Forums: Climbing Information: Gear Heads:
MADROCK site security risk?
RSS FeedRSS Feeds for Gear Heads

Premier Sponsor:

 


ajkclay


Jun 27, 2007, 2:28 AM
Post #1 of 9 (1766 views)
Shortcut

Registered: May 9, 2002
Posts: 1567

MADROCK site security risk?
Report this Post
Average: avg_1 avg_2 avg_3 avg_4 avg_5 (0 ratings)  
Can't Post

Hi there, I just went to the Madrock site to buy some gear and when I went to proceed to the checkout was issued with a warning that the certificate was invalid...

what's the deal? It was redirecting to an http: not https:

Anyone know the story here?

Also anyone know what the shipping costs to Australia are?

Cheers

Adam


shrug7


Jun 27, 2007, 2:49 AM
Post #2 of 9 (1749 views)
Shortcut

Registered: Oct 18, 2006
Posts: 866

Re: [ajkclay] MADROCK site security risk? [In reply to]
Report this Post
Average: avg_1 avg_2 avg_3 avg_4 avg_5 (0 ratings)  
Can't Post

ajkclay wrote:
Hi there, I just went to the Madrock site to buy some gear and when I went to proceed to the checkout was issued with a warning that the certificate was invalid...

what's the deal? It was redirecting to an http: not https:

Anyone know the story here?

Also anyone know what the shipping costs to Australia are?

Cheers

Adam

If it's not https don't ever put your CC in there.
If it says it's not trusted......call them directly just to be safe.
Just went there and the same thing happened to me. However....I got redirected to an https site.
The cert is coming from a none "popular" certificate authority. but...hell, the date on their server could be wrong for all we know...

Call (time zone thingy might be fun)Smile


ajkclay


Jun 27, 2007, 2:53 AM
Post #3 of 9 (1743 views)
Shortcut

Registered: May 9, 2002
Posts: 1567

Re: [shrug7] MADROCK site security risk? [In reply to]
Report this Post
Average: avg_1 avg_2 avg_3 avg_4 avg_5 (0 ratings)  
Can't Post

Yep, that was my immediate thought re the https thing.

thanks mate, I'll call when I can Smile

Cheers

Adam


overlord


Jun 27, 2007, 8:32 AM
Post #4 of 9 (1695 views)
Shortcut

Registered: Mar 25, 2002
Posts: 14120

Re: [ajkclay] MADROCK site security risk? [In reply to]
Report this Post
Average: avg_1 avg_2 avg_3 avg_4 avg_5 (0 ratings)  
Can't Post

ajkclay wrote:
Hi there, I just went to the Madrock site to buy some gear and when I went to proceed to the checkout was issued with a warning that the certificate was invalid...

what's the deal? It was redirecting to an http: not https:

Anyone know the story here?

Also anyone know what the shipping costs to Australia are?

Cheers

Adam

https is secure (encrypted) http (thats what the S is there for).

it might be that their certificate wasnt updated when they shouldve done it, or yours and theirs timestamps dont match up (happens sometimes when you change your comp time settings for instance, or when youre in different time zones). send them an email and ask about it. if that is the issue, its no biggie.


bbirtle


Jun 27, 2007, 9:19 AM
Post #5 of 9 (1689 views)
Shortcut

Registered: Jan 28, 2007
Posts: 102

Re: [ajkclay] MADROCK site security risk? [In reply to]
Report this Post
Average: avg_1 avg_2 avg_3 avg_4 avg_5 (0 ratings)  
Can't Post

Yeah the certificate error either has to do with your own computer's clock being off or they just forgot to update it. Or it could be a hacker trying to impersonate them, but that's not very likely. In any case, the connection IS secure, otherwise you wouldn't get the certificate error.

Speaking of Mad Rock, I just received a SPAM from them. I think because I made a purchase last year. I never asked them to send me newsletters, promos, or other crap, yet they did.

I suggest you use a fake/disposable email address when doing business with them, or better yet choose another vendor that understands SPAM is not an acceptable way to do marketing.

And if you think I'm overreacting, I'll give you the password to an older email account of mine that I abandoned due to it receiving about 100 SPAM emails a day. Last I checked, it was still up at that level so it's a veritable treasure trove of Viagra ads and other great offers.

Shop safe!


(This post was edited by bbirtle on Jun 27, 2007, 9:21 AM)


gothcopter


Jun 27, 2007, 12:59 PM
Post #6 of 9 (1622 views)
Shortcut

Registered: Apr 20, 2004
Posts: 145

Re: [ajkclay] MADROCK site security risk? [In reply to]
Report this Post
Average: avg_1 avg_2 avg_3 avg_4 avg_5 (0 ratings)  
Can't Post

The real reason you are receiving this error is because Mad Rock bought what is known as a "chained root certificate". When a web site uses one of these certificates to secure their web server, they need to install not only the certificate for their server, but an intermediate certificate provided by the certificate authority.

Starfield provides clear, simple instructions on how to do this on their web site. The fact that the server administrator in charge of the Mad Rock web site failed to do this, or even to verify that the site certificate was working, should bring up a great big warning flag in your head. If they can't even follow simple instructions, then how competent will they be in securing your payment card data?


madrock


Jul 2, 2007, 5:57 PM
Post #7 of 9 (1419 views)
Shortcut

Registered: Dec 11, 2002
Posts: 255

Server Glitch [In reply to]
Report this Post
Average: avg_1 avg_2 avg_3 avg_4 avg_5 (0 ratings)  
Can't Post

The problems was fixed. It was a glitch from our server. Our certificate was valid and is valid. I am guessing some of you have not had a computer computer problem before. Relax and go climbing, all is well. For those reasonable folks, thanks for your patience.


(This post was edited by madrock on Jul 2, 2007, 5:59 PM)


foeslts16


Jul 2, 2007, 6:02 PM
Post #8 of 9 (1411 views)
Shortcut

Registered: Dec 27, 2002
Posts: 210

Re: [bbirtle] MADROCK site security risk? [In reply to]
Report this Post
Average: avg_1 avg_2 avg_3 avg_4 avg_5 (0 ratings)  
Can't Post

bbirtle - i think you might need some serious meds.


(This post was edited by foeslts16 on Jul 2, 2007, 6:03 PM)


bbirtle


Jul 2, 2007, 8:10 PM
Post #9 of 9 (1340 views)
Shortcut

Registered: Jan 28, 2007
Posts: 102

Re: [foeslts16] MADROCK site security risk? [In reply to]
Report this Post
Average: avg_1 avg_2 avg_3 avg_4 avg_5 (0 ratings)  
Can't Post

foeslts16 wrote:
bbirtle - i think you might need some serious meds.

I've tried all the Viagra ads but they only make me super horney.

No seriously spam is just one of those things that gets me going. I had a beautiful email address "firstname@lastname.com" ruined due to spam, had to reprint business cards, re-sign digital photos... Frown


Forums : Climbing Information : Gear Heads

 


Search for (options)

Log In:

Username:
Password: Remember me:

Go Register
Go Lost Password?



Follow us on Twiter Become a Fan on Facebook