OT - Whatever happened to B&H's site!?!

Wow I just went to the B&H web page and went to the check out icon
and up popped someones order, saw another order for over 12,000
dollars in stuff.

Very scary that B&H has such an unsecure site, and B&H claims they
are just trying to protect you when they require you to fax or
email the front and back of your credit cards.

Just another good reason to stay far away from this fly by night
out fit.
Well Doc, apparently you have an axe to grind with B&H. They are hardly a fly-by-night outfit.
 
I tried ringing them (from Australia no less) using the info in their whois entry, even tried guessing an extension number that sounded important .. "1000" .. but unfortuantely no luck .. looking at some of the 'orders' - some not-so-honorable folk are trying their luck .. =(
 
Sorry to doubt the previous poster. In fact you can see the entire credit card number, presumably if the person chose to have the info stored by B&H (can't remember but I thought they made it an option).

Lots of people from connecticut are up making orders, very scary.

Jason
 
I just called to a guy who's contact info and full credit card info popped up on my screen. I told him the whole story and to cancel his credit card. He said he was on B&H just as I called him. If someone wanted to help they could hang around and call each of these people that pop up. I'm going to call one local guy in the morning, but I'm off to bed (again).

Jason
It was down for a while, now it's up again but is absolutely messed
up.

The language keeps changing between Spanish and English, and I can
see other people's order details and shopping carts.

This includes names, addresses and semi-masked payment details!!

This is really worrying... does anyone else experience the same?
 
dude quote your ass to bed, who cares what I said. The main problem is B&H site is messed up.

Have a good day.
 
Ok now you’re starting to !@#$ me off, I came in this thread to try and help in what ever way I can and you for some reason just have to worry about me. It's very late, I been up and working for almost 16hrs. So big deal if I made a mistake on a word or two, no one else seemed to mind and went on with their business like I am about to do and you should have done. Later
 
Ok now you’re starting to !@#$ me off, I came in this thread to try
and help in what ever way I can and you for some reason just have
to worry about me. It's very late, I been up and working for
almost 16hrs. So big deal if I made a mistake on a word or two, no
one else seemed to mind and went on with their business like I am
about to do and you should have done. Later
Its no big deal, I am just trying to clarify the situation and eliminating misinformation. Another way I've done this is to call and warn people who's credit card info has been exposed. They've been very appreciative about it so far.

Jason
 
That's what I get, regardless of how many times I click on the shopping cart.

Mark
 
I went to the site but I couldn't see anything out of the ordinary. Then, I've never gotten a login or a password. Do you think that is necessary to see the problems?

Does this look like it is all orders or just orders being placed over the Internet. Could this be hackers hitting their site to steal credit card numbers and information. I'm wondering those past customers who have ordered by phone have credit card info at risk...
What do you guys think?

Diderot

BTW, It will be interesting to hear Henry Posner explain THIS away...
 
As I said earlier, I know B&H is not perfect, and I don't at all doubt the existence of this problem. And I know you didn't start this thread (but you did start five others on the subject, apparently). The only thing I question is your characterization of B&H's business practices, and your knowledge of the existence of hundreds of phantom negative reviews.

And, of course, your motives in creating this account, which you've only used to attack B&H, even though you've also hinted that you're a long-term poster here.
Yeah your right I created this account just for tonight, get real,
B&H Photo is not perfect and tonight proves it beyond any doubt, I
have stopped buying from B&H and after seeing this information I am
glad I did.

By the way before your over active imagination runs away, I am not
the one who started this thread.

Someone else found the problem and I tried it and he was correct,
the B&H site is allowing others to view your personal information.
 
I was just on it at 2:48 Iraqi time and the language does keep changing, and when you click on shipping cost, it keeps bringing up the cost to ship to Norway.
--
KOENIG
 
Man, I think they can forget me ordering online for a while. Hope somebody gets through to them, looks like a lot of huge orders being made right now. Every time you click my cart, there are new orders, and most are rather large and the fastest shipping. Hopefully the credit card orders aren't going through. Sure would hate to work their customer service in the morning.
--
KOENIG
 
That's true. It sounds like this is going to be one heck of a mess to clean up. If anybody's looking for steady employment in the New York area....
Man, I think they can forget me ordering online for a while. Hope
somebody gets through to them, looks like a lot of huge orders
being made right now. Every time you click my cart, there are new
orders, and most are rather large and the fastest shipping.
Hopefully the credit card orders aren't going through. Sure would
hate to work their customer service in the morning.
--
KOENIG
 
B&H is probably the most reputable online/mail order photography site.

Their reseller rating is very, very good. Consider that most satisfied customers don't bother posting (I have used them dozens of times and never bothered posting good reviews) and that the very few angry customers post as many places as they can.

Even against these odds, only 8.4% of B&H customers posted anything other than the fact that they were satisfied. In fact, 85% of the postings said they were VERY satisfied. Show me any retailer with higher ratings and I will give your opinion some merit.

Furthermore, B&H is one of the few resellers who take the time to address people's complaints by pointing out the facts of the case and how they tried to resolve it. Most retailers just ignore the negative posts (and most of them have a LOT more than 9% negative).

Resellerratings doesn't allow people to make false or libellous statements on their website. If you couldn't back up the complaints you were making, they removed your post.

This security problem is serious, but your personal beef with B&H is a separate issue. So you think you were wronged. Everyone else here seems very happy with the service B&H provides. Why does that bother you so much?

--
---------------------------
Chris Harrison
 
Click LOG OUT.

It appears that session IDs are being shared or truncated, and if you're logged in, your info may appear to others as well. It's not clear if the exposure is with the users table, or only the active sessions table. "Hopefully" it's just with active sessions (people who haven't logged out) and by logging out of your account, you can gain some protection.
 
late last night, I went to B&H's site to buy a camera bag. My experience was first slow, then all of a sudden in Spanish. I didn't see the shopping cart issues until this morning, 12 hours later. But after refreshing the cart several times, I slip between an empty cart, a Spanish cart with one item, then after I delete that item I get an English cart with that item still plus another item.

So, don't be so quick to holler "troll," it's not becoming.

Andy C.

--
See my Digital Astrophotography at:
http://www.macnmotion.com
 
This guy Doc Brown has only joined dpreview a week ago and has contributed nothing but critisim of B&H and rubbishes anyone who likes to deal with them.I know nothing about B&H as I live in Europe but this guy wants to be reported to the appropiate authorities.
--
Fred
 
He didn't start this thread and the problem was/is visible to anyone who cared to look and to many just trying to place an order (I think that B&H have started to take action to remedy the problem now).
This guy Doc Brown has only joined dpreview a week ago and has
contributed nothing but critisim of B&H and rubbishes anyone who
likes to deal with them.I know nothing about B&H as I live in
Europe but this guy wants to be reported to the appropiate
authorities.
--
Fred
--
TZ=GMT+1
 

Keyboard shortcuts

Back
Top