removes ads, and lets you post! [Dismiss]
Top