Quantcast
NCIX data breach - Beyond.ca - Car Forums
Page 1 of 2 1 2 LastLast
Results 1 to 20 of 40

Thread: NCIX data breach

  1. #1
    Join Date
    Jan 2004
    Location
    Calgary, Alberta
    My Ride
    Bicycle
    Posts
    9,277
    Rep Power
    49

    Default NCIX data breach

    https://www.privacyfly.com/articles/ncix_breach/#three

    Watch for your transactions if you ever did business with them.

  2. #2
    Join Date
    Sep 2008
    Location
    Calgary
    My Ride
    Turbo stuff
    Posts
    3,408
    Rep Power
    70

    Default

    Haven't ordered from them in a decade. That's pretty crazy though, guess they didn't give a fuck after going bankrupt and just fire sale'd all their shit without wiping it.

  3. #3
    Join Date
    Sep 2008
    Location
    Calgary
    My Ride
    Turbo stuff
    Posts
    3,408
    Rep Power
    70

    Default

    The examination portion of the meeting began to wind-down as time flew by and Jeff jumped into brokering a deal over a cup of tea. The first offer was thirty-five thousand dollars which would allow me to purchase all the desktop’s and server hardware, excluding one group of hard drives that I had analyzed which he would allow me to copy. This struck me as strange and I inquired as to why I couldn’t purchase those drives. He explained that those drives and the data on them had already sold for around fifteen thousand dollars to a foreign buyer who was arriving in Vancouver to acquire them in December. “December” I quipped in questioning tone which, prompted Jeff to explain that even though the buyer was picking up the physical drives in December. Jeff had already copied the data from those drives to a network storage device and allowed the buyers remote access. The data on those drives contained thirteen terabytes of SQL databases and various VHD and Xen server backup files. I cringed at the thought of that data being sold once, as it was dangerous enough when during further conversation Jeff mentioned at least five other buyers. Jeff described one as a completing retailer while the other three Jeff claimed to “Not Want to Know” their intentions or business. Armed with the knowledge that Jeff was willing to sell the data without all the hardware attached to the deal, I mentioned that I had little use for hardware which prompted him to make a considerably shadier proposal. Jeff stated that I could pay fifteen thousand dollars to copy all the data from the hard drives including the ones that he had previously sold. This scenario would playout with my employer paying fifteen thousand dollars to “Rent the Room” and he would provide me with a couple of desks and some servers to image all the data onto my own drives. Jeff and I tentatively agreed on the second deal and I quickly exited the warehouse.

    On my way out, I couldn’t help but think about how Jeff boasted that he was able to “crack their ISCSI server with very simple tools in five minutes” and called their security “really, really, bad” and I would whole heartedly agree with him there. This entire scenario could have been avoided by simply implementing full disk encryption within their organization or destroying the drives as their bankruptcy loomed. NCIX founder Steve Wu worked in IT for many years and fully understood the risk involved in his choice not to encrypt any data and then the repercussions of him abandoning the assets in a warehouse. Mr. Wu’s reckless behavior has harmed every individual and business NCIX dealt with, by allowing millions of confidential records to be sold without any oversight to anonymous buyers. The data can easily be used to cash out credit cards, craft convincing phishing messages containing details on purchases and commit identity theft.
    I wouldn't at all be surprised if Steve Wu was in on this sale of data, now that the company is sunk. This story is just breaking so it could be interesting to see how it plays out.

  4. #4
    Join Date
    Jan 2004
    Location
    Calgary, Alberta
    My Ride
    Bicycle
    Posts
    9,277
    Rep Power
    49

    Default

    Quote Originally Posted by Sentry View Post
    This quote is hidden because you are ignoring this member. Show Quote
    Haven't ordered from them in a decade. That's pretty crazy though, guess they didn't give a fuck after going bankrupt and just fire sale'd all their shit without wiping it.
    Sounds like the DB goes back to to 2005. Also there are tons of employee SIN numbers exposed with T4 and such as well.

    August 21st, 2018. Twenty days had passed since my inquiry when I received the following response, “sorry for replying late, it has the data. it's unerased server contents.” The seller proceeds to inform me that he has three NCIX servers for sale for which he has the passwords required to login. These series of messages immediately renewed my curiosity and we arranged to meet in person to inspect the data on August 25th, 2018.

    August 25th, 2018. I arrived to the agreed upon address, a warehouse in Richmond, British Columbia. I met an Asian man in his mid-thirties who identified himself as Jeff. He led me up a flight of stairs above the warehouse into a nearly empty office with cheap laminate flooring. The office contained three rooms. The first housed nothing but a child’s play mat. The second, a main room contained two cheap folding tables, some chairs and a tea stand. The third was sporting a bed, various electronics equipment and a NCIX Server propped up on a folding table in what I can only describe as feeling unsettlingly transient. I remember the thought crossing my mind that this was the kind of room someone could “disappear” in. Those thoughts were quickly dashed as Jeff’s young son came into the room, which put me at ease while also making me question why he would bring this son along on this deal.
    Sounds like Jeff got the password. So either it got sold with auction or "Jeff" used to work for NCIX and stole the gear.

  5. #5
    Join Date
    Sep 2008
    Location
    Calgary
    My Ride
    Turbo stuff
    Posts
    3,408
    Rep Power
    70

    Default

    Yeah the thing is, I no longer live at the billing address used and the credit card used expired ages and ages ago lol. So I'm probably safe.

    EDIT: I'm having fun going through my old orders on gmail and getting nostalgic though.
    Last edited by Sentry; 09-20-2018 at 03:48 PM.

  6. #6
    Join Date
    Aug 2011
    Location
    Strathmore
    My Ride
    2005 Dirtymax
    Posts
    2,222
    Rep Power
    22

    Default

    This is not good news for people like myself. As I was both an employee AND customer *sigh*

    Will be watching shit closely for awhile.

  7. #7
    Join Date
    Jan 1970
    Location
    YYC
    My Ride
    1 x E Class Benz
    Posts
    23,608
    Rep Power
    101

    Default

    Ordered tons of shit through them, somehow I setup my first payment via PayPal in 2009 and only paid that way because I was lazy.
    Originally posted by SEANBANERJEE
    I have gone above and beyond what I should rightfully have to do to protect my good name

  8. #8
    Join Date
    Oct 2005
    Location
    Calgary
    My Ride
    Grimace
    Posts
    6,816
    Rep Power
    26

    Default

    My last payments in 2016 and 2017 were all paypal, but since it seemingly goes back forever I will watch my mastercard which it looks like I used once as well.

  9. #9
    Join Date
    Jan 2004
    Location
    Calgary, Alberta
    My Ride
    Bicycle
    Posts
    9,277
    Rep Power
    49

    Default

    Quote Originally Posted by rage2 View Post
    This quote is hidden because you are ignoring this member. Show Quote
    Ordered tons of shit through them, somehow I setup my first payment via PayPal in 2009 and only paid that way because I was lazy.
    Same here, so other than shipping address, I could care less.

  10. #10
    Join Date
    Sep 2008
    Location
    Calgary
    My Ride
    Turbo stuff
    Posts
    3,408
    Rep Power
    70

    Default

    Yeah mine was only ever through paypal, from 2005-2009. Then I moved to Calgary and discovered Memex. Check out this absolute beauty of a build I did in 2008.
    Name:  gfgfgf.jpg
Views: 436
Size:  60.7 KB

  11. #11
    Join Date
    Jul 2008
    Location
    Pallet Town
    Posts
    814
    Rep Power
    0

    Default

    I guess they know now that I used an 8800GT for eight years without upgrading. Yup, choices were a little more limited back then as a computer enthusiast - NCIX and Newegg (also data breached) were both go to places for tech.
    Cocoa $10,000 per ton.

  12. #12
    Join Date
    Jun 1987
    Location
    SK
    My Ride
    Fit Dugan Signature (2016)
    Posts
    3,375
    Rep Power
    100

    Default

    Quote Originally Posted by ZenOps View Post
    This quote is hidden because you are ignoring this member. Show Quote
    I guess they know now that I used an 8800GT for eight years without upgrading. Yup, choices were a little more limited back then as a computer enthusiast - NCIX and Newegg (also data breached) were both go to places for tech.
    https://www.skyandtelescope.com/obse...landing-sites/
    Originally posted by SJW
    Once again another useless post by JRSCOOLDUDE.
    Originally posted by snowcat
    Don't let the e-thugs and faggots get to you when they quote your posts and write stupid shit.
    Originally posted by JRSC00LUDE
    I say stupid shit all the time.
    ^^ Fact Checked

  13. #13
    Join Date
    Jul 2008
    Location
    Pallet Town
    Posts
    814
    Rep Power
    0

    Default

    Yup, when NASA finally had the ability to launch a vehicle that could accurately look at the surface of the moon (at least down to the meter) in 2009 is about the same time as when the 8800GT became popularized. By that timeline, it only took NASA 40 years to degrade to the point of only observing instead of actually doing.

    By my estimation, it took 10 years to increase graphics processing by a factor of 10x (1,000% faster) quite impressive given the obvious regression of space technology of the last 40 years.


    Side factoid: The LRO also did eventually find the Russian rover landing spot after about a year of searching the surface of the moon. I hear they actually employed actual humans to for thousands of hours to visually look at the pictures, instead of *totally* relying on the AI to find that needle in a haystack.

    https://www.universetoday.com/59881/...an-spacecraft/

    https://en.wikipedia.org/wiki/Lunokhod_2 Some say 2010 is when they spotted it, others say 2012.

    I think China should launch a LRO by 2050, so that they can attempt a manned moon mission with accurate data on landing spots - maybe by 2100. That is - when you don't have to bankrupt the entire nation to get a few moon rocks made of chalk.

    PS: I can say with 99.9% certainty that the USA did manage to launch a spacecraft capable of taking pictures of the moon from orbit in 2009. No conspiracy there, it is quite a technical and fully realistic achievement. And is a cautious first step - to landing a donkey on the moon.



    I'd like to thank NCIX for selling me that 8800GT, it has served me well for nearly a decade of flesh tone and moon based image viewing :P
    Last edited by ZenOps; 09-21-2018 at 08:03 PM.
    Cocoa $10,000 per ton.

  14. #14
    Join Date
    Jan 2004
    Location
    Calgary, Alberta
    My Ride
    Bicycle
    Posts
    9,277
    Rep Power
    49

    Default

    https://www.cbc.ca/news/canada/briti...each-1.4833976

    RCMP recovered hardware, investigation started.

  15. #15
    Join Date
    Aug 2011
    Location
    Strathmore
    My Ride
    2005 Dirtymax
    Posts
    2,222
    Rep Power
    22

    Default

    This forum was started by a NCIX employee and a lot of the members are either ex employees or customers. Interesting thread.

    https://www.hardwarecanucks.com/foru...000-users.html

  16. #16
    Join Date
    Jan 1970
    Location
    YYC
    My Ride
    1 x E Class Benz
    Posts
    23,608
    Rep Power
    101

    Default

    Well the NCIX data is clearly out there. Got this email this AM, complete with the correct unique password I used on NCIX.

    Name:  ncix.jpg
Views: 354
Size:  107.6 KB

    Guy's right, I do have great taste in porn.
    Originally posted by SEANBANERJEE
    I have gone above and beyond what I should rightfully have to do to protect my good name

  17. #17
    Join Date
    Aug 2011
    Location
    Strathmore
    My Ride
    2005 Dirtymax
    Posts
    2,222
    Rep Power
    22

    Default

    Quote Originally Posted by rage2 View Post
    This quote is hidden because you are ignoring this member. Show Quote
    Well the NCIX data is clearly out there. Got this email this AM, complete with the correct unique password I used on NCIX.

    Name:  ncix.jpg
Views: 354
Size:  107.6 KB

    Guy's right, I do have great taste in porn.
    Oh shit?!

  18. #18
    Join Date
    Jul 2010
    Location
    Homeless
    My Ride
    Blue Dabadee
    Posts
    9,664
    Rep Power
    100

    Default

    Lol that’s some great software he’s got there!
    Originally posted by Thales of Miletus

    If you think I have been trying to present myself as intellectually superior, then you truly are a dimwit.
    Originally posted by Toma
    fact.
    Quote Originally Posted by Yolobimmer View Post
    This quote is hidden because you are ignoring this member. Show Quote

    guessing who I might be, psychologizing me with your non existent degree.

  19. #19
    Join Date
    Apr 2006
    Location
    Cowtown
    My Ride
    10' 4Runner SR5
    Posts
    6,363
    Rep Power
    59

    Default

    Wow that's fucked.
    Ultracrepidarian

  20. #20
    Join Date
    Sep 2008
    Location
    Calgary
    My Ride
    Turbo stuff
    Posts
    3,408
    Rep Power
    70

    Default

    What was the subject? So we know what to look for in our inboxes. Or was it just your password as the subject?

Page 1 of 2 1 2 LastLast

Similar Threads

  1. Yahoo data breach - 500million compromised

    By AndyL in forum Society / Law / Current Events / Politics
    Replies: 15
    Latest Threads: 09-23-2016, 10:36 AM
  2. APEGA Data Breach

    By schurchill39 in forum Careers
    Replies: 24
    Latest Threads: 10-05-2015, 03:17 PM
  3. Data usage while travelling. Roaming off. Cell Data off. Still uses data. iPhone 6+

    By benyl in forum Computers, Consoles, and other Electronics
    Replies: 41
    Latest Threads: 02-04-2015, 05:01 PM
  4. NCIX Boxing day Sale

    By natejj in forum Computers, Consoles, and other Electronics
    Replies: 0
    Latest Threads: 12-24-2007, 06:45 PM
  5. Logitech G25 on sale @ NCIX

    By Kamen in forum Computers, Consoles, and other Electronics
    Replies: 1
    Latest Threads: 09-20-2007, 04:37 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •