Most Recent Posts
ACITIC user seat dilemma
by Enio - 12/10/2025 12:35 PM
Citrix
by Enio - 12/10/2025 12:32 PM
Updox replacement?
by ffac - 12/09/2025 12:53 PM
Erx slowness
by ChrisFNP - 12/08/2025 11:23 AM
Closing up shop
by Nephron - 11/29/2025 3:00 PM
AC Version 12.3
by denvertech - 11/24/2025 12:23 PM
Script
by denvertech - 11/24/2025 12:16 PM
Losing connectivity in Peer-to-Peer networks
by denvertech - 11/24/2025 12:02 PM
Member Spotlight
Bert
Bert
Maine
Posts: 12,899
Joined: September 2003
Newest Members
scfpmd1955, jpark, sara25, SmartRX, sne787
4,601 Registered Users
Previous Thread
Next Thread
Print Thread
Rate Thread
#54281 05/10/2013 5:28 PM
Joined: Feb 2011
Posts: 1,023
Likes: 5
DocGene Offline OP
Member
OP Offline
Member
Joined: Feb 2011
Posts: 1,023
Likes: 5
Everyone get this?


IMPORTANT INFORMATION

Dear Friend of Amazing Charts,

Earlier this week we discovered there was a cyber attack to the server that hosts the Amazing Charts User Board (UB) that may involve some of your information.

We value your business and respect your privacy. According to our records, you once registered as a member of the Amazing Charts UB. The data accessed included email addresses and some passwords for User Board registrants. To our knowledge, the data accessed did not include any other information.

We have already implemented additional security measures designed to prevent a recurrence of such an attack. We are also working closely with law enforcement to ensure the incident is properly addressed.

As a precaution, please log into the User Board and change your password as soon as possible.

For further information and assistance, please contact us at UB@amazingcharts.com.

Sincerely,
Kathleen Repoli
Senior Vice President
Amazing Charts


Gene Nallin MD solo family practice with one PA Cumberland, Md

DocGene #54283 05/10/2013 5:34 PM
Joined: Apr 2011
Posts: 2,316
Likes: 2
G
Member
Offline
G
Member
Joined: Apr 2011
Posts: 2,316
Likes: 2
I got it. I find it interesting. I changed the email linked to my account a few months back and the email went to that old account. Makes me question the veracity of the email. I would proceed with caution before clicking any links.

It seems legit though. Traces back to MailChimp's servers. MailChimp is used to send bulk emails.

DocGene #54284 05/10/2013 5:48 PM
Joined: Dec 2011
Posts: 51
Member
Offline
Member
Joined: Dec 2011
Posts: 51
Hi Sandeep,

This is a legit email, we were notified by Kathleen about an hour before the email went out.

Thanks,
Anthony@AC



DocGene #54285 05/10/2013 5:48 PM
Joined: Apr 2011
Posts: 2,316
Likes: 2
G
Member
Offline
G
Member
Joined: Apr 2011
Posts: 2,316
Likes: 2
Alrighty. Thought so.

DocGene #54286 05/10/2013 5:49 PM
Joined: Apr 2011
Posts: 2,316
Likes: 2
G
Member
Offline
G
Member
Joined: Apr 2011
Posts: 2,316
Likes: 2
Might be worth posting in the Amazing Charts Status Update area so all the board members can see it.

DocGene #54289 05/10/2013 6:58 PM
Joined: Apr 2011
Posts: 99
Member
Offline
Member
Joined: Apr 2011
Posts: 99
According to the email:

"The data accessed included email addresses and some passwords for User Board registrants."

This implies that the AC UB doesn't store the passwords in encrypted form.
Isn't that a major security issue?

Michael
NY

DocGene #54290 05/10/2013 7:02 PM
Joined: Jan 2005
Posts: 442
Member
Offline
Member
Joined: Jan 2005
Posts: 442
The hyperlink in the email to the board is of the format like

amazingcharts....mananage2.com/track/click?u=...

which makes it look suspicious. emails like this should NOT include a hyperlink. They should force the user to actually type the web address. If a hyperlink is provided it should clearly link to the UB and not some funky third party tracking email.






...KenP
Internist (retired 2020)
Florida
mjmd #54291 05/10/2013 7:05 PM
Joined: Jan 2005
Posts: 442
Member
Offline
Member
Joined: Jan 2005
Posts: 442
Originally Posted by mjmd
According to the email:

"The data accessed included email addresses and some passwords for User Board registrants."

This implies that the AC UB doesn't store the passwords in encrypted form.
Isn't that a major security issue?

Michael
NY

Yes, it would be nice to know if the passwords were free text or whether they were hashed and salted.


...KenP
Internist (retired 2020)
Florida
DocGene #54292 05/10/2013 8:07 PM
Joined: Sep 2003
Posts: 12,899
Likes: 34
Member
Offline
Member
Joined: Sep 2003
Posts: 12,899
Likes: 34
As everyone knows, this is an important time for AC as it transitions to Pri-Med. AC is working diligently to release v6.5.4 and continues to work on v7 while trying to make the Cloud Version more accessible.

While it probably should be, it is likely that the security of AC's servers that host the userboard may not have been as good as it should have been.

One thing to ponder: According to the 2013 Data Breach Investigative Report, 66% of breaches were not discovered for months to years. AC's was discovered in less than five weeks. This speaks volumes to the safeguards which must have been in place.

Let's look at a few companies which were hacked between 2012 and 2013, and some of them were hacked more than once.

Facebook
Microsoft
Twitter
NBC
Evernote

And, we all know that there have been many, many more huge companies who have been compromised in the past.

It is interesting that while many computer users are wary of storing data in the cloud, very few cloud companies were hacked.

By law, Amazing Charts is obligated to advise anyone whose information was compromised that his or her information was obtained and what was obtained. This is what AC did. They sent emails notifying THOSE USERS whose email addresses and passwords were taken. I do not believe their intent was to notify every Amazing Charts user since they were taking the right steps to rectify the situation, which they have. There seems to be nothing positive to be gained by informing the entire user base, when such a small subset of those were compromised. I do not mean to downplay what happened as it happened to me as well, but, again, according to the DBIR, this year authored by Verizon Security Risk Division which collects data breach information from all over the world, if you are even a fairly well known company with a public website or forum, it is only a matter of time before hackers exploit your weaknesses. The important thing is that you detect it quickly and correct the security holes.

It should be known that any email, whether it is your current profile email or one no longer used, can be harvested as long as it was used at any time in the past.

I suppose it is up to each user who received notification to decide if it is in AC's and/or their best interest to post the events on the board. This is likely the reason it was not posted as a status update.

From my perspective, I wish we could stop this thread right here and use PMs. Just my perspective.


Bert
Pediatrics
Brewer, Maine


Moderated by  ChrisFNP, DocGene, JBS, Wendell365 

Link Copied to Clipboard
ShoutChat
Comment Guidelines: Do post respectful and insightful comments. Don't flame, hate, spam.
Who's Online Now
2 members (Ruben, Enio), 1,260 guests, and 20 robots.
Key: Admin, Global Mod, Mod
Top Posters(30 Days)
JBS 3
Enio 3
Raj1 3
Top Posters
Bert 12,899
JBS 2,999
Wendell365 2,367
Sandeep 2,316
ryanjo 2,084
Leslie 2,002
Wayne 1,889
This board is dedicated to the memory of Michael "Indy" Astleford. February 6, 1961 -- April 16, 2019




SiteLock
Powered by UBB.threads™ PHP Forum Software 7.7.5