![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
|
|
#1
|
||||
|
||||
![]()
I received an email this morning from Bill Goodwin’s new venture. In the email he includes a username and password. He uses the password from his old auction house, which he sold to Beckett’s 5-6 years ago.
First, the password info is supposed to protected and not available to the auction house. Second, in this day and age, no one should be posting that info in an unencrypted fashion, in an email. I’d like to know whether the source of this breach was Beckett’s, or Bob Freedman. It’s certainly possible that Beckett’s sold the customer list to Bill. (I prefer thinking that they sold it, as the alternative is that Bill stole it.), but theoretically, that list should not include passwords. I have emailed my concerns to Beckett’s, Bill Goodwin, and Bob Freedman. None have replied. To me, this is a HUGE concern. Remember, we have been told in the past that generally speaking, auction houses are not able to see your max bids. However, if the house has access to the password, they can now simply log on and look.
__________________
Jim Van Brunt Last edited by Jim VB; 03-26-2020 at 03:41 PM. |
#2
|
||||
|
||||
![]()
I received the same email. Very troubling.
|
#3
|
||||
|
||||
![]()
+1. Jim, thanks for quickly taking the actions you did.
__________________
Seeking very scarce/rare cards for my Sam Rice master collection, e.g., E210 York Caramel Type 2 (upgrade), 1931 W502, W504 (upgrade), W572 sepia, W573, 1922 Haffner's Bread, 1922 Keating Candy, 1922 Witmor Candy Type 2 (vertical back), 1926 Sports Co. of Am. with ad & blank backs. Also 1917 Merchants Bakery & Weil Baking cards of WaJo. Also E222 cards of Lipe, Revelle & Ryan. Last edited by ValKehl; 03-20-2020 at 11:48 AM. |
#4
|
||||
|
||||
![]()
I just looked at the same email too!
I actually just looked at his auction listings. I am in the same boat as to why the 'private password/username' was there.
__________________
1916-20 UNC Big Heads Need: Ping Bodie |
#5
|
||||
|
||||
![]()
I also received this email. My username and password was unprotected in the body of the email. When I used this info to log into Heartland, Google told me that there was a data breech and that I should change my password immediately, which I did. I wanted to log into my account to see if my credit card info was listed. Thank heaven it was not transferred to Heartland Auctions from the old site.
Rick
__________________
Rick McQuillan T213-2 139 down 46 to go. |
#6
|
||||
|
||||
![]()
^^^interesting???
I am gonna try and log-in and see if this happens, and if so change mine. BTW- i also sent a message thru the site's contact page about this matter.
__________________
1916-20 UNC Big Heads Need: Ping Bodie Last edited by pawpawdiv9; 03-20-2020 at 12:34 PM. |
#7
|
||||
|
||||
![]()
They shouldn't even have access to my password in the first place, let alone sending that in an email. Very concerning.
__________________
Always looking for: 1913 Cravats pennants St. Paul Saints Game Used Bats and Memorabilia http://www.net54baseball.com/showthread.php?t=180664 |
#8
|
||||
|
||||
![]()
I would imagine that a lot of users reuse passwords across sites. This is a good reason not to do that.
Password managers are a good thing... KeePass, 1Password, etc. |
#9
|
|||
|
|||
![]() Quote:
![]()
__________________
Current Wantlist: E92 Nadja - Bescher, Chance, Cobb, Donovan, Doolan, Dougherty, Doyle (with bat), Lobert, Mathewson, Miller (fielding), Tinker, Wagner (throwing), Zimmerman E/T Young Backrun - Need E90-1 E92 Red Crofts - Anyone especially Barry and Shean |
#10
|
||||
|
||||
![]() Quote:
Spot on advice. When I received the email from Bill I was alarmed but not overly worried, because I use 1Password and have a different password for every website. |
#11
|
||||
|
||||
![]()
Changing your password is a futile exercise if the software company makes it available to the auction house.
At that point, it’s no longer “secure.”
__________________
Jim Van Brunt |
#12
|
|||
|
|||
![]()
There is no breach.
Simpleauctionsite does not encrypt passwords, I know owners of several who have been able to view passwords and provide them if I forgot. In my opinion Bill sent this out in a shameless effort to bring awareness to his auction, not understanding the severity of sending out passwords unencrypted to an email. Based on his this happened, Bob ported over Goodwin's old info to a new website or Bill kept one for his records. I am sure Beckett would love to hear about this. |
#13
|
|||
|
|||
![]()
Assume the non-compete is over
__________________
"Trolling Ebay right now" © Always looking for signed 1952 topps as well as variations and errors |
#14
|
|||
|
|||
![]()
..got the same email this AM. It looked so "Fishy" that I did not even open it...straight to delete. I am thankful to the OP and the other respondents that put me informed on this. I always had good phone contacts with Bill Goodwin on items in his past auctions. Always the low $ stuff but he was very helpful. But this is inexcusable and in this competitive market I do not need reckless and careless houses putting me at risk. Both parties are off of my list of places to do business with. Once again the Net54 community was vigilant and helpful in keeping us informed. Thank you...
Sincerely, Dennis O'Brien ( Name as per the rules on these matters...I think) |
#15
|
||||
|
||||
![]()
An unencrypted password is not a password; it is basically useless from a data integrity perspective.
__________________
Looking for: Type 1 photos of baseball HOFers N172 Old Judge Portraits Will buy or trade for the above. Check out my cards at: www.imageevent.com/crb972 |
#17
|
||||
|
||||
![]() Quote:
I’ve spoken to two other auction houses who use SimpleAuctionSite.com. They both told me they do not have access to passwords. If you forget a password and ask them to help, all they can do is give you a “Reset Password” link. Now, it’s possible that this is one of those options that Bob can turn on or off for each auction house. (Like he has admitted he can do with the visibility of max bids.) If so, the first breach is theirs, by giving/selling that info to Goodwin. The second breach is Bill’s by publishing it in unencrypted fashion in an email.
__________________
Jim Van Brunt |
#18
|
|||
|
|||
![]()
[QUOTE=Sean1125;1963574]There is no breach.
Simpleauctionsite does not encrypt passwords, I know owners of several who have been able to view passwords and provide them if I forgot. This is false.... I can not see any ones password on my admin page for Simple Auctions. I can not even see how many characters there are to even begin to assist anyone in remembering their password. I can only send a password reset. |
#19
|
|||
|
|||
![]()
There was a time when the least secure thing you could do was write your password down and put it beside your computer. Now it's probably the safest place for your password to be.
|
#20
|
||||
|
||||
![]() Quote:
![]()
__________________
Leon Luckey www.luckeycards.com Last edited by Leon; 03-20-2020 at 01:34 PM. |
![]() |
|
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Has anyone been able to reach Bill Goodwin? | Blunder19 | Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions | 33 | 09-18-2013 02:29 PM |
Chatted With Bill Goodwin Today | GregMitch34 | Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions | 42 | 06-09-2013 08:49 AM |
Anyone speak or hear from bill goodwin in last 10 days??? | forazzurri2axz | Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions | 11 | 03-07-2011 07:05 PM |
Special Thanks To Bill Goodwin | Archive | Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions | 5 | 03-24-2009 06:32 AM |
Bill Goodwin's e-mail addy please? | Archive | Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions | 2 | 11-04-2007 09:11 PM |