Skip to content

Channel Register

Renault F1 comp site spills entrants' details

8 May 2008 16:01

You will never break the chain

SlashdotDiggdel.icio.usReddit
® [Mobile]

« Back to article page

Comment form

Well... 

By David Wiernicki
Posted Thursday 8th May 2008 16:45 GMT

At least their web site is performing better than their car...

*ducks*

Fleetwood Mac puntastic subtitle 

By Carl Marshall
Posted Thursday 8th May 2008 17:37 GMT
Coat

*groan*

Even worse, it's a coat related band...

Renault site spills details 

By Fatman
Posted Thursday 8th May 2008 21:14 GMT
Unhappy

Don't those idiots test their websites???

I bet the web developer wrote that site by throwing bananas at the keyboard.

Awesome subtitle 

By Ben Rose
Posted Friday 9th May 2008 06:15 GMT
Joke

I laughed out loud at that one, nice one John.

Quality control... 

By Anonymous Coward
Posted Friday 9th May 2008 07:05 GMT

Nice to see Renault uses the same quality control on their website as they do on their cars...... both just as crap

Doesn't surprise me... 

By Anonymous Coward
Posted Friday 9th May 2008 08:04 GMT

...if it's the same guy running their web team as a couple of years back. Renault UK wanted to build a purchasing page for it's members in association with our company. We had the meeting and discussed with them how to do it. After 2 months they decided they couldn't do it and gave us 1 week for our web developer to write it himself.

Utter rollocks 

By Pete James
Posted Friday 9th May 2008 08:14 GMT

For the record Renault have always been reactively very good vis a vis data security.

Unfortunately they're not so hot at turning this into being proactive.

But hey, they could of course behave like Oracle. Or Apple.

Not Fixed 

By Anonymous Coward
Posted Friday 9th May 2008 08:26 GMT
Thumb Down

This has been bodged, not fixed. I just found the website via Google and the details of a guy called Nick in Derby were given to me, email address, postal address, phone number...

Not the first, won't be the last 

By Mike Holden
Posted Friday 9th May 2008 13:15 GMT
Thumb Down

I notiiced a similar issue on the mailing list page of a well known UK sports team. If you go to edit your details, your member id is used as part of the url to your personal details page (www.team.com/edit?id=1234). Changing the id got you to another user's details.

I emailed them, they responded quickly, taking the page down short-term, and fixing it with a proper system within a few days.

You do have to wonder at the mentality of a "developer" who comes up with crap like that and implements it in a live site though. No doubt a simple download of demo code from an HTML For Dummies site, never intended as a secure solution, just a "how does a POST form work" example..

non-story 

By Anonymous Coward
Posted Monday 12th May 2008 09:50 GMT
Thumb Down

ok a bit of cock up but with the execption of the email address this is hardly sensitive information. name, address, telephone number and postcode? can you say "telephone directory"?


Add your own comment

Never published
Password reminder

Related Whitepapers