![]() |
![]() |
![]() |
![]() |
![]() ![]() |
![]() |
BMW Garage | BMW Meets | Register | Today's Posts | Search |
![]() |
![]() ![]() |
BMW 3-Series (E90 E92) Forum
>
GetBMWParts aka Tischer Internet Parts Security Breach
![]() |
![]() |
07-10-2014, 12:17 PM | #1 |
Master Gunner
78
Rep 435
Posts
Drives: 2008 335i Sport
Join Date: Aug 2013
Location: Sandy Eggo
|
![]()
Anyone else get a letter from MileOne Automotive?
First I had my personal data and credit card info stolen off of Target's databases which my bank discovered illegal charge attempts against my account, just before the huge data theft made headline news nation/world-wide. Now I get a notice from GetBMWParts that their website sales vendor, TradeMotion, just had a "Security Breach" wherein customer credit card information was stolen. I'm getting pissed off with retail/online vendors in their apparently insufficient protection of our personal credit information. This is only going to get worse unless significant changes are made to electronic payment methods, such as the proposal to incorporate smart chips into credit cards.
__________________
2008 335i Alpine White Sport Sedan AT | Avant Garde M364 Staggered 19"
|
07-10-2014, 12:19 PM | #2 |
Lieutenant
![]() ![]() ![]() ![]() 25
Rep 432
Posts
Drives: 2017 BMW M3
Join Date: Mar 2013
Location: Sherwood, OR
|
Yep, got the same thing!
__________________
2017 M3 - Long Beach Blue, Competition Package, Burger Performance Intake
2009 135i - Dinan CAI, Dinan Exhaust, Turbonetics FMIC, Dinan Stage 2 |
Appreciate
0
|
07-10-2014, 01:11 PM | #5 |
Lieutenant General
![]() ![]() ![]() 1751
Rep 14,825
Posts |
Don't you love when a health care (PPO or HMO) loses all member information (like 300,000+) because someone at a health fair had it on a thumb drive, lost it, and couldn't find it? All kidding aside since HIPPA you don't hear of that happening as much. But these eTailers are free to do what they want, and likely farm out their IT work to insecure and possibly shady vendors.
|
Appreciate
0
|
07-10-2014, 01:34 PM | #7 | |
First Lieutenant
![]() ![]() 39
Rep 315
Posts |
Quote:
An IT worker would still need to hack the cipher text which can't be understood by individuals, so a computer would need to format it into understandable information. Anyways, GetBMWParts only uses a 128-bit encryption which is significantly less protective than a 256-bit encryption used by companies like PayPal. A 128-bit can be cracked in less than 1/4 of the time it takes to crack a 256-bit.
__________________
07 335i
Mods: JB4 + MHD BEF, RB Twos Plus, Phoenix PI Manifold, Dual Walbro 450 LPFP's, DCI, VRSF DP's, VRSF 7.5" FMIC, VRSF CP + TiAL BOV, VRSF inlets & aluminum outlets, TC Kline SA, M3 F/R control arms, M3 subframe bushings |
|
Appreciate
0
|
07-10-2014, 01:46 PM | #8 |
First Lieutenant
![]() ![]() 39
Rep 315
Posts |
Wow. I'm surprised how outdated their security is.
![]() They are using TLS 1.0 which came out in 1999! That's 15 years ago!!! A security system developed in 1999 simply can't match a hacker with the technology available today.
__________________
07 335i
Mods: JB4 + MHD BEF, RB Twos Plus, Phoenix PI Manifold, Dual Walbro 450 LPFP's, DCI, VRSF DP's, VRSF 7.5" FMIC, VRSF CP + TiAL BOV, VRSF inlets & aluminum outlets, TC Kline SA, M3 F/R control arms, M3 subframe bushings |
Appreciate
0
|
07-10-2014, 02:12 PM | #10 |
Colonel
![]() ![]() 326
Rep 2,016
Posts |
There's nothing you can really do about it except pay in cash from now on in retail stores.
__________________
WedgePerformance E40 MHD | Performance Exhaust Mod | BMS DP | Vibrant 1790 | BMS Intake | VRSF CP | xHP Stage 3 Michelin PSS | M3 Control Arms LUX v4 LEDs | Shadowline Grills | Lip Spoiler |
Appreciate
0
|
07-10-2014, 02:30 PM | #11 |
Brigadier General
![]() ![]() 92
Rep 3,731
Posts
Drives: BMW S1000XR
Join Date: Jun 2011
Location: Gilbert, AZ
|
Yeah, I received notification trade in motion but have not seen any illegal purchases.
I am all for a smart chip as long as it is not RFID (constant radio signal emitted). Thats another manner in which your personal data can be obtained by someone close or next to you if they have the appropriate equipment.
__________________
![]() BMWCCA member |
Appreciate
0
|
07-10-2014, 03:05 PM | #12 |
Lieutenant Colonel
![]() 118
Rep 1,951
Posts |
You'd be scared shitless just how secondary the concerns of security and privacy are on the internet. You'd be scared slightly-less-shitless at the proportion that's willful ignorance and development cost savings vs ineptitude. http://stilldrinking.org/programming-sucks
__________________
![]() |
Appreciate
0
|
07-10-2014, 03:44 PM | #14 |
735
Rep 12,478
Posts |
Dear valued getBMWparts.com customers and forum members,
Regarding the security breach notice our Corporation - MileOne Automotive recently sent only to customers recognized as potentially at risk - we can certainly understand your questions and frustration. As stated in the notification letter, however, the security incident did not occur on MileOne's systems or on our GetBMWParts.com or SubaruPartsDepot.com websites. Rather, the incident originated at one of our third party vendors, TradeMotion. TradeMotion is an e-commerce service provider that we, and hundreds of other online retailers (including other vendors on these forums), use to process online transactions including payment processing. Nonetheless, we recognize that you purchased one or more of our products and we take the privacy and security of our customers extremely seriously. That is why, despite the fact the incident did not originate with our systems, we took proactive steps to help you minimize potential harm from the incident. As to any concerns regarding the timing of the incident and the notification, the dates identified in the letter reflect the period of time that TradeMotion has determined account information was vulnerable to unauthorized acquisition. The March 5, 2014 date is not the date when the security incident was discovered. Rather, it is the beginning of the security breach period which was determined after the breach was discovered and TradeMotion completed its investigation. The notice was provided only to customers identified as potentially at risk after TradeMotion completed its investigation, including the following:
We continue to encourage you to take advantage of the complementary ProtectMyID program being offered through the notice. In addition to the ProtectMyID program, you are also encouraged to consider the "Additional Actions" described in the notice, including:
Sincerely, getBMWparts.com MileOne Automotive Email: getHelp@getBMWparts.com |
Appreciate
0
|
07-10-2014, 04:27 PM | #15 |
Second Lieutenant
![]() 31
Rep 257
Posts
Drives: 2021 Hockenheim Silver M2C
Join Date: Oct 2012
Location: WA
|
I had several fraudulent charges back in March/April, this explains a lot.
|
Appreciate
0
|
07-10-2014, 11:01 PM | #16 |
Major General
![]() ![]() 896
Rep 5,476
Posts |
Me too, Amex had to reissue my card in April!
__________________
2025 X5 Msport
2008 E93 335i FBO 2012 Mercedes C63 Black Series Alanite Grey |
Appreciate
0
|
07-11-2014, 12:23 AM | #18 |
Private First Class
![]() 8
Rep 172
Posts |
thought it was something local, got a call from my bank's fraud department that someone in Illinois had purchased $2600 in pizzas, shopping stuff (pier one, vicki's secret, gap) and was happy they caught it.... 4 days later i got a letter.... little bastards.
any way of getting a large discount on part for my troubles? jk |
Appreciate
0
|
07-12-2014, 01:51 AM | #19 |
New Member
0
Rep 12
Posts |
These things do happen unfortunately just be glad they disclosed it. I'm a project manager for an $8MM a year ecommerce company and during an audit we identified an unknown file on our server which was saving credit card information and being retrieved every few days. The source of the problem was a vulnerability in the ecommerce platform. Of course we told our customers effected and informed the authorities. The FBI got involved and we gave them complete access so they could run their own audits.
Attacks like this assuming it wasn't negligent are ultimately very hard to protect against 100% of the time. If there's a will there's a way. |
Appreciate
0
|
07-12-2014, 12:17 PM | #21 | |
Master Gunner
78
Rep 435
Posts
Drives: 2008 335i Sport
Join Date: Aug 2013
Location: Sandy Eggo
|
Quote:
If the information posted from other members regarding the use of older and/or lesser security technology by this "third party" is true, then GetBMWParts aka Tischer Internet Sales is even more culpable because they did not do proper due diligence nor vetting of TradeMotion to ensure it truly can provide the necessary safeguards to protect private and privileged customer information.
__________________
2008 335i Alpine White Sport Sedan AT | Avant Garde M364 Staggered 19"
|
|
Appreciate
0
|
07-12-2014, 12:32 PM | #22 |
///M Driver
112
Rep 1,973
Posts |
I got the letter too. Actually had two rounds of fraudulent purchases from some 3rd party vendor in Early May. Had to get a new card and all.
Definitely makes me not want to purchase from them again..
__________________
| 07 Jet Black 335 - N54 Single Turbo | 20 Toronto Red X3M | |
Appreciate
0
|
![]() |
Bookmarks |
|
|