davidjay
December 3 2007, 10:08 AM
I think it's awesome that OSPers discovered this because of the quality and character of those on this forum.
This problem is being handled by Pictage immediately and so I'm making the thread invisible because it is a security issue and I'm sure you understand that until it is fixed nobody should be able to figure out how to get into other people's account....
Please DO NOT ATTEMPT to get anyone's passwords or to make this problem worse than it is. It will be resolved ASAP.
Keep rocking,
DJ
steve bélinge
December 3 2007, 10:09 AM
QUOTE(davidjay @ December 3 2007, 10:08 AM)

I think it's awesome that OSPers discovered this because of the quality and character of those on this forum.
This problem is being handled by Pictage immediately and so I'm making the thread invisible because it is a security issue and I'm sure you understand that until it is fixed nobody should be able to figure out how to get into other people's account....
Please DO NOT ATTEMPT to get anyone's passwords or to make this problem worse than it is. It will be resolved ASAP.
Keep rocking,
DJ
Thanks DJ!
Jasont
December 3 2007, 10:11 AM
Looks like it's gone over on the Pictage boards too. Maybe I can get some work done today now. LOL!
SarahQ
December 3 2007, 10:14 AM
Damn, DJ. I was JUST about to have your checks forwarded over to my house! Oh, well. No early Christmas for me this year
davidjay
December 3 2007, 10:26 AM
LOL ... thanks for spotting this and sending me the message. If the photo thing doesn't work out you should work for the CIA or something!

Rock on!
DJ
Jasont
December 3 2007, 11:23 AM
I just released an event and it looks like Pictage already fixed this issue. It's probably a temp fix until they change the way they do these things, but it's good to see that the problem is over.
Eric Hegwer
December 3 2007, 11:42 AM
I just cancelled my membership.
I've got a folder that automatically gets pictage e-mails, and as I was going through it, I saw instances of MY info going out to clients 5 months ago!
If you haven't already, change your Password NOW. pictage should send out a notice about this ASAP to all current and previous clients.
SarahQ
December 3 2007, 11:44 AM
QUOTE(Eric Hegwer @ December 3 2007, 11:42 AM)

I've got a folder that automatically gets pictage e-mails, and as I was going through it, I saw instances of MY info going out to clients 5 months ago!
What?! How was your info going out to clients?????
Eric Hegwer
December 3 2007, 11:52 AM
This is huge!
When I first started to try them out a few months ago, I didn't know how to release events, so I released them to myself, and then invited the owner to view them.
That's where it started. I found 5 month old events with this.
mattcam
December 3 2007, 12:07 PM
QUOTE(Eric Hegwer @ December 3 2007, 02:42 PM)

If you haven't already, change your Password NOW.
Or maybe everyone should cancel now (like you did). That might send the right message about protecting privacy.
SarahQ
December 3 2007, 12:16 PM
QUOTE(Eric Hegwer @ December 3 2007, 11:52 AM)

This is huge!
When I first started to try them out a few months ago, I didn't know how to release events, so I released them to myself, and then invited the owner to view them.
That's where it started. I found 5 month old events with this.
WOW!

I wonder how many Pictage users do it that way. I think that's what David from Puerto Rico does, too.
Jasont
December 3 2007, 12:58 PM
I make myself the event owner on all of my events. That would be something if like 500 people left at one time wouldn't it? Here's the thing though, people like me that's been with Pictage for a while will not have an easy time breaking away. That's what I'm dealing with right now. I think I'm gonna go ahead and get a photocart, but what happens with the 60-70 active events I have there? If it was just a few like Eric, it would be easy, but it's not for someone that's been there a long time.
Jillian Kay
December 3 2007, 01:08 PM
yeah, i've got a bride dealing with a sort of issue right now. not sure if it's related or not, but i've advised her to change her password.
glad to hear this is getting resolved. i won't share my story, but i did give a pictage customer service dude a peice of my mind a couple of months ago. i was told it was a normal practice, and not to be worried. i'm really glad it's not really acceptable.
Jasont
December 3 2007, 01:11 PM
[quote name='Jillian Kay' date='December 3 2007, 04:08 PM' post='243973']
yeah, i've got a bride dealing with a sort of issue right now. not sure if it's related or not, but i've advised her to change her password.
glad to hear this is getting resolved. i won't share my story, but i did give a pictage customer service dude a peice of my mind a couple of months ago. i was told it was a normal practice, and not to be worried. i'm really glad it's not really acceptable.
[/quote
Now that really makes me angry if they knew about the security issue but refused to do anything about it. It took Sarah starting that thread here and several other things behind the curtains for Pictage to finally do something about this. They knew all along that this could happen.
Jillian Kay
December 3 2007, 01:32 PM
QUOTE(JasonTench @ December 3 2007, 01:11 PM)

Now that really makes me angry if they knew about the security issue but refused to do anything about it. It took Sarah starting that thread here and several other things behind the curtains for Pictage to finally do something about this. They knew all along that this could happen.
i didn't give the other thread a thorough read before it was removed. so i am not sure if it's the same issue. i'm just glad they are taking passwords more seriously. and i was really only talking to the low man on the totem pole, i doubt my complaint was raised higher up on the food chain. you can im me if you want to know the exact issue.
SarahQ
December 3 2007, 02:26 PM
QUOTE(Jillian Kay @ December 3 2007, 01:32 PM)

i didn't give the other thread a thorough read before it was removed. so i am not sure if it's the same issue. i'm just glad they are taking passwords more seriously. and i was really only talking to the low man on the totem pole, i doubt my complaint was raised higher up on the food chain. you can im me if you want to know the exact issue.
Yeah, it does really suck that Jillian pointed it out and was blown off. I PM'd her and got the scoop and yep, it's the same issue.
What the hell, Pictage? This was a big big big screw up
davidjay
December 3 2007, 03:36 PM
If you guys want something to get upset about there are many issues in the world worth your emotional energy. As far as I know nobody has had anything bad happen to them as a result and Pictage is fixing the problem so I think it's worth moving on.
Eric Hegwer
December 3 2007, 03:47 PM
QUOTE(davidjay @ December 3 2007, 03:36 PM)

If you guys want something to get upset about there are many issues in the world worth your emotional energy. As far as I know nobody has had anything bad happen to them as a result and Pictage is fixing the problem so I think it's worth moving on.
And I do: Volunteering my services to help out battered children, donating a large percentage of my pre-tax profit to worthwhile causes, heck I even spent a year working in Israel for free.
DJ, I hate to be the one to say this, but Yeah, this is a big deal. Sure, nothing bad happened, but this kind of mistake can ruin businesses. Feel free to PM me if you need me to explain more.
Pictage is supposed to make our lives easier. We should just be able to hand off things and outsource without any problems, right?
SarahQ
December 3 2007, 03:50 PM
QUOTE(davidjay @ December 3 2007, 03:36 PM)

If you guys want something to get upset about there are many issues in the world worth your emotional energy. As far as I know nobody has had anything bad happen to them as a result and Pictage is fixing the problem so I think it's worth moving on.
Wow. Seriously, DJ??? I think that's a little harsh. I do worry about important things in the world, thank you very much. That's why I volunteer with my kids and donate to charity on a regular basis.
This issue had the potential to hurt my business. OSP isn't a forum for discussing "real" world problems. It's a forum for discussing photography and the business, right? Don't belittle our complaints by saying there are more important things in the world. We know there are more important things.
You know, I just signed up with Pictage and I've been vocal in telling people that it's really worked well for me so far. I don't bash Pictage, but this was an issue that needed to be addressed. Apparently, mentioning it to Pictage reps didn't work (for Jillian), and this is what it took to get something done. And it was a HUGE issue. Yeah, we can drop it now that it's being fixed, but REALLY?? We can't even discuss it? At least not without being treated like we're whining?
Please.
**EDIT** Looks like you and I were posting at the same time, Eric

Glad I'm not the only one a tiny bit offended by DJ's post.
*Troy*
December 3 2007, 04:22 PM
QUOTE(Sarah Quiara @ December 3 2007, 06:50 PM)

...
**EDIT** Looks like you and I were posting at the same time, Eric

Glad I'm not the only one a tiny bit offended by DJ's post.
I was kindof worried when someone posted that they tried to get Ian's password to have some fun.
Getting someone else's password is never just a bit of "fun"
SarahQ
December 3 2007, 04:26 PM
QUOTE(Troy Hill @ December 3 2007, 04:22 PM)

I was kindof worried when someone posted that they tried to get Ian's password to have some fun.
Getting someone else's password is never just a bit of "fun"
Yeah, that was DJ that posted that (getting passwords as "fun") Not me or Eric.
Jillian Kay
December 3 2007, 04:28 PM
While I don't want to make too big of a deal of this or cause an over-reaction (which is why I didn't post my own story), and I realize that children are starving in third world countries....
protecting my client's information is important to me. a breach of that kind has the potential to harm my business reputation and my relationship with my clients. it is important to me, and this is a forum to talk about important business concerns.
Dj, this isn't the normal, level-headed, business-like reaction i would expect from you. It was the emotional reaction of someone who has more of a personal stake in the company (whether individually or because you have established friendships). i appreciate your concern for maintaining a professional opinion of Pictage, and I absolutely appreciate that they are correcting the issue currently.
I just wish that you were able to take a more objective view, and allow us the courtesy of assuming that we will come to a rational, professional opinion based on how Pictage handles the situation.
Ryan Mc.
December 3 2007, 04:36 PM
QUOTE(davidjay @ December 3 2007, 04:36 PM)

If you guys want something to get upset about there are many issues in the world worth your emotional energy. As far as I know nobody has had anything bad happen to them as a result and Pictage is fixing the problem so I think it's worth moving on.
I must admit DJ after reading this post my first thought was hmmm he must have is hand in that cookie jar.
I think potential Identity theft is worth a lot of emotional energy. As stated in the other thread Sarah not only had Bobbi pictage password but could potentially have even got into her Paypal account. If you don't know what I am talking about I am sure you can go back and read the whole thread.
Not slamming you DJ just sayin
BillCawley
December 3 2007, 04:41 PM
QUOTE(Jillian Kay @ December 3 2007, 04:28 PM)

While I don't want to make too big of a deal of this or cause an over-reaction (which is why I didn't post my own story), and I realize that children are starving in third world countries....
protecting my client's information is important to me. a breach of that kind has the potential to harm my business reputation and my relationship with my clients. it is important to me, and this is a forum to talk about important business concerns.
Dj, this isn't the normal, level-headed, business-like reaction i would expect from you. It was the emotional reaction of someone who has more of a personal stake in the company (whether individually or because you have established friendships). i appreciate your concern for maintaining a professional opinion of Pictage, and I absolutely appreciate that they are correcting the issue currently.
I just wish that you were able to take a more objective view, and allow us the courtesy of assuming that we will come to a rational, professional opinion based on how Pictage handles the situation.
Anybody every tell you you have a way with words?

(oh, and plus one to the last posts by Eric and Sarah too)
davidjay
December 3 2007, 05:19 PM
I apologize for offending anybody. I know you are good people I was just bummed that you didn't move on from this.
I don't have ownership in Pictage, I have never been paid by Pictage, most of my friends don't work there any more and I'm not even pursuing a sponsorship with them (see the speakers for their next partnercon which I declined to be a part of)
All the best,
DJ
Eric Hegwer
December 3 2007, 05:22 PM
No worries DJ.
Jillian Kay
December 3 2007, 06:04 PM
No problem.

I wasn't offended, I just disagreed. I think it's great that you were able to find out for us that it was getting resolved. I just so happened to be on the system earlier when it went down for about 60 seconds for the fix. That was fast!
No more being bummed!!
QUOTE(davidjay @ December 3 2007, 05:19 PM)

I apologize for offending anybody. I know you are good people I was just bummed that you didn't move on from this.
I don't have ownership in Pictage, I have never been paid by Pictage, most of my friends don't work there any more and I'm not even pursuing a sponsorship with them (see the speakers for their next partnercon which I declined to be a part of)
All the best,
DJ
kaybeaton
December 3 2007, 06:27 PM
QUOTE(davidjay @ December 3 2007, 04:36 PM)

If you guys want something to get upset about there are many issues in the world worth your emotional energy. As far as I know nobody has had anything bad happen to them as a result and Pictage is fixing the problem so I think it's worth moving on.
I agree DJ....there's not many internet based companies that one can't take pot shots at.....I've been through about 10 online photo print fullfillment companies before finding Pictage. YES, this is a problem, YES, Pictage is responding. I agree with putting energy to more important world issues!
Jeff Schaefer
December 3 2007, 07:58 PM
In the first thread I didn't understand how to deliberately get other people's passwords. Now I get it. Wow. That was bad on Pictage's part.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.