Skip to navigation
Latest News

PhotoBox sorry after email "screw up"

PhotoBox

By Nicole Kobie

Posted on 9 Aug 2010 at 17:25

PhotoBox has apologised for sending customers email marketing messages with user names and passwords in plain text.

The photo printing site apparently sent the emails to customers who haven't ordered for a while, raising security concerns by including unencrypted password details.

Some customers took to Twitter to complain about the email. "I was just emailed my password in plain text by PhotoBox, when I didn't request it," asked one customer. "Does that mean they also store them unencrypted?"

Another echoed those thoughts: "Surprised that PhotoBox send out random emails with account passwords in plain text, front and centre. Not great security practice, surely?"

Over on Facebook one user said: "I just closed my account with you guys because you sent me my password in plain text. That is incredibly bad security."

On the PhotoBox Twitter feed, the firm apologised: "We really screwed up today and we're really sorry. It will never happen again and we're genuinely sorry for letting some of you down."

Subscribe to PC Pro magazine. We'll give you 3 issues for £1 plus a free gift - click here

From around the web

User comments

So what?

What am I going to do with your Photobox id & pw? Send in my photos and get them sent to your house? I doubt this compromises payment / your card details.

As usual some people have reacted as if it's the end of the world. It's careless but Photobox have apologised and there's no harm done.

JH

By JohnHo1 on 9 Aug 2010

Jlbrad

I got sent my u/name & password - agreed careless but actually ended up being useful... I went back on to Photo Box and ordered all my recent travel snaps... Cant wait for my Photobook.

By jldeaks on 9 Aug 2010

Excellent opportunity to close my account. They've got brownie points from me just allowing you to do that. But I'm afraid I just don't use them anymore, and I'd completely forgotten about my account. This was the proverbial last straw.

By c6ten on 9 Aug 2010

Password security is important

JohnHo1 says, so what?
It is well known that rightly or wrongly, a lot of people use the same password for different websites, and some people, even for banking sites, so revealing passwords by email, or having unencripted passwords stored on any system, is not acceptable.

By giltbrook on 10 Aug 2010

Can store passwords but not your photo credits?

I stopped using them when they introduced a time limit on their photo credits in order to screw more out of their customers.

If they can store my username and password for three years, I see no reason why they cant store an integer to hold the number of credits I have paid them for but not used!

By Fraz_pro on 10 Aug 2010

That's strange!

Is this the same company that the current PC Pro gave a 5 star review and described as "a great all round service"?

By ironbath on 10 Aug 2010

Can store passwords but not your photo credits?

I stopped using them when they introduced a time limit on their photo credits in order to screw more out of their customers.

If they can store my username and password for three years, I see no reason why they cant store an integer to hold the number of credits I have paid them for but not used!

By Fraz_pro on 10 Aug 2010

Leave a comment

You need to Login or Register to comment.

(optional)

advertisement

Most Commented News Stories
More From PC Pro
Latest Blog Posts Subscribe to our RSS Feeds
Latest ReviewsSubscribe to our RSS Feeds
Latest Real World Computing

advertisement

Sponsored Links
 
SEARCH
SIGN UP

Your email:

Your password:

remember me

advertisement


Hitwise Top 10 Website 2010
 
 

PCPro-Computing in the Real World Printed from www.pcpro.co.uk

Register to receive our regular email newsletter at http://www.pcpro.co.uk/registration.

The newsletter contains links to our latest PC news, product reviews, features and how-to guides, plus special offers and competitions.