All Top Banking

Personal Finance Startup Rudder Exposes Customers Data

Posted by John B. Frank Thursday, May 21, 2009

Source: Finextra
Complete item: http://www.finextra.com/fullstory.asp?id=20056

Description:
Houston-based personal financial management start-up Rudder has inadvertently exposed the private account details of hundreds of individuals to other users of the site.

Daily account updates sent to two percent of Rudder's active users also provided a direct link through to the accounts of hundreds of other subscribers, where visitors could view balance updates and transaction information relating to personal bank accounts, credit cards and bill payments.

Rudder says that in total 732 accounts were compromised, but that no bank user names, passwords, addresses or other personal identity-based information were exposed.

In a statement posted on its site, Rudder says: "This issue was not the result of a data breach, but due to a software issue in our program that generates emails. It is important to know that Rudder has "read only" access to your account balances and transactions and we do not store account credentials like user names, passwords, or your personal information like name, address or social security number."

As a precautionary measure, the company says it will be offering a free identity-theft service to all compromised Rudder members.

Finextra verdict Competitors such as Mint and Wesabe might be rubbing their hands with glee at the prospect of picking off defecting Rudder subscribers, but this security lapse reflects badly on the entire sector. Mint for one has recently been talking about charging commercial third parties for access to aggregated anonymous consumer spending data. Like Rudder, Mint doesn't store names or account numbers - and there's no danger of individual account compromise - but subscribers might revolt at the idea that details of their personal spending habits are being sold on to the private sector.

E-Secure-IT
https://www.e-secure-it.com


Reblog this post [with Zemanta]

0 comments

Post a Comment

Powered by Blogger.

Blog Archive

Search This Blog

Our Manufacturing Facility

Learn More About Us

Find out how our patented technology can empower your financial institution.

Our secure two-factor online banking authentication eliminates dangerous passwords and usernames and replicates the same trusted process used to access cash at ATM's. (Insert Bank Issued Card, Enter Bank Issued PIN)

There is an R.O.I. as FI's also earn recurring revenue from each transaction conducted using our PCI 2.0 Certified PIN Entry Device. Our technology also provides a unique real-time P2P "Instant-Transfer" which allows your online banking customer to transfer cash from ANY of their bankcards to ANY other bankcard...with the Swipe of a card.

Help your bank eliminate phishing and your customers avoid identity theft by providing them with the ability to stop typing and start swiping. There is no safer way to conduct financial transactions online than by 3DES DUKPT encrypting the cardholder details, which we do at the mag-head "inside the box/outside the browser."

Total Pageviews

SLIM for PC or SmartPhone

SLIM for PC or SmartPhone
Click to Inquire

Chip and PIN eCommerce and Mobile

Chip and PIN eCommerce and Mobile
Click to Inquire

Kapersky Calls for Mass Adoption of Card Readers

Kapersky Calls for Mass Adoption of Card Readers

Translate This Blog

BobCaps

Search ePayment News (example: NFC)

About Me

My photo
Named one of the best Payment Industry News Blogs 4 Years Running

Feedjit

My Zimbio