Reply
Honored Contributor
Posts: 17,606
Registered: ‎06-27-2010

Re: ****QVC Website - Serious Security Vulnerability****

[ Edited ]

@Allegheny wrote:

@dooBdoo

I like you!  You have such a nice way about you.  And for us limited tech people explain things in a way we can understand!


 

            @Allegheny,  How sweet of you!   I like you, too!   Thanks for the lovely compliment.❤️   

             Most people really don't need to have a comprehensive knowledge of tech stuff, all those details that should be handled well by the website software.    QVC's site happens to be dreadfully glitchy, not user-friendly, and unfortunately they don't have a tech-support person "on site" who reads or responds to our posts.   So, we're on our own.

 

Few things reveal your intellect and your generosity of spirit—the parallel powers of your heart and mind—better than how you give feedback.~Maria Popova
Trusted Contributor
Posts: 1,821
Registered: ‎02-16-2018

Re: ****QVC Website - Serious Security Vulnerability****


@goldensrbest wrote:

Could  someone from qvc,comment ,please.


@goldensrbest  Right! You would have thought corporate would have been involved by now. This topic has been brought up on the customer care forum today and no one has answered. Some customer care. It shows how much they care about protecting our financial and personal data. 

QVC Customer Care
Posts: 706
Registered: ‎06-14-2015

Re: ****QVC Website - Serious Security Vulnerability****

Please be aware that a service request has been opened regarding this. Thank you for posting in our Community forums. We will keep you advised on any updates that we receive. ~Kim, Customer Care

Honored Contributor
Posts: 17,606
Registered: ‎06-27-2010

Re: ****QVC Website - Serious Security Vulnerability****

[ Edited ]

@Ketra wrote:

@goldensrbest wrote:

Could  someone from qvc,comment ,please.


@goldensrbest  Right! You would have thought corporate would have been involved by now. This topic has been brought up on the customer care forum today and no one has answered. Some customer care. It shows how much they care about protecting our financial and personal data. 


 

            @Ketra,  QVC Corporate never shows concern about even the most alarming signs of security issues on this site.   Several years ago our logins began displaying other customers' sign-in information.   I'd have to see if I still have my reports from then, but I remember it taking a while before QVC did anything to fix that mess, and if memory serves they gave it minimal acknowledgement with a notice that they were working on a website problem -- yet they kept the site up and running, when they should've shut it down.   That's when many of us stopped leaving our actual name, address, phone number, or financial info saved on the site.   (I add mine in when I order, and then I change it or remove it after I receive the order and everything has cleared.)  This site, in my opinion, has never been professionally or securely designed or managed and at this point I don't expect it ever will be.

 

Few things reveal your intellect and your generosity of spirit—the parallel powers of your heart and mind—better than how you give feedback.~Maria Popova
Trusted Contributor
Posts: 1,821
Registered: ‎02-16-2018

Re: ****QVC Website - Serious Security Vulnerability****


@dooBdoo wrote:

@Ketra wrote:

@goldensrbest wrote:

Could  someone from qvc,comment ,please.


@goldensrbest  Right! You would have thought corporate would have been involved by now. This topic has been brought up on the customer care forum today and no one has answered. Some customer care. It shows how much they care about protecting our financial and personal data. 


 

            @Ketra,  QVC Corporate never shows concern about even the most alarming signs of security issues on this site.   Several years ago our logins began displaying other customers' sign-in information.   I'd have to see if I still have my reports from then, but I remember it taking a while before QVC did anything to fix that mess, and if memory serves they gave it minimal acknowledgement with a notice that they were working on a website problem -- yet they kept the site up and running, when they should've shut it down.   That's when many of us stopped leaving our actual name, address, phone number, or financial info saved on the site.   (I add mine in when I order, and then I change it or remove it after I receive the order and everything has cleared.)  This site, in my opinion, has never been professionally or securely designed or managed and at this point I don't expect it ever will be.

 


@dooBdoo  Thank you! Your advice is spot on. When shopping at QVC we should delete or alter our personal and financial information on QVC’s website after we receive our order. They’ve proven that they cannot be trusted with such valuable personal information. It’s a shame such a big company is willing to risk cyber theft of customer data and the reputation of their company over hiring a decent Technical Director and staff.

Trusted Contributor
Posts: 1,821
Registered: ‎02-16-2018

Re: ****QVC Website - Serious Security Vulnerability****


@Kim-QVC wrote:

Please be aware that a service request has been opened regarding this. Thank you for posting in our Community forums. We will keep you advised on any updates that we receive. ~Kim, Customer Care


@Kim-QVC  Thank you for opening the service request. Since this is an ongoing

serious issue, I can only hope that it gets the attention of senior QVC corporate leadership so that immediate and appropriate actions can be taken to protect customer data.

Honored Contributor
Posts: 17,596
Registered: ‎03-10-2010

Re: ****QVC Website - Serious Security Vulnerability****

Is it possible that they do it this way,so for some that forget their password?

When you lose some one you L~O~V~E, that Memory of them, becomes a TREASURE.
Trusted Contributor
Posts: 1,821
Registered: ‎02-16-2018

Re: ****QVC Website - Serious Security Vulnerability****


@goldensrbest wrote:

Is it possible that they do it this way,so for some that forget their password?


@goldensrbest  No, it’s a serious security vulnerability on their website that they have tried unsuccessfully to fix numerous times. They have to care about protecting their customers data enough to employ and pay for a competent Technical Division staff.

Esteemed Contributor
Posts: 5,278
Registered: ‎09-15-2016

Re: ****QVC Website - Serious Security Vulnerability****


@dooBdoo wrote:

@kitcat51 wrote:

I'm using a tablet & like @ Montana it's the same for me....Show hides & Hide shows my password but the LOCK is showing when signing in so I thought it's safe....is that right? There are many glitches on this website depending on what device you're using & for me, the small print since the website update is so annoying that I spend less time shopping & posting.


 

            @kitcat51,   The word "SHOW" means you must click on that word in order to tell the system to show your password.   If you see the word "SHOW" that means the system currently is hiding/masking the characters and you'll have to click/tap the word "SHOW" to change that.

            It's always been that way on this site (it's that way on eBay, too, if anyone wants to compare), but most of us didn't notice in the past because our password always was masked as a default.

            The padlock does mean the login is secure.

            I understand, though...  the way it looks, it's about as clear as mud!🙃                                                                       Since the update when signing in Hide will fill the box with asterisks & prints out my password below the box & Show only fills the box with asterisks. I'm not tech savvy so THANKS for answering my lock question, providing an explanation on how Hide - Show works & doing it in a way that's easy to understand...you've helped me & others too.

Frequent Contributor
Posts: 110
Registered: ‎03-10-2010

Re: ****QVC Website - Serious Security Vulnerability****


@ Montana wrote:

Sometimes the “Show” or “Hide” functions are reversed. If it says “Hide” the entire password is visible.  If switched to “Show” you can’t see it.  

 

 


This happens to me all the time. I use Firefox browser.