NonSports Forum

Net54baseball.com
Welcome to Net54baseball.com. These forums are devoted to both Pre- and Post- war baseball cards and vintage memorabilia, as well as other sports. There is a separate section for Buying, Selling and Trading - the B/S/T area!! If you write anything concerning a person or company your full name needs to be in your post or obtainable from it. . Contact the moderator at leon@net54baseball.com should you have any questions or concerns. When you click on links to eBay on this site and make a purchase, this can result in this site earning a commission. Affiliate programs and affiliations include, but are not limited to, the eBay Partner Network. Enjoy!
Net54baseball.com
Net54baseball.com
ebay GSB
T206s on eBay
Babe Ruth Cards on eBay
t206 Ty Cobb on eBay
Ty Cobb Cards on eBay
Lou Gehrig Cards on eBay
Baseball T201-T217 on eBay
Baseball E90-E107 on eBay
T205 Cards on eBay
Baseball Postcards on eBay
Goudey Cards on eBay
Baseball Memorabilia on eBay
Baseball Exhibit Cards on eBay
Baseball Strip Cards on eBay
Baseball Baking Cards on eBay
Sporting News Cards on eBay
Play Ball Cards on eBay
Joe DiMaggio Cards on eBay
Mickey Mantle Cards on eBay
Bowman 1951-1955 on eBay
Football Cards on eBay

Go Back   Net54baseball.com Forums > Net54baseball Main Forum - WWII & Older Baseball Cards > Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions

Reply
 
Thread Tools Display Modes
  #1  
Old 03-20-2020, 11:10 AM
Jim VB's Avatar
Jim VB Jim VB is offline
Jim VB
Member
 
Join Date: Apr 2009
Posts: 2,090
Default Security Breech from Bill Goodwin- UPDATE IN POST #77

I received an email this morning from Bill Goodwin’s new venture. In the email he includes a username and password. He uses the password from his old auction house, which he sold to Beckett’s 5-6 years ago.

First, the password info is supposed to protected and not available to the auction house.

Second, in this day and age, no one should be posting that info in an unencrypted fashion, in an email.

I’d like to know whether the source of this breach was Beckett’s, or Bob Freedman.

It’s certainly possible that Beckett’s sold the customer list to Bill. (I prefer thinking that they sold it, as the alternative is that Bill stole it.), but theoretically, that list should not include passwords.

I have emailed my concerns to Beckett’s, Bill Goodwin, and Bob Freedman. None have replied.

To me, this is a HUGE concern.

Remember, we have been told in the past that generally speaking, auction houses are not able to see your max bids. However, if the house has access to the password, they can now simply log on and look.
__________________
Jim Van Brunt

Last edited by Jim VB; 03-26-2020 at 03:41 PM.
Reply With Quote
  #2  
Old 03-20-2020, 11:32 AM
t206fanatic's Avatar
t206fanatic t206fanatic is offline
Jeff Willi@ms
Member
 
Join Date: Aug 2018
Posts: 319
Default

I received the same email. Very troubling.
Reply With Quote
  #3  
Old 03-20-2020, 11:47 AM
ValKehl's Avatar
ValKehl ValKehl is offline
Val Kehl
Member
 
Join Date: May 2009
Location: Manassas, VA (DC suburb)
Posts: 3,825
Default

Quote:
Originally Posted by t206fanatic View Post
I received the same email. Very troubling.
+1. Jim, thanks for quickly taking the actions you did.
__________________
Seeking very scarce/rare cards for my Sam Rice master collection, e.g., E210 York Caramel Type 2 (upgrade), 1931 W502, W504 (upgrade), W572 sepia, W573, 1922 Haffner's Bread, 1922 Keating Candy, 1922 Witmor Candy Type 2 (vertical back), 1926 Sports Co. of Am. with ad & blank backs. Also 1917 Merchants Bakery & Weil Baking cards of WaJo. Also E222 cards of Lipe, Revelle & Ryan.

Last edited by ValKehl; 03-20-2020 at 11:48 AM.
Reply With Quote
  #4  
Old 03-20-2020, 12:22 PM
pawpawdiv9's Avatar
pawpawdiv9 pawpawdiv9 is offline
Chr!$ M!ll!c@n
Member
 
Join Date: Oct 2012
Location: GA
Posts: 2,916
Default

I just looked at the same email too!
I actually just looked at his auction listings.
I am in the same boat as to why the 'private password/username' was there.
__________________
1916-20 UNC Big Heads
Need: Ping Bodie
Reply With Quote
  #5  
Old 03-20-2020, 12:23 PM
buymycards's Avatar
buymycards buymycards is offline
Rick McQuillan
Member
 
Join Date: May 2009
Location: Wisconsin
Posts: 3,178
Default Me too

I also received this email. My username and password was unprotected in the body of the email. When I used this info to log into Heartland, Google told me that there was a data breech and that I should change my password immediately, which I did. I wanted to log into my account to see if my credit card info was listed. Thank heaven it was not transferred to Heartland Auctions from the old site.

Rick
__________________
Rick McQuillan


T213-2 139 down 46 to go.
Reply With Quote
  #6  
Old 03-20-2020, 12:26 PM
pawpawdiv9's Avatar
pawpawdiv9 pawpawdiv9 is offline
Chr!$ M!ll!c@n
Member
 
Join Date: Oct 2012
Location: GA
Posts: 2,916
Default

^^^interesting???
I am gonna try and log-in and see if this happens, and if so change mine.
BTW- i also sent a message thru the site's contact page about this matter.
__________________
1916-20 UNC Big Heads
Need: Ping Bodie

Last edited by pawpawdiv9; 03-20-2020 at 12:34 PM.
Reply With Quote
  #7  
Old 03-20-2020, 12:26 PM
Bugsy's Avatar
Bugsy Bugsy is offline
©hri$ $€X₮ØΝ
Member
 
Join Date: Jun 2009
Posts: 813
Default

They shouldn't even have access to my password in the first place, let alone sending that in an email. Very concerning.
__________________
Always looking for:

1913 Cravats pennants

St. Paul Saints Game Used Bats and Memorabilia

http://www.net54baseball.com/showthread.php?t=180664
Reply With Quote
  #8  
Old 03-20-2020, 12:27 PM
brass_rat's Avatar
brass_rat brass_rat is offline
Steve
Member
 
Join Date: Dec 2009
Posts: 1,053
Default

I would imagine that a lot of users reuse passwords across sites. This is a good reason not to do that.

Password managers are a good thing... KeePass, 1Password, etc.
Reply With Quote
  #9  
Old 03-20-2020, 12:31 PM
Jim VB's Avatar
Jim VB Jim VB is offline
Jim VB
Member
 
Join Date: Apr 2009
Posts: 2,090
Default

Changing your password is a futile exercise if the software company makes it available to the auction house.

At that point, it’s no longer “secure.”
__________________
Jim Van Brunt
Reply With Quote
  #10  
Old 03-20-2020, 12:32 PM
x2drich2000 x2drich2000 is offline
(DJ) Rich.ard.s
 
Join Date: May 2009
Posts: 2,252
Default

Quote:
Originally Posted by brass_rat View Post
I would imagine that a lot of users reuse passwords across sites. This is a good reason not to do that.

Password managers are a good thing... KeePass, 1Password, etc.
You mean my password shouldn't be Password123 on every site?
__________________
Current Wantlist:
E92 Nadja - Bescher, Chance, Cobb, Donovan, Doolan, Dougherty, Doyle (with bat), Lobert, Mathewson, Miller (fielding), Tinker, Wagner (throwing), Zimmerman
E/T Young Backrun - Need E90-1
E92 Red Crofts - Anyone especially Barry and Shean
Reply With Quote
  #11  
Old 03-20-2020, 12:34 PM
glynparson's Avatar
glynparson glynparson is offline
Glyn Parson
Member
 
Join Date: May 2009
Location: Blandon PA
Posts: 2,185
Default

Quote:
Originally Posted by x2drich2000 View Post
You mean my password shouldn't be Password123 on every site?
Wow I never thought of adding the 123. I just went with password. Lol :-)
Reply With Quote
  #12  
Old 03-20-2020, 12:37 PM
ullmandds's Avatar
ullmandds ullmandds is offline
pete ullman
Member
 
Join Date: Apr 2009
Location: saint paul, mn
Posts: 11,488
Default

he must be upset that disney is closed?
Reply With Quote
  #13  
Old 03-20-2020, 12:52 PM
wondo wondo is offline
John Wondowski
Member
 
Join Date: May 2009
Posts: 1,370
Default

Quote:
Originally Posted by ullmandds View Post
he must be upset that disney is closed?
Now that’s funny!
Reply With Quote
  #14  
Old 03-20-2020, 01:00 PM
brass_rat's Avatar
brass_rat brass_rat is offline
Steve
Member
 
Join Date: Dec 2009
Posts: 1,053
Default

Sorry, yes, I agree... Changing the passwords don't help, but if an entity has access to your password, at least they have access to only that one account and trying your email/password on multiple sites won't give them access to other things.

My comment was meant to be a tangent to the original post. Agreed that entities should not have access to passwords, whether it be auction house or other... And they should not be emailed in plain text, visible to any admins under any circumstances, etc.

Just trying to be helpful. Will bow out of this conversation now.
Reply With Quote
  #15  
Old 03-20-2020, 01:05 PM
Sean1125 Sean1125 is offline
Member
 
Join Date: Jan 2011
Posts: 3,567
Default

There is no breach.

Simpleauctionsite does not encrypt passwords, I know owners of several who have been able to view passwords and provide them if I forgot.

In my opinion Bill sent this out in a shameless effort to bring awareness to his auction, not understanding the severity of sending out passwords unencrypted to an email.

Based on his this happened, Bob ported over Goodwin's old info to a new website or Bill kept one for his records.

I am sure Beckett would love to hear about this.
Reply With Quote
  #16  
Old 03-20-2020, 01:14 PM
Republicaninmass Republicaninmass is offline
T3d $h3rm@n
Member
 
Join Date: May 2009
Posts: 8,569
Default

Assume the non-compete is over
__________________
"Trolling Ebay right now" ©

Always looking for signed 1952 topps as well as variations and errors
Reply With Quote
  #17  
Old 03-20-2020, 01:22 PM
Jim VB's Avatar
Jim VB Jim VB is offline
Jim VB
Member
 
Join Date: Apr 2009
Posts: 2,090
Default

Quote:
Originally Posted by Sean1125 View Post
There is no breach.

Simpleauctionsite does not encrypt passwords, I know owners of several who have been able to view passwords and provide them if I forgot.

In my opinion Bill sent this out in a shameless effort to bring awareness to his auction, not understanding the severity of sending out passwords unencrypted to an email.

Based on his this happened, Bob ported over Goodwin's old info to a new website or Bill kept one for his records.

I am sure Beckett would love to hear about this.

I’ve spoken to two other auction houses who use SimpleAuctionSite.com. They both told me they do not have access to passwords. If you forget a password and ask them to help, all they can do is give you a “Reset Password” link.

Now, it’s possible that this is one of those options that Bob can turn on or off for each auction house. (Like he has admitted he can do with the visibility of max bids.) If so, the first breach is theirs, by giving/selling that info to Goodwin. The second breach is Bill’s by publishing it in unencrypted fashion in an email.
__________________
Jim Van Brunt
Reply With Quote
  #18  
Old 03-20-2020, 01:24 PM
sb1 sb1 is offline
Member
 
Join Date: Apr 2009
Posts: 3,201
Default

[QUOTE=Sean1125;1963574]There is no breach.

Simpleauctionsite does not encrypt passwords, I know owners of several who have been able to view passwords and provide them if I forgot.

This is false....

I can not see any ones password on my admin page for Simple Auctions. I can not even see how many characters there are to even begin to assist anyone in remembering their password. I can only send a password reset.
Reply With Quote
  #19  
Old 03-20-2020, 01:27 PM
bbcard1 bbcard1 is offline
T0dd M@rcum
Member
 
Join Date: Jul 2009
Location: Roanoke, VA
Posts: 3,415
Default

There was a time when the least secure thing you could do was write your password down and put it beside your computer. Now it's probably the safest place for your password to be.
Reply With Quote
  #20  
Old 03-20-2020, 01:33 PM
Leon's Avatar
Leon Leon is offline
Leon
peasant/forum owner
 
Join Date: Mar 2009
Location: near Dallas
Posts: 35,617
Default

Quote:
Originally Posted by bbcard1 View Post
There was a time when the least secure thing you could do was write your password down and put it beside your computer. Now it's probably the safest place for your password to be.
I have my computer lock password taped to the bottom of my screen . Never been a problem. It is a 23" LCD at home, of course.
__________________
Leon Luckey
www.luckeycards.com

Last edited by Leon; 03-20-2020 at 01:34 PM.
Reply With Quote
  #21  
Old 03-20-2020, 01:37 PM
Den*nis O*Brien Den*nis O*Brien is offline
Den*nis O*Brien
Member
 
Join Date: Nov 2009
Location: Northern Wisconsin
Posts: 493
Default I Also..

..got the same email this AM. It looked so "Fishy" that I did not even open it...straight to delete. I am thankful to the OP and the other respondents that put me informed on this. I always had good phone contacts with Bill Goodwin on items in his past auctions. Always the low $ stuff but he was very helpful. But this is inexcusable and in this competitive market I do not need reckless and careless houses putting me at risk. Both parties are off of my list of places to do business with. Once again the Net54 community was vigilant and helpful in keeping us informed. Thank you...

Sincerely, Dennis O'Brien ( Name as per the rules on these matters...I think)
Reply With Quote
  #22  
Old 03-20-2020, 01:43 PM
the-illini's Avatar
the-illini the-illini is offline
C.hris Bl.and
Member
 
Join Date: Apr 2009
Location: Champaign IL
Posts: 887
Default

An unencrypted password is not a password; it is basically useless from a data integrity perspective.
__________________
Looking for:

Type 1 photos of baseball HOFers
N172 Old Judge Portraits


Will buy or trade for the above. Check out my cards at:

www.imageevent.com/crb972
Reply With Quote
  #23  
Old 03-20-2020, 02:04 PM
conor912's Avatar
conor912 conor912 is offline
C0nor D0na.hue
 
Join Date: Feb 2012
Posts: 3,269
Default

Piss poor form by Goodwin. The subject line “your username and password” almost makes it comical, it’s that stupid.
__________________
Items for sale or trade here UPDATED 3-16-18
Reply With Quote
  #24  
Old 03-20-2020, 02:40 PM
mechanicalman's Avatar
mechanicalman mechanicalman is offline
Sam Sw@rtz
Member
 
Join Date: Mar 2015
Posts: 1,136
Default

When I saw an email address "bill@___," I thought, shoot, what I am getting a bill for?
Reply With Quote
  #25  
Old 03-20-2020, 03:13 PM
daves_resale_shop's Avatar
daves_resale_shop daves_resale_shop is offline
David Linardy
Member
 
Join Date: Aug 2011
Location: Southport, CT
Posts: 3,191
Default Email

does anyone have a screenshot of the email. May be a spoof attempt to compromise the recipient, and not necessarily a data leak from goodwin... i’d be very careful in investigating the situation prior to ruling it a breach.

David linardy
Reply With Quote
  #26  
Old 03-20-2020, 03:42 PM
buymycards's Avatar
buymycards buymycards is offline
Rick McQuillan
Member
 
Join Date: May 2009
Location: Wisconsin
Posts: 3,178
Default Screen shot

Quote:
Originally Posted by daves_resale_shop View Post
does anyone have a screenshot of the email. May be a spoof attempt to compromise the recipient, and not necessarily a data leak from goodwin... i’d be very careful in investigating the situation prior to ruling it a breach.

David linardy


Username and Password
Inbox
x

bill@go-heartland.com
8:15 AM (8 hours ago)
to me

Welcome to Bill Goodwin's Heartland Sports Auctions

Our first auction starts tomorrow, Saturday March 21 and ends Thursday April 9.

Here are your credentials to log in to your account along with a link for the Go-Heartland site.

Username: deleted
Password: deleted
Link: https://go-heartland.com/

Feel free to update any information such as your address, or update your username and/or password if you would like.

Thank you,

Bill Goodwin
Heartland Auctions
314-849-9798
Go-Heartland.com
__________________
Rick McQuillan


T213-2 139 down 46 to go.
Reply With Quote
  #27  
Old 03-20-2020, 05:23 PM
daves_resale_shop's Avatar
daves_resale_shop daves_resale_shop is offline
David Linardy
Member
 
Join Date: Aug 2011
Location: Southport, CT
Posts: 3,191
Default

Quote:
Originally Posted by buymycards View Post
Username and Password
Inbox
x

bill@go-heartland.com
8:15 AM (8 hours ago)
to me

Welcome to Bill Goodwin's Heartland Sports Auctions

Our first auction starts tomorrow, Saturday March 21 and ends Thursday April 9.

Here are your credentials to log in to your account along with a link for the Go-Heartland site.

Username: deleted
Password: deleted
Link: https://go-heartland.com/

Feel free to update any information such as your address, or update your username and/or password if you would like.

Thank you,

Bill Goodwin
Heartland Auctions
314-849-9798
Go-Heartland.com
Thanks for that Rick,

Now I follow.
Reply With Quote
  #28  
Old 03-20-2020, 05:30 PM
NATCARD NATCARD is offline
Jeff Weisenberg
Member
 
Join Date: Aug 2009
Location: Massachusetts
Posts: 468
Default User name and Passowrd

I use Simple Auction Site for my auctions. I can see all of my customers User id's and passwords. If they were to call and ask for their password I can give it to them. It also has the ability to send a reset password email which is much safer. Thanks, Jeff W (National Card Investors)
Reply With Quote
  #29  
Old 03-20-2020, 05:49 PM
sb1 sb1 is offline
Member
 
Join Date: Apr 2009
Posts: 3,201
Default

Odd.... then it must be an option for the administrator. I certainly can't see that.
Reply With Quote
  #30  
Old 03-20-2020, 05:57 PM
Aquarian Sports Cards Aquarian Sports Cards is offline
Scott Russell
Member
 
Join Date: Jun 2016
Location: Pennsylvania
Posts: 6,955
Default

It's a big problem for an auction to have access to user passwords. It really is carte blanche to do whatever they want. Not saying that any particular company would do something unethical, but the opportunity should not be there.
__________________
Check out https://www.thecollectorconnection.com Always looking for consignments 717.327.8915 We sell your less expensive pre-war cards individually instead of in bulk lots to make YOU the most money possible!

and Facebook: https://www.facebook.com/thecollectorconnectionauctions
Reply With Quote
  #31  
Old 03-20-2020, 06:36 PM
Sean's Avatar
Sean Sean is offline
Sean Costello
Member
 
Join Date: Dec 2012
Location: Woodland, California
Posts: 3,823
Default

I don't know whether to be insulted or grateful that I didn't get an email from Bill.
Reply With Quote
  #32  
Old 03-20-2020, 06:52 PM
Leon's Avatar
Leon Leon is offline
Leon
peasant/forum owner
 
Join Date: Mar 2009
Location: near Dallas
Posts: 35,617
Default

Quote:
Originally Posted by sb1 View Post
Odd.... then it must be an option for the administrator. I certainly can't see that.
I believe it was/is an option. I am sure we, when we ran the auctions together, chose the option to not see anyone's passwords or up to bids. My guess is that followed you to your new company.
__________________
Leon Luckey
www.luckeycards.com
Reply With Quote
  #33  
Old 03-20-2020, 07:14 PM
bcornell bcornell is offline
Ⓑⓘⓛⓛ Ⓒⓞⓡⓝⓔⓛⓛ
Member
 
Join Date: May 2009
Location: SJC
Posts: 393
Default

Quote:
Originally Posted by NATCARD View Post
I use Simple Auction Site for my auctions. I can see all of my customers User id's and passwords. Thanks, Jeff W (National Card Investors)
Thanks for confirming this, Jeff.

It is completely unacceptable for the SimpleAuctionSite and Barnebys.com (their parent company) to allow passwords to be stored in clear text and to allow auction site owners to optionally see them. It's not an oversight or "not a big deal". This is a complicit, lazy, unacceptable breach of data security.

The list of sports auctions sites using their software is long. You can easily check this by looking at the footer of any page on a site. If it shows the SimplyAuctionSite logo, you can assume that your username and password are NOT private.

If the excuse is "it wasn't malicious", then the answer is that it's incompetence. They can choose. Bob Freedman and SimplyAuctionSite, get this fixed tomorrow.

Last edited by bcornell; 03-20-2020 at 07:21 PM.
Reply With Quote
  #34  
Old 03-20-2020, 07:16 PM
Phil68's Avatar
Phil68 Phil68 is offline
Phil Apostle
Ph,il Ap0stle
 
Join Date: Nov 2019
Location: Midwest
Posts: 527
Default

Is it possible it was a simple mistake by Bill or his administrator?
I got the email and was stupid enough to think "cool, my login hasn't changed" as I am a regular Goodwin participant. After reading this thread, I can see how foolish I was.
I'd like to think Bill is a solid dude. Maybe it was an honest mistake--albeit a rather large one?
Reply With Quote
  #35  
Old 03-20-2020, 07:34 PM
swarmee's Avatar
swarmee swarmee is offline
J0hn Raff3rty
Member
 
Join Date: Jul 2014
Location: Niceville FL
Posts: 7,264
Default

This would definitely be good information for the FBI (as it pertains to possible likelihood of shilling) and the Cyber Security feds to have. Shouldn't everyone involved in this be notified and given the option for oversight of their online accounts from the various credit tracking agencies?
I would recommend that you who have been notified by email forward it to the proper authorities.
__________________
--
PWCC: The Fish Stinks From the Head
PSA: Regularly Get Cheated
BGS: Can't detect trimming on modern
SGC: Closed auto authentication business
JSA: Approved same T206 Autos before SGC
Oh, what a difference a year makes.
Reply With Quote
  #36  
Old 03-20-2020, 07:41 PM
prestigecollectibles's Avatar
prestigecollectibles prestigecollectibles is offline
Robert Klevens
Member
 
Join Date: May 2009
Location: Lauderhill, FL
Posts: 746
Default

We use createauction.com, the same platform used by REA, Memory Lane, Lelands and others. We can't see user passwords or autobids.
Reply With Quote
  #37  
Old 03-20-2020, 08:09 PM
Phil68's Avatar
Phil68 Phil68 is offline
Phil Apostle
Ph,il Ap0stle
 
Join Date: Nov 2019
Location: Midwest
Posts: 527
Default

Quote:
Originally Posted by swarmee View Post
This would definitely be good information for the FBI (as it pertains to possible likelihood of shilling) and the Cyber Security feds to have. Shouldn't everyone involved in this be notified and given the option for oversight of their online accounts from the various credit tracking agencies?
I would recommend that you who have been notified by email forward it to the proper authorities.
John,
They have it.
Reply With Quote
  #38  
Old 03-20-2020, 08:46 PM
doug.goodman doug.goodman is offline
Doug Goodman
Member
 
Join Date: Apr 2009
Location: On the road again...
Posts: 5,107
Default

Quote:
Originally Posted by bcornell View Post
Thanks for confirming this, Jeff.

It is completely unacceptable for the SimpleAuctionSite and Barnebys.com (their parent company) to allow passwords to be stored in clear text and to allow auction site owners to optionally see them. It's not an oversight or "not a big deal". This is a complicit, lazy, unacceptable breach of data security.

The list of sports auctions sites using their software is long. You can easily check this by looking at the footer of any page on a site. If it shows the SimplyAuctionSite logo, you can assume that your username and password are NOT private.

If the excuse is "it wasn't malicious", then the answer is that it's incompetence. They can choose. Bob Freedman and SimplyAuctionSite, get this fixed tomorrow.
I agree.
Reply With Quote
  #39  
Old 03-20-2020, 08:50 PM
RedsFan1941 RedsFan1941 is offline
Banned
 
Join Date: Feb 2016
Posts: 1,207
Default

i am not expecting either bill Goodwin or bob freedman to come on the board and explain anything.
Reply With Quote
  #40  
Old 03-20-2020, 09:08 PM
bcornell bcornell is offline
Ⓑⓘⓛⓛ Ⓒⓞⓡⓝⓔⓛⓛ
Member
 
Join Date: May 2009
Location: SJC
Posts: 393
Default

Quote:
Originally Posted by RedsFan1941 View Post
i am not expecting either bill Goodwin or bob freedman to come on the board and explain anything.
Nope, Ronnie, they won't. That's why I contacted both directly, as well as Barnebys.com, the Swedish outfit that bought SimpleAuctionSite to let them know what they did wrong, why it's wrong, and how they have to fix it immediately.

I realize you think you're smarter than everyone else. That comes through in all your snarky, know-it-all posts. Some of them are even funny, although mostly they're just predictable and boring. Who are you, anyway?
Reply With Quote
  #41  
Old 03-20-2020, 09:28 PM
Jobu's Avatar
Jobu Jobu is offline
Bry@n
member
 
Join Date: Jul 2014
Location: WI
Posts: 3,822
Default

The grand kids are probably happy though, now that they are in their 20s it is tough spending so much time there.

Quote:
Originally Posted by ullmandds View Post
he must be upset that disney is closed?
Reply With Quote
  #42  
Old 03-21-2020, 01:31 AM
Stampsfan's Avatar
Stampsfan Stampsfan is offline
Bob Davies
Member
 
Join Date: Jul 2015
Location: Calgary, Alberta, Canada
Posts: 1,141
Default

As a now retired IT professional, this is absolutely shocking. I would not be doing business with anyone who does not use some kind of encryption for their clients passwords. Not acceptable in any way.

I've always suspected that bids are known to many auction sites, as that can be raw data that anyone with a modicum of SQL skills could find... but this is on another level.

Any auction house using Simple Auction Site is now off my bid list.

Thanks for sharing.
__________________
Successful transactions on Net54 with balltrash, greenmonster66; Peter_Spaeth; robw1959; Stetson_1883; boxcar18; Blackie

Last edited by Stampsfan; 03-21-2020 at 01:32 AM.
Reply With Quote
  #43  
Old 03-21-2020, 07:10 AM
Buythatcard's Avatar
Buythatcard Buythatcard is offline
Howard Chernick
Member
 
Join Date: May 2009
Location: Middlesex, NJ
Posts: 1,658
Default

Because of this thread, he received free advertising.

All of you who didn't know about the upcoming auction, now do.
__________________
Please visit my eBay store:

Buythatcard

http://stores.ebay.com/Buythatcard
Reply With Quote
  #44  
Old 03-21-2020, 07:11 AM
NATCARD NATCARD is offline
Jeff Weisenberg
Member
 
Join Date: Aug 2009
Location: Massachusetts
Posts: 468
Default passwords and ids

As I woke up and read the continued thread I can not think of the last time anyone asked me for this info. Maybe back in the day before I used Simple Auction site when i used dry erase boards and took bids mostly by phone (back in 2009 and before). I see no reason to have access to any of this information and agree it should be blocked. If you forget you user password, GET A NEW ONE!
Reply With Quote
  #45  
Old 03-21-2020, 09:53 AM
Jim VB's Avatar
Jim VB Jim VB is offline
Jim VB
Member
 
Join Date: Apr 2009
Posts: 2,090
Default

Quote:
Originally Posted by Stampsfan View Post

Any auction house using Simple Auction Site is now off my bid list.

Thanks for sharing.

I think that’s probably a step too far, at least for now. Most of the auction house owners I know are honest guys. Several have told me they have never had access to passwords. Others have cleared it up and said it’s an option that SimpleAuctionSite.com can turn on or off. Obviously Bill Goodwin had it turned on.

What needs to happen is that Freedman needs to confirm it’s an option.

Then the various auctions houses using his software need to make clear that they do, or do not, have access to this info.

Then, old time auctioneers, like Bill Goodwin, need to stay far, far away from technology they don’t understand! Anyone who sends out plain text, unencrypted, passwords in emails shouldn’t be trusted with your info.
__________________
Jim Van Brunt
Reply With Quote
  #46  
Old 03-21-2020, 11:30 AM
the-illini's Avatar
the-illini the-illini is offline
C.hris Bl.and
Member
 
Join Date: Apr 2009
Location: Champaign IL
Posts: 887
Default

Quote:
Originally Posted by Jim VB View Post
I think that’s probably a step too far, at least for now. Most of the auction house owners I know are honest guys. Several have told me they have never had access to passwords. Others have cleared it up and said it’s an option that SimpleAuctionSite.com can turn on or off. Obviously Bill Goodwin had it turned on.

What needs to happen is that Freedman needs to confirm it’s an option.

Then the various auctions houses using his software need to make clear that they do, or do not, have access to this info.

Then, old time auctioneers, like Bill Goodwin, need to stay far, far away from technology they don’t understand! Anyone who sends out plain text, unencrypted, passwords in emails shouldn’t be trusted with your info.
Thing is, SimpleAuctionSite shouldn't have the ability to turn access to passwords on or off either.
__________________
Looking for:

Type 1 photos of baseball HOFers
N172 Old Judge Portraits


Will buy or trade for the above. Check out my cards at:

www.imageevent.com/crb972
Reply With Quote
  #47  
Old 03-21-2020, 03:33 PM
whiteymet whiteymet is offline
Fr3d mcKi3
Member
 
Join Date: Jul 2009
Location: whiteymet
Posts: 2,171
Default

I too received the email with my password and user ID.

Is there any thought to when I opened the link my computer could have been infected?
Reply With Quote
  #48  
Old 03-21-2020, 04:37 PM
edhans's Avatar
edhans edhans is offline
Ed Hans
Member
 
Join Date: Apr 2009
Location: Buffalo, N.Y.
Posts: 1,301
Default

Quote:
Originally Posted by whiteymet View Post
Is there any thought to when I opened the link my computer could have been infected?
There was no link in the email I received.
__________________
Please visit my website at http://t206.monkberry.com/index.html
Reply With Quote
  #49  
Old 03-21-2020, 04:49 PM
3-2-count's Avatar
3-2-count 3-2-count is online now
T0NY @
Member
 
Join Date: Apr 2009
Posts: 1,958
Default

Quote:
Originally Posted by edhans View Post
There was no link in the email I received.
There was in mine. Directly under my user name and PW.
__________________
Tony A.
Reply With Quote
  #50  
Old 03-21-2020, 05:31 PM
edhans's Avatar
edhans edhans is offline
Ed Hans
Member
 
Join Date: Apr 2009
Location: Buffalo, N.Y.
Posts: 1,301
Default

Quote:
Originally Posted by 3-2-count View Post
There was in mine. Directly under my user name and PW.
The "link" was not live; that is, clicking on it would not take you directly to the website. I had to key the url into my browser. FWIW I didn't log in anyway. Was your email different?
__________________
Please visit my website at http://t206.monkberry.com/index.html
Reply With Quote
Reply




Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Has anyone been able to reach Bill Goodwin? Blunder19 Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 33 09-18-2013 02:29 PM
Chatted With Bill Goodwin Today GregMitch34 Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 42 06-09-2013 08:49 AM
Anyone speak or hear from bill goodwin in last 10 days??? forazzurri2axz Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 11 03-07-2011 07:05 PM
Special Thanks To Bill Goodwin Archive Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 5 03-24-2009 06:32 AM
Bill Goodwin's e-mail addy please? Archive Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 2 11-04-2007 09:11 PM


All times are GMT -6. The time now is 06:26 PM.


ebay GSB