NonSports Forum

Net54baseball.com
Welcome to Net54baseball.com. These forums are devoted to both Pre- and Post- war baseball cards and vintage memorabilia, as well as other sports. There is a separate section for Buying, Selling and Trading - the B/S/T area!! If you write anything concerning a person or company your full name needs to be in your post or obtainable from it. . Contact the moderator at leon@net54baseball.com should you have any questions or concerns. When you click on links to eBay on this site and make a purchase, this can result in this site earning a commission. Affiliate programs and affiliations include, but are not limited to, the eBay Partner Network. Enjoy!
Net54baseball.com
Net54baseball.com
ebay GSB
T206s on eBay
Babe Ruth Cards on eBay
t206 Ty Cobb on eBay
Ty Cobb Cards on eBay
Lou Gehrig Cards on eBay
Baseball T201-T217 on eBay
Baseball E90-E107 on eBay
T205 Cards on eBay
Baseball Postcards on eBay
Goudey Cards on eBay
Baseball Memorabilia on eBay
Baseball Exhibit Cards on eBay
Baseball Strip Cards on eBay
Baseball Baking Cards on eBay
Sporting News Cards on eBay
Play Ball Cards on eBay
Joe DiMaggio Cards on eBay
Mickey Mantle Cards on eBay
Bowman 1951-1955 on eBay
Football Cards on eBay

Go Back   Net54baseball.com Forums > Net54baseball Main Forum - WWII & Older Baseball Cards > Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions

Reply
 
Thread Tools Display Modes
  #1  
Old 03-20-2020, 12:23 PM
buymycards's Avatar
buymycards buymycards is offline
Rick McQuillan
Member
 
Join Date: May 2009
Location: Wisconsin
Posts: 3,178
Default Me too

I also received this email. My username and password was unprotected in the body of the email. When I used this info to log into Heartland, Google told me that there was a data breech and that I should change my password immediately, which I did. I wanted to log into my account to see if my credit card info was listed. Thank heaven it was not transferred to Heartland Auctions from the old site.

Rick
__________________
Rick McQuillan


T213-2 139 down 46 to go.
Reply With Quote
  #2  
Old 03-20-2020, 12:26 PM
pawpawdiv9's Avatar
pawpawdiv9 pawpawdiv9 is offline
Chr!$ M!ll!c@n
Member
 
Join Date: Oct 2012
Location: GA
Posts: 2,947
Default

^^^interesting???
I am gonna try and log-in and see if this happens, and if so change mine.
BTW- i also sent a message thru the site's contact page about this matter.
__________________
1916-20 UNC Big Heads
Need: Ping Bodie

Last edited by pawpawdiv9; 03-20-2020 at 12:34 PM.
Reply With Quote
  #3  
Old 03-20-2020, 12:26 PM
Bugsy's Avatar
Bugsy Bugsy is offline
©hri$ $€X₮ØΝ
Member
 
Join Date: Jun 2009
Posts: 813
Default

They shouldn't even have access to my password in the first place, let alone sending that in an email. Very concerning.
__________________
Always looking for:

1913 Cravats pennants

St. Paul Saints Game Used Bats and Memorabilia

http://www.net54baseball.com/showthread.php?t=180664
Reply With Quote
  #4  
Old 03-20-2020, 12:27 PM
brass_rat's Avatar
brass_rat brass_rat is offline
Steve
Member
 
Join Date: Dec 2009
Posts: 1,058
Default

I would imagine that a lot of users reuse passwords across sites. This is a good reason not to do that.

Password managers are a good thing... KeePass, 1Password, etc.
Reply With Quote
  #5  
Old 03-20-2020, 12:32 PM
x2drich2000 x2drich2000 is offline
(DJ) Rich.ard.s
 
Join Date: May 2009
Posts: 2,264
Default

Quote:
Originally Posted by brass_rat View Post
I would imagine that a lot of users reuse passwords across sites. This is a good reason not to do that.

Password managers are a good thing... KeePass, 1Password, etc.
You mean my password shouldn't be Password123 on every site?
__________________
Current Wantlist:
E92 Nadja - Bescher, Chance, Cobb, Donovan, Doolan, Dougherty, Doyle (with bat), Lobert, Mathewson, Miller (fielding), Tinker, Wagner (throwing), Zimmerman
E/T Young Backrun - Need E90-1
E92 Red Crofts - Anyone especially Barry and Shean
Reply With Quote
  #6  
Old 03-20-2020, 12:34 PM
glynparson's Avatar
glynparson glynparson is offline
Glyn Parson
Member
 
Join Date: May 2009
Location: Blandon PA
Posts: 2,185
Default

Quote:
Originally Posted by x2drich2000 View Post
You mean my password shouldn't be Password123 on every site?
Wow I never thought of adding the 123. I just went with password. Lol :-)
Reply With Quote
  #7  
Old 03-20-2020, 12:37 PM
ullmandds's Avatar
ullmandds ullmandds is offline
pete ullman
Member
 
Join Date: Apr 2009
Location: saint paul, mn
Posts: 11,519
Default

he must be upset that disney is closed?
Reply With Quote
  #8  
Old 03-20-2020, 12:52 PM
wondo wondo is offline
John Wondowski
Member
 
Join Date: May 2009
Posts: 1,379
Default

Quote:
Originally Posted by ullmandds View Post
he must be upset that disney is closed?
Now that’s funny!
Reply With Quote
  #9  
Old 03-20-2020, 01:00 PM
brass_rat's Avatar
brass_rat brass_rat is offline
Steve
Member
 
Join Date: Dec 2009
Posts: 1,058
Default

Sorry, yes, I agree... Changing the passwords don't help, but if an entity has access to your password, at least they have access to only that one account and trying your email/password on multiple sites won't give them access to other things.

My comment was meant to be a tangent to the original post. Agreed that entities should not have access to passwords, whether it be auction house or other... And they should not be emailed in plain text, visible to any admins under any circumstances, etc.

Just trying to be helpful. Will bow out of this conversation now.
Reply With Quote
  #10  
Old 03-20-2020, 09:28 PM
Jobu's Avatar
Jobu Jobu is offline
Bry@n
member
 
Join Date: Jul 2014
Location: WI
Posts: 3,839
Default

The grand kids are probably happy though, now that they are in their 20s it is tough spending so much time there.

Quote:
Originally Posted by ullmandds View Post
he must be upset that disney is closed?
Reply With Quote
  #11  
Old 03-21-2020, 01:31 AM
Stampsfan's Avatar
Stampsfan Stampsfan is offline
Bob Davies
Member
 
Join Date: Jul 2015
Location: Calgary, Alberta, Canada
Posts: 1,143
Default

As a now retired IT professional, this is absolutely shocking. I would not be doing business with anyone who does not use some kind of encryption for their clients passwords. Not acceptable in any way.

I've always suspected that bids are known to many auction sites, as that can be raw data that anyone with a modicum of SQL skills could find... but this is on another level.

Any auction house using Simple Auction Site is now off my bid list.

Thanks for sharing.
__________________
Successful transactions on Net54 with balltrash, greenmonster66; Peter_Spaeth; robw1959; Stetson_1883; boxcar18; Blackie

Last edited by Stampsfan; 03-21-2020 at 01:32 AM.
Reply With Quote
  #12  
Old 03-22-2020, 02:30 AM
T206.org's Avatar
T206.org T206.org is offline
Trae Regan
Member
 
Join Date: Apr 2009
Location: North Carolina
Posts: 926
Default

Quote:
Originally Posted by brass_rat View Post
I would imagine that a lot of users reuse passwords across sites. This is a good reason not to do that.

Password managers are a good thing... KeePass, 1Password, etc.

Spot on advice.

When I received the email from Bill I was alarmed but not overly worried, because I use 1Password and have a different password for every website.
__________________
Trae Regan
trae@t206.org
Reply With Quote
  #13  
Old 03-22-2020, 07:04 AM
buymycards's Avatar
buymycards buymycards is offline
Rick McQuillan
Member
 
Join Date: May 2009
Location: Wisconsin
Posts: 3,178
Default password manager

I was thinking about using a password manager, so I looked through the notebook that I use to keep track of websites, usernames, and passwords, and I found that I have nearly 140 usernames and over 100 different passwords for 226 different websites.

I'm not sure what that says about me and the amount of time that I spend online. Nerd? Yes. Nothing better to do? Most of the time. Obsessed with baseball cards? Certainly. Spending too much money? Yup. Having fun? Oh yeah! Going to try to cut back on the amount of time that I am online? Hell no!
__________________
Rick McQuillan


T213-2 139 down 46 to go.
Reply With Quote
  #14  
Old 03-22-2020, 07:59 AM
bobfreedman bobfreedman is offline
Member
 
Join Date: May 2009
Posts: 1,155
Default Apologies

Guys, I apologize for the confusion and the mistakes we made in sending out the User Names and Passwords. We have reset everyone's passwords to a randomly generated value. When you log in for the first time, you will be forced to change your password or you can go to Forgot Password and change it immediately.

As for other auction companies being able to see PW's, the vast majority cannot see your passwords nor your Max bids. We do have some older smaller legacy companies that can and we are working with them to turn them off. I will not name them so do not ask but it is a very small amount and they are very small companies. Please accept my apologies once again.

I will not be responding to this thread further.

Bob Freedman
Reply With Quote
  #15  
Old 03-22-2020, 08:13 AM
buymycards's Avatar
buymycards buymycards is offline
Rick McQuillan
Member
 
Join Date: May 2009
Location: Wisconsin
Posts: 3,178
Default New email

Here is the email that I received this morning.

Username and Password
Inbox
x

bill@go-heartland.com
8:42 AM (21 minutes ago)
to me

Dear Bidder,

As you are probably aware clear text usernames and passwords were sent out via email to all the bidders imported into Heartland's database. This was done in error. The email was not sent from the website, but was sent using mail merge and the spreadsheet used to import the data. We have since changed all the passwords in the system to a random value. To reset your password please go to this page:

https://go-heartland.com/forgotpassword.aspx

and enter your email address. A reset password link will be sent to you. You may use the forgot password page at any time to reset it.

Your new password will not be visible to anyone at Heartland Auctions or Simple Auction Site.

We apologize for any inconvenience this may have caused you.

Bill Goodwin
Heartland Auctions
314-849-9798
Go-Heartland.com
__________________
Rick McQuillan


T213-2 139 down 46 to go.
Reply With Quote
  #16  
Old 03-22-2020, 08:25 AM
pawpawdiv9's Avatar
pawpawdiv9 pawpawdiv9 is offline
Chr!$ M!ll!c@n
Member
 
Join Date: Oct 2012
Location: GA
Posts: 2,947
Default

Yep ^^ got the the new email too this morning. Already re-set password again.
And looked at the early bidding on some nice High-graded cards.
__________________
1916-20 UNC Big Heads
Need: Ping Bodie
Reply With Quote
  #17  
Old 03-22-2020, 08:21 AM
Jim VB's Avatar
Jim VB Jim VB is offline
Jim VB
Member
 
Join Date: Apr 2009
Posts: 2,090
Default

Quote:
Originally Posted by bobfreedman View Post
Guys, I apologize for the confusion and the mistakes we made in sending out the User Names and Passwords. We have reset everyone's passwords to a randomly generated value. When you log in for the first time, you will be forced to change your password or you can go to Forgot Password and change it immediately.

As for other auction companies being able to see PW's, the vast majority cannot see your passwords nor your Max bids. We do have some older smaller legacy companies that can and we are working with them to turn them off. I will not name them so do not ask but it is a very small amount and they are very small companies. Please accept my apologies once again.

I will not be responding to this thread further.

Bob Freedman

With all due respect Bob, this isn’t quite accurate. Heartland is NOT an “older, smaller, legacy company.” They are brand new. Their first auction started yesterday.

The email addresses, usernames, and passwords which were released were from a different company.
__________________
Jim Van Brunt

Last edited by Jim VB; 03-22-2020 at 10:24 AM.
Reply With Quote
  #18  
Old 03-23-2020, 05:02 PM
BeanTown's Avatar
BeanTown BeanTown is offline
Jay Cee
Member
 
Join Date: Jan 2010
Posts: 2,117
Default

Quote:
Originally Posted by bobfreedman View Post
Guys, I apologize for the confusion and the mistakes we made in sending out the User Names and Passwords. We have reset everyone's passwords to a randomly generated value.

I will not be responding to this thread further.

Bob Freedman
Many are talking over my pay grade for how auction software works. However, reading the last statement from Bob, makes me think he doesn't want to address an on going problem. Bill brings up good points and I thought Bob would be more than happy to put everyones mind to ease and answer any questions.
__________________
Love Ty Cobb rare items and baseball currency from the 19th Century.
Reply With Quote
  #19  
Old 03-26-2020, 03:40 PM
Jim VB's Avatar
Jim VB Jim VB is offline
Jim VB
Member
 
Join Date: Apr 2009
Posts: 2,090
Default

UPDATE:

SIMPLEAUCTIONSITE.COM is in the process of updating their systems. They have notified all of their clients that they are changing their systems. As Bob posted here, some auction houses have had the ability to see passwords. This function will go away shortly. I guess that’s the good news.

The bad news is that some of these guys have, for years, been able to use the passwords and that means they had the ability to see everything you bid in their auctions. Changing passwords did nothing. The guys with password access, including certain auction houses, and SimpleAuctionSite.com, could simply look at anything you bid on and see your max bids!

As always, remember that the honesty of any auction house comes down to the honesty of the auction house owner. Only deal with people you trust.

Bob also told me that he did not “leak” the old Goodwin list to Bill Goodwin. Bob says he was given the data and merely input it to Heartland Auctions.

That means the info could only have come from two sources. Either Beckett’s gave it or sold it back to Bill, or Bill made a copy before he sold his company to Beckett.

Keep that in mind when deciding who the “people you trust” really are!

(During the course of this mess, I emailed questions to Freedman, Goodwin, and Beckett. Only Freedman was nice enough to respond.)
__________________
Jim Van Brunt
Reply With Quote
  #20  
Old 03-20-2020, 12:31 PM
Jim VB's Avatar
Jim VB Jim VB is offline
Jim VB
Member
 
Join Date: Apr 2009
Posts: 2,090
Default

Changing your password is a futile exercise if the software company makes it available to the auction house.

At that point, it’s no longer “secure.”
__________________
Jim Van Brunt
Reply With Quote
Reply



Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Has anyone been able to reach Bill Goodwin? Blunder19 Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 33 09-18-2013 02:29 PM
Chatted With Bill Goodwin Today GregMitch34 Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 42 06-09-2013 08:49 AM
Anyone speak or hear from bill goodwin in last 10 days??? forazzurri2axz Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 11 03-07-2011 07:05 PM
Special Thanks To Bill Goodwin Archive Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 5 03-24-2009 06:32 AM
Bill Goodwin's e-mail addy please? Archive Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 2 11-04-2007 09:11 PM


All times are GMT -6. The time now is 03:25 PM.


ebay GSB