Seems like they apologized to the four users involved. I don't know that they owe the public in general an apology. They basically explained why this is less scary than the headlines (including the one here on HN) makes it look and said that they were committed to keeping this from happening again, including giving examples of steps they were going to take.
What would you have liked to see from them? Prostrating themselves before you for revealing someone else's credit card data?
I would have liked to have seen "a lot less bad that it looks" replaces with "one would have been too many" and "we will work very hard to regain your trust". It's okay... but the public is their target audience! Simple phrases, big impact.
Leaking 4 of thousands of credit card number IS a huge deal. It's a disservice to their users (even the ones who weren't affected) for them to downplay it.
I'm personally getting the feeling that downplaying it was more of a trip up on their part. They wake up, find they are suddenly being viewed as the devil, and for some strange reason want people to believe that things are not as bad as they look. The problem, though, is they should never have said that directly. They should have given us every reason to believe that things are not as bad as they look and have us come to that conclusion for ourselves. They should also get some PR people on pay; they probably need them more than the added security.
But technically speaking it really isn't a big deal, if you take any one of your own credit cards, extract the 'bin' and generate the rest of the numbers to be valid (http://en.wikipedia.org/wiki/Luhn_algorithm) you can make credit card numbers until you drop, with a high probability that they are currently in service (if your number is active, so are a lot of other numbers in your bin).
But those numbers alone will not allow you to do anything.
Comments
Seems like they apologized to the four users involved. I don't know that they owe the public in general an apology. They basically explained why this is less scary than the headlines (including the one here on HN) makes it look and said that they were committed to keeping this from happening again, including giving examples of steps they were going to take.
What would you have liked to see from them? Prostrating themselves before you for revealing someone else's credit card data?
I would have liked to have seen "a lot less bad that it looks" replaces with "one would have been too many" and "we will work very hard to regain your trust". It's okay... but the public is their target audience! Simple phrases, big impact.
Leaking 4 of thousands of credit card number IS a huge deal. It's a disservice to their users (even the ones who weren't affected) for them to downplay it.
I'm personally getting the feeling that downplaying it was more of a trip up on their part. They wake up, find they are suddenly being viewed as the devil, and for some strange reason want people to believe that things are not as bad as they look. The problem, though, is they should never have said that directly. They should have given us every reason to believe that things are not as bad as they look and have us come to that conclusion for ourselves. They should also get some PR people on pay; they probably need them more than the added security.
But technically speaking it really isn't a big deal, if you take any one of your own credit cards, extract the 'bin' and generate the rest of the numbers to be valid (http://en.wikipedia.org/wiki/Luhn_algorithm) you can make credit card numbers until you drop, with a high probability that they are currently in service (if your number is active, so are a lot of other numbers in your bin).
But those numbers alone will not allow you to do anything.