Kayako logo
SupportSuite, eSupport and LiveResponse Discussion, troubleshooting and feedback related to Kayako's flagship support desk products SupportSuite, eSupport and LiveResponse.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  (#1) Old
cogorno Offline
New Member
 
Posts: 4
Join Date: Jun 2006
Security warning for Kayako customers - 22-06-2006, 09:03 PM

This is a warning to Kayako customers about the security of your member account.

Do *not* use a password that you've used anywhere else. The passwords are not secure.

The kayako staff gave out my password to another employee while I was on vacation! Make sure you don't use a password that is used anywhere else.

PS: Kayako people, you need to get your act together. This is the most *unprofessional* company I've ever delt with.
   
Reply With Quote
  (#2) Old
Digital Mayhem Offline
Community Moderator
 
Digital Mayhem's Avatar
 
Posts: 874
Join Date: May 2005
Location: Henderson, Nevada
22-06-2006, 10:08 PM

1) Kayako uses the latest Secure Socket Layer (SSL) protection technology to protect the members account area and Payment Gateway.

2) Kayako never gives out any passwords or account information to any third party..
   
Reply With Quote
  (#3) Old
Giray Offline
Member
 
Posts: 107
Join Date: Nov 2004
Location: France/Switzerland
23-06-2006, 04:10 AM

Quote:
Originally Posted by cogorno
The kayako staff gave out my password to another employee while I was on vacation! Make sure you don't use a password that is used anywhere else.
No such thing as 'another' employee. If it's an employee, it's an employee, de facto and basta.
Question: do you have reason to believe that your password and user id were used maliciously? If so, I believe we would all like to know. You've dropped an accusation on a public board. You either substantiate it or we assume you're blindly attacking the company.
   
Reply With Quote
  (#4) Old
User Name Offline
Member
 
Posts: 116
Join Date: May 2005
23-06-2006, 04:55 AM

Wait, let's get this straight. What does "another employee" mean? Are you saying that Kayako staff gave your password to another member of the Kayako staff, or are you saying that Kayako staff gave your password to another member of your company that was not yourself?

The former would be ridiculous to complain about; the latter would be a matter of concern.
   
Reply With Quote
  (#5) Old
darkhorse Offline
New Member
 
darkhorse's Avatar
 
Posts: 17
Join Date: Jun 2005
Location: Belmont, Ohio, USA
23-06-2006, 05:10 AM

From what he said it looks like Kayako staff gave out cogorono's password to one of his other employess (not withing Kayako itself)
While this is a concern, it is possible for this to happen in any organization. I can call my brother's cellular provider and if i supply his address and a some other identification information, they will tell me anything i want, heck, i could even order things on his bill if i was so inclined to do so.

The point i am trying to make is this: No matter what you do it is allways possible that someone else could pose as you and be given your passwords. Therefore follow the standard security guidelines. Dont use passwords between different providers. As much of a hassle as it is, this is the only way you can really ensure security with passwords for different services.


-------------------------------------------------
Jacob Feisley
Dark Horse Networks
-------------------------------------------------
   
Reply With Quote
  (#6) Old
cogorno Offline
New Member
 
Posts: 4
Join Date: Jun 2006
23-06-2006, 03:28 PM

Quote:
Originally Posted by XeSolutions
2) Kayako never gives out any passwords or account information to any third party..

That's just not true.

I have an email that was sent *from Kayako* to my coworker with my account details in it.

Kayako does *not* take customer account information seriously.

-Steve
   
Reply With Quote
  (#7) Old
cogorno Offline
New Member
 
Posts: 4
Join Date: Jun 2006
23-06-2006, 03:31 PM

Quote:
Originally Posted by User Name
Wait, let's get this straight. What does "another employee" mean? Are you saying that Kayako staff gave your password to another member of the Kayako staff, or are you saying that Kayako staff gave your password to another member of your company that was not yourself?

The former would be ridiculous to complain about; the latter would be a matter of concern.

Kayako gave my password to another Sun Microsystems employee so that he could log into my account.

The problem is that I used the same password on the Kayako site as some other passwords at Sun, which I had to change as soon as I found out that my password was compromised. If he were the malicious sort, he could have changed my payroll details or read my email.

Hence, my warning not to use the same password on kayako.com sites as any other password that is important to you. Yes, I know that you should use different passwords for every site as a matter of general security. But it isn't really practical to rememebr hundreds of passwords.

-Steve
   
Reply With Quote
  (#8) Old
cogorno Offline
New Member
 
Posts: 4
Join Date: Jun 2006
23-06-2006, 03:36 PM

Quote:
Originally Posted by darkhorse
The point i am trying to make is this: No matter what you do it is allways possible that someone else could pose as you and be given your passwords. Therefore follow the standard security guidelines. Dont use passwords between different providers. As much of a hassle as it is, this is the only way you can really ensure security with passwords for different services.

Yes, you're right that someone could pose as me, but in this case, he clearly said who he was and they sent him the password and said "oh, just log into his account."

First of all, I'm shocked that the passwords are even *visible* to Kayako staff. Passwords should always be encoded in a one way hash.

And yes, I agree with you that passwords shouldn't be duplicated between sites. You don't know what people are doing with those passwords. But with so many accounts every, it's just not that practical to have different passwords everywhere.

But surely I will not use the same password on Kayako sites that I've used anywhere else.
   
Reply With Quote
  (#9) Old
User Name Offline
Member
 
Posts: 116
Join Date: May 2005
27-06-2006, 02:38 PM

Quote:
Originally Posted by cogorno
Kayako gave my password to another Sun Microsystems employee so that he could log into my account.
-Steve
That is a serious problem. You deserve an apology from Kayako, I believe. Regardless of how the customer handles his or her own passwords, the seller should take the utmost care when handling them.
   
Reply With Quote
Reply

Tags
customers, warning

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
problem ! graziano68 SupportSuite, eSupport and LiveResponse 2 08-11-2006 07:07 AM
Swift CLI problem joshopkins SupportSuite, eSupport and LiveResponse 2 02-09-2006 06:12 AM



Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
vBulletin Skin developed by: vBStyles.com


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46