Owners.ferrari security Log Out | Topics | Search
Moderators | Edit Profile

FerrariChat.com » General Ferrari Discussion » Archive through October 22, 2003 » Owners.ferrari security « Previous Next »

Author Message
g dan (Nsk)
New member
Username: Nsk

Post Number: 23
Registered: 9-2003
Posted on Monday, October 20, 2003 - 4:35 am:   

Mark, unfortunately, that isn't the case. She indicated she can, which I verified by opening
the newsletter and clicking the links, specifically ordering and personal info. Hopefully, Ferrari addresses the problem.

Can you assist? I have notified the owners' site but have yet to receive a response.


Dan (Bobafett)
Intermediate Member
Username: Bobafett

Post Number: 1625
Registered: 9-2002
Posted on Monday, October 20, 2003 - 4:29 am:   

Ben,

We all know you're a freak! :-) I remember the biometric access points in AboveNet and Exodus.

--Dan
Mark Langfield (Ferrari_co_uk)
Junior Member
Username: Ferrari_co_uk

Post Number: 109
Registered: 4-2003
Posted on Monday, October 20, 2003 - 4:08 am:   

Hi Nsk,

Whilst your friend can enter the site there are places that she wont be able to view like your personal info, the forum section or even the spare parts ordering section.

Best
Mark
g dan (Nsk)
New member
Username: Nsk

Post Number: 22
Registered: 9-2003
Posted on Saturday, October 18, 2003 - 3:58 pm:   

"With Ferrari, we had one s/n and one random code. Ferrari is not even close to Bentley in security."

The problem is that the newsletter allows anyone to access the account sans logging in.
Hence any number of passwords etc would be useless. More dissapointing is that, after two days, Ferrari has yet to respond to my email and requests. Hopefully the issue will be resolved by Tuesday ...
Ben Cannon (Artherd)
Intermediate Member
Username: Artherd

Post Number: 1093
Registered: 6-2002
Posted on Friday, October 17, 2003 - 8:53 pm:   

Dan- Apple computer uses the same thing.

For some of my clients, I employ full biometrics (combination of fingerprint/retina scan, and ultrasonic body volume measurment in an anchloric chamber.)

Although that is usually not nessicary to get on the LAN.

Usually...

Best!
Ben.
Rosso (Redhead)
Member
Username: Redhead

Post Number: 529
Registered: 12-2001
Posted on Friday, October 17, 2003 - 3:27 pm:   

Following Dans Tagent..
Bentley has the same thing. I have 5 different screens to just log into the Bentley DCS (Dealer Communication Site) and loads of screenames and passwords.

With Ferrari, we had one s/n and one random code. Ferrari is not even close to Bentley in security.
Dan (Bobafett)
Intermediate Member
Username: Bobafett

Post Number: 1618
Registered: 9-2002
Posted on Friday, October 17, 2003 - 2:53 pm:   

In a random bit of info, did you know that Ferrari employees have to carry an RSA key generator just to log in to the employee website? Talk about paranoid.

--Dan
g dan (Nsk)
New member
Username: Nsk

Post Number: 21
Registered: 9-2003
Posted on Thursday, October 16, 2003 - 6:33 pm:   

Please be advised that the security on https://www.owners.ferrari.com/ appears to be problematic.

I have forwarded the most recent Ferrari owners newsletter to a friend and she unknowingly accessed my account by simply opening the newsletter and clicking the links. Absurd.

After being informed of this, I modified the password, which takes effect immediately.
Nonetheless she was still able to access my account by simply opening the newsletter. Even more absurd!

The newsletter references the account's email address followed by "&prov=NL" (no login?) which is the likely culprit. I thus modified the personal information, however these changes must be approved by Ferrari, and so they do not take effect immediately. Unfortunately, it appears the account's security can be circumvented until Ferrari approves the changes.

Ferrari has been notified of the problem and hopefully it will be addressed. Nonetheless, a very disappointing experience.

Topics | Last Day | Last Week | Tree View | Search | Help/Instructions | Program Credits Administration