Notices

Club reg hacked. PCA members beware !

Thread Tools
 
Search this Thread
 
Old 08-14-2018, 09:42 AM
  #1  
theiceman
Team Owner
Thread Starter
 
theiceman's Avatar
 
Join Date: Aug 2005
Location: Cambridge Ontario Canada
Posts: 26,664
Received 1,022 Likes on 727 Posts
Default Club reg hacked. PCA members beware !

I absolutely hated this when it came out . But we all had to sign up for a new service to make the clubs job easier. It has now become a nightmare for all the users. I mean I understand as the club grows it gets more difficult to manage. The reason they have not carved it up into smaller chapters is a discussion for another day , but I see it coming with more and more dealers opening ( Oakville, London North Toronto ) .

Anyhow it has been completely hacked and decrypted and your log on credentials are out there. I am not sure how well this organization was vetted security wise before PCA jumped into bed with them. Now it means changing all other passwords in your life that used the same credentials.

Seen very little leadership from the club so far on this on this so thought I would let everyone know who may have missed the email .

Extremely disappointed but it is what it is I guess.
Old 08-14-2018, 10:49 AM
  #2  
911 Rod
Race Car
 
911 Rod's Avatar
 
Join Date: Aug 2005
Location: Terrorizing your neighbourhood!
Posts: 4,327
Received 287 Likes on 198 Posts
Default

I knew I should have put a piece of tape over my laptop camera lens. lol
Old 08-14-2018, 11:00 AM
  #3  
olegd
Rennlist Member
 
olegd's Avatar
 
Join Date: Oct 2016
Posts: 1,280
Received 206 Likes on 145 Posts
Default

Where you getting this from? No mention of this on ClubRegustration or PCA sites.
Old 08-14-2018, 11:39 AM
  #4  
burgerkong
Track Day
 
burgerkong's Avatar
 
Join Date: Jun 2017
Posts: 22
Received 3 Likes on 3 Posts
Default

Originally Posted by olegd
Where you getting this from? No mention of this on ClubRegustration or PCA sites.
Got an email this morning:

It has come to our attention that ClubRegistration.net's user list has been stolen. Some of you may have received an email containing a demand of funds. This is a fraudulent email.

Our user list is encrypted but the hackers were successful at decrypting our data. We have updated our servers and site security in response to this breach. ClubReg does NOT have access to your credit card or medical information. That information does not exist on our servers. Event payments are handled by a third party merchant account only.

We recommend that you update your login credentials on any other site where the username and password are the same as ClubReg. As a good practice we suggest that your ClubReg username and password be unique. If you need assistance changing this information please contact our office at 512-273-5016. We apologize for any inconvenience this may cause you.


Thank you,

Chris Alvarado
ClubRegistration.net
Old 08-14-2018, 12:26 PM
  #5  
wildcat077
Drifting
 
wildcat077's Avatar
 
Join Date: Apr 2009
Location: Montreal,Canada
Posts: 3,396
Received 188 Likes on 161 Posts
Default

Got the notification email as well today ... at least Club Reg is taking care of the issue !
Old 08-14-2018, 12:26 PM
  #6  
olegd
Rennlist Member
 
olegd's Avatar
 
Join Date: Oct 2016
Posts: 1,280
Received 206 Likes on 145 Posts
Default

I didn't get the email
Old 08-14-2018, 03:15 PM
  #7  
Bacura
Three Wheelin'
 
Bacura's Avatar
 
Join Date: Sep 2013
Posts: 1,710
Likes: 0
Received 10 Likes on 8 Posts
Default

I'm never registering on-line again for any PCA event. I just won't go.
Old 08-14-2018, 11:35 PM
  #8  
theiceman
Team Owner
Thread Starter
 
theiceman's Avatar
 
Join Date: Aug 2005
Location: Cambridge Ontario Canada
Posts: 26,664
Received 1,022 Likes on 727 Posts
Default

Thats why i shared the news, for those that may not have gotten or filtered the email
They mentioned it at tonights social.
"Just log on and change your password"

"Make sure everyone signs up who hasn't !! "

Seriously ??

Last edited by theiceman; 08-15-2018 at 08:42 AM.
Old 08-18-2018, 07:52 AM
  #9  
KLCC 88
Pro
 
KLCC 88's Avatar
 
Join Date: Apr 2015
Location: Toronto
Posts: 514
Received 99 Likes on 53 Posts
Default

Originally Posted by theiceman
Thats why i shared the news, for those that may not have gotten or filtered the email
They mentioned it at tonights social.
"Just log on and change your password"

"Make sure everyone signs up who hasn't !! "

Seriously ??
lol and she compared it when Facebook was hacked so this was not a big deal. Comparing this hack to Facebook? Lol FB probably has 10000x more members that quick and join per hour than PCA and especially UCR. She said “fb was hacked, are you going to stop using fb?”



Last edited by KLCC 88; 08-18-2018 at 08:01 AM. Reason: Autocorrect
Old 08-18-2018, 08:43 AM
  #10  
JTT
Rennlist Member
 
JTT's Avatar
 
Join Date: Jul 2015
Location: Halifax, NS. Canada
Posts: 2,145
Received 338 Likes on 246 Posts
Default

Originally Posted by Bacura
I'm never registering on-line again for any PCA event. I just won't go.
FYI, Rennlist got hacked too. Better get off here in a hurry. Change your password and move on, or disconnect from everything.
Old 08-18-2018, 08:54 AM
  #11  
Bacura
Three Wheelin'
 
Bacura's Avatar
 
Join Date: Sep 2013
Posts: 1,710
Likes: 0
Received 10 Likes on 8 Posts
Default

I don't really care about PCA registration or Rennlist registration. I use low level passwords for low level sites. And I also don't use FB. /shrug.
Old 08-18-2018, 10:16 PM
  #12  
Christien
Race Car
 
Christien's Avatar
 
Join Date: Nov 2004
Location: Hamilton, Ont. Canada
Posts: 4,856
Received 48 Likes on 33 Posts
Default

Originally Posted by Bacura
I use low level passwords for low level sites.
This. 100%.
Old 08-22-2018, 10:31 PM
  #13  
Turbodan
Rennlist Member
 
Turbodan's Avatar
 
Join Date: Jun 2006
Location: Toronto Canada eh!
Posts: 11,313
Received 488 Likes on 365 Posts
Default

I use unique passwords for each site...not necessarily complex, just unique. Anything can get hacked and does nowadays. If you are looking for an excuse to stop attending anything, you will find it. I enjoy many PCA gatherings, particularly ones that are held at a racetrack.
Old 08-25-2018, 02:48 AM
  #14  
na94
Advanced
 
na94's Avatar
 
Join Date: Nov 2017
Posts: 63
Received 0 Likes on 0 Posts
Default

They are not clear enough about passwords being compromised. Passwords should never be stored 'encrypted' - only a one-way fingerprint of it should bestored, and it had to be salted in a way that makes it extremely expensive in both computation and memory usage to try and brute-force guess.

Few services will store user information 'encrypted', but rather stored in a database with sufficient access controls. They only thing that could possibly encrypted is the auth passwords - but that would have been a foolish thing to do.



Quick Reply: Club reg hacked. PCA members beware !



All times are GMT -3. The time now is 11:17 PM.