Pages in topic:   < [1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24] >
Illegal use of data from ProZ.com profile
Thread poster: RoxanaTrad (X)
Henry Dotterer
Henry Dotterer
Local time: 23:44
SITE FOUNDER
Announcement made, notifications being sent Aug 6, 2009

Hi all,

The announcement has been made, notifications are now being sent.

The information page is here: http://www.proz.com/about/security

I'm really sorry about this, folks.

Henry


 
MariusV
MariusV  Identity Verified
Lithuania
Local time: 06:44
English to Lithuanian
+ ...
Don't quite get it... Aug 6, 2009

Henry D wrote:

Hi all,

The announcement has been made, notifications are now being sent.

The information page is here: http://www.proz.com/about/security

I'm really sorry about this, folks.

Henry


Dear Henry,

Just received an email from you. Quoting:

"This notice is to inform you that certain ProZ.com user
information was recently accessed improperly. Your profile may be
among those affected.

Among the forms of data accessed in the security breach were
name, email address, postal address and phone number. Login
information (usernames and passwords) was also accessed, though
passwords are protected by encryption. Other forms of information,
such as financial information, etc., were not accessed. (ProZ.com
does not store credit card information, etc.) "

Sorry, but I do not quite understand:

1) What do you mean by "may be affected"? Was it affected or not? Because this "may be" in this case sounds like "a little bit pregnant" instead of "yes" or "no";
2) "Security breach" - do you mean that I, as a member, breached the security, or was it someone else ("a third party, speaking in legal terms) which made this "security breach"?
3) "Financial information" - what do you mean exactly? There was no financial information on my profile (I am not that crazy yet)...
4) "Password was accessed", but "passwords are protected by encryption"...Well, if someone managed to "crack" my password (i.e. managed to know it), what other protection of passwords we can speak about?

All in all, I fully understand that Internet is such a place where no one is fully secure. And we, as proz members, undertake certain risks posting our info (and we are aware of that)...And Proz cannot neither technically nor even theoretically protect everyone against everyone or everything possible...

BUT (at the end) what I want to know:

1) Which country or USA state laws regarding personal data protection and related things Proz.com is subject to?
2) What are there the manatory requirements/regulations under these laws Proz.com has to implement?
3) What Proz.com actually does to implement these requirements/regulations and what "extra mile" Proz.com walked or intends to walk for non-mandatory requirements - for improving the security of its members and the general trust in Proz.com?

All in all, the only thing I expect from Proz.com is clarity. Starting from email messages (just to be able to understand what was actually intended to write) down to legal things related to personal data protection...


 
polyglot45
polyglot45
English to French
+ ...
I repeat what I said earlier Aug 6, 2009

Is it any wonder that some of use "hide" behind nicks and enter strictly NO personal data in our profiles ?
Mugs of the world unite ! You have nothing to lose but your identity.
Well it all scares the hell out of me ! What about private and public keys, about data protection and the like?
Quid Proz, I ask ?


 
Vito Smolej
Vito Smolej
Germany
Local time: 05:44
Member (2004)
English to Slovenian
+ ...
SITE LOCALIZER
++ Aug 6, 2009

ViktoriaG wrote:
...
Telling us that this is top priority and that you are making every effort you can is entirely beside the point, Henry. What we want to know is not whether you are working on this, but rather what has been done so far and what's next. At the moment, I don't care how data will be made more secure in the future on this site. I want to get "my" account removed FIRST. Can you tell me what is being done to achieve this? As I have already said a few times, I have found no way to remove it myself. Since the data was stolen from YOUR site, I believe the ball is in YOUR court. Had my data not been on your site, it wouldn't have been stolen in the first place.


I OF COURSE appreciate, as anybody else this side of the trust gap, that everybody is so darn busy (even on weekends, chapeau) but then its beyond the point, which by now I dont need to repeat.

Regards

Vito


 
Ralf Lemster
Ralf Lemster  Identity Verified
Germany
Local time: 05:44
English to German
+ ...
Thanks, Henry Aug 6, 2009


The announcement has been made, notifications are now being sent.

Thanks, Henry - this is an important step; I appreciate it.

The information page is here: http://www.proz.com/about/security[/quote]
Good; I also noticed the link provided on the home page.

Best regards,
Ralf

 
Viktoria Gimbe
Viktoria Gimbe  Identity Verified
Canada
Local time: 23:44
English to French
+ ...
May I ask... Aug 6, 2009

Please, for the love of [insert name of deity here], tell me what ProZ is doing to get the data removed! I just want my data removed. I am not able to remove it myself. The data came from ProZ, so the first victim of this is ProZ. Therefore, it should be up to ProZ to demand that the data be removed. Has this been done? Did you get a reply?

I hope I don't need to explain the difference between tens of thousands of people asking separately to get their data removed versus one entity
... See more
Please, for the love of [insert name of deity here], tell me what ProZ is doing to get the data removed! I just want my data removed. I am not able to remove it myself. The data came from ProZ, so the first victim of this is ProZ. Therefore, it should be up to ProZ to demand that the data be removed. Has this been done? Did you get a reply?

I hope I don't need to explain the difference between tens of thousands of people asking separately to get their data removed versus one entity asking to get all of the data removed.

I want to get my data removed. Can I expect for ProZ to assist me with that?

Again, for the sake of clarity, I want my data removed and I expect ProZ to collaborate.

Please, don't force me to ask again!

P.S.: Thanks for the e-mail. It has a link to a lot of blabla that means nothing to me. Nothing new there. It does NOT answer my question. Too little, too late.
Collapse


 
Monica Paolillo
Monica Paolillo
Italy
Local time: 05:44
English to Italian
+ ...
I did the same Aug 6, 2009

Hallo Giovanni,

I did exactly the same. Some users were worried they might make things worse by letting these guys have our email addresses but Henry informed us that our email addresses had already been hijacked from the very first place. And the fact that my password retrieval procedure was successful (userID+email matching) confirms that. So all I could choose to do is try and remove my details from that website.

This incident makes me feel extremely uncomfortable... See more
Hallo Giovanni,

I did exactly the same. Some users were worried they might make things worse by letting these guys have our email addresses but Henry informed us that our email addresses had already been hijacked from the very first place. And the fact that my password retrieval procedure was successful (userID+email matching) confirms that. So all I could choose to do is try and remove my details from that website.

This incident makes me feel extremely uncomfortable and came as a really bad piece of news.

Monica

Giovanni Guarnieri MITI, MIL wrote:

did a search with my surname, clicked on it (to get my username). Then I went to the "sign-in" page (click on link top right) and clicked on Forgot Password? In the "Get new Password" window, I inserted my username and real e-mail address. After 5 minutes I received an e-mail with a link, which took me to the change password page. Inserted my username and new password. New password was confirmed. I then went to the sign-in page again. Signed-in and got to my profile. I clicked on "deactivate account".

I'm not listed anymore, but this does not necessarily mean that my profile has been deleted...

HTH,

G
Collapse


 
Monica Paolillo
Monica Paolillo
Italy
Local time: 05:44
English to Italian
+ ...
I agree with Viktoria Aug 6, 2009

You're right Viktoria,

I do think Proz should take immediate action and make sure our details are removed without hesitation. I received Henry's email but there is not a lot I can do from my BlackBerry while I'm on holiday.

Monica

ViktoriaG wrote:

Please, for the love of [insert name of deity here], tell me what ProZ is doing to get the data removed! I just want my data removed. I am not able to remove it myself. The data came from ProZ, so the first victim of this is ProZ. Therefore, it should be up to ProZ to demand that the data be removed. Has this been done? Did you get a reply?

I hope I don't need to explain the difference between tens of thousands of people asking separately to get their data removed versus one entity asking to get all of the data removed.

I want to get my data removed. Can I expect for ProZ to assist me with that?

Again, for the sake of clarity, I want my data removed and I expect ProZ to collaborate.

Please, don't force me to ask again!

P.S.: Thanks for the e-mail. It has a link to a lot of blabla that means nothing to me. Nothing new there. It does NOT answer my question. Too little, too late.


 
Paul Malone
Paul Malone  Identity Verified
France
Local time: 05:44
Member (2004)
French to English
+ ...
What does Mr. Ohrimenko think he's playing at? Aug 6, 2009

The website is being hosted in Namibia and the "netblock owner" is one Dmitriy Ohrimenko, according to www.netcraft.com.

Perhaps we should all take a trip to Namibia, all 250,000 of us together, knock on Mr. Ohrimenko's door and ask him exactly what he thinks he's playing at?



[Edited at 2009-08-06 20:29 GMT]
... See more
The website is being hosted in Namibia and the "netblock owner" is one Dmitriy Ohrimenko, according to www.netcraft.com.

Perhaps we should all take a trip to Namibia, all 250,000 of us together, knock on Mr. Ohrimenko's door and ask him exactly what he thinks he's playing at?



[Edited at 2009-08-06 20:29 GMT]

[Edited at 2009-08-06 20:47 GMT]
Collapse


 
Ines Burrell
Ines Burrell  Identity Verified
United Kingdom
Local time: 04:44
Member (2004)
English to Latvian
+ ...
Where is my notification? Aug 6, 2009

I have not received any. Checked the spam box as well, nothing. Is everytbody supposed to get it? Or does it get sent in batches? Obviously it is rather useless but if I even do not even get a notification weeks after my data was stolen, how many months will I have to wait for that info to be removed?

 
Nicole Schnell
Nicole Schnell  Identity Verified
United States
Local time: 20:44
English to German
+ ...
In memoriam
I received my notification Aug 6, 2009

Burrell wrote:

I have not received any. Checked the spam box as well, nothing. Is everytbody supposed to get it? Or does it get sent in batches? Obviously it is rather useless but if I even do not even get a notification weeks after my data was stolen, how many months will I have to wait for that info to be removed?


The notifications are personalized and obviously not sent in batches.

Thanks for your email, Jared!


 
Lucia Leszinsky
Lucia Leszinsky
SITE STAFF
Please submit a support request Aug 6, 2009

Hi all,

Burrell wrote:

I have not received any. Checked the spam box as well, nothing. Is everytbody supposed to get it? Or does it get sent in batches? Obviously it is rather useless but if I even do not even get a notification weeks after my data was stolen, how many months will I have to wait for that info to be removed?


Please note that notifications were sent to affected profile owners. If you would like to see whether your contact information was included in the breach or not, please submit a support request and more information will be provided to you.

Thanks in advance.

Regards,

Lucia


 
Uldis Liepkalns
Uldis Liepkalns  Identity Verified
Latvia
Local time: 06:44
Member (2003)
English to Latvian
+ ...
You have not missed much Aug 6, 2009

Burrell wrote:

I have not received any. Checked the spam box as well, nothing. Is everytbody supposed to get it? Or does it get sent in batches? Obviously it is rather useless but if I even do not even get a notification weeks after my data was stolen, how many months will I have to wait for that info to be removed?


I received mine, but basically it doesn't say anything more than this link: http://www.proz.com/about/security

The problem, how I see it, is it should have been sent out when it happened, not about 3 weeks later. Also, some strong legal action should have been undertaken (after all, ProZ has an office in Ukraine, as well as there is a US Embassy and Ukrainian Iterpol Department ( http://www.interpol.int/Public/Region/Europe/pjsystems/Ukraine.asp )- I believe with these 3 factors combined the offender - AFAIK, Ukrainian citizen- could have been nailed to the floor long ago).

Uldis


 
JaneTranslates
JaneTranslates  Identity Verified
Puerto Rico
Local time: 23:44
Spanish to English
+ ...
Would you like one of mine? Aug 7, 2009

Burrell wrote:

I have not received any. Checked the spam box as well, nothing. Is everytbody supposed to get it? Or does it get sent in batches? Obviously it is rather useless but if I even do not even get a notification weeks after my data was stolen, how many months will I have to wait for that info to be removed?


I would be glad to share. I received the notification 6 times within 2 minutes! No, I haven't bothered to read and compare every word to be sure they are absolutely identical.


 
avsie (X)
avsie (X)  Identity Verified
Local time: 05:44
English to French
+ ...
Hear, hear! Aug 7, 2009

ViktoriaG wrote:

Please, for the love of [insert name of deity here], tell me what ProZ is doing to get the data removed! I just want my data removed. I am not able to remove it myself. The data came from ProZ, so the first victim of this is ProZ. Therefore, it should be up to ProZ to demand that the data be removed. Has this been done? Did you get a reply?

I hope I don't need to explain the difference between tens of thousands of people asking separately to get their data removed versus one entity asking to get all of the data removed.

I want to get my data removed. Can I expect for ProZ to assist me with that?

Again, for the sake of clarity, I want my data removed and I expect ProZ to collaborate.

Please, don't force me to ask again!

P.S.: Thanks for the e-mail. It has a link to a lot of blabla that means nothing to me. Nothing new there. It does NOT answer my question. Too little, too late.


I have the same problem: they just won't remove my data. My e-mails remain unanswered and my 'profile' is still there.

Can I expect ProZ to assist me with this removal???


 
Pages in topic:   < [1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24] >


To report site rules violations or get help, contact a site moderator:


You can also contact site staff by submitting a support request »

Illegal use of data from ProZ.com profile






Trados Business Manager Lite
Create customer quotes and invoices from within Trados Studio

Trados Business Manager Lite helps to simplify and speed up some of the daily tasks, such as invoicing and reporting, associated with running your freelance translation business.

More info »
Anycount & Translation Office 3000
Translation Office 3000

Translation Office 3000 is an advanced accounting tool for freelance translators and small agencies. TO3000 easily and seamlessly integrates with the business life of professional freelance translators.

More info »