Only the later seems to enforce SSL. I registered a dummy account on photobox, username/password/email, via their form which was not using ssl.
Only the later seems to enforce SSL. I registered a dummy account on photobox, username/password/email, via their form which was not using ssl.
Coupled with the tone of the job advert already posted by others [5], it doesn't seem too hard to imagine a corporate culture where security is not a serious concern until things go wrong.
[1] http://www.bbc.co.uk/news/business-14275632
[2] http://www.pcpro.co.uk/news/security/360163/photobox-sorry-a...
[3] https://twitter.com/PhotoBox/status/20719242964
[4] http://blog.dave.org.uk/2006/06/more-password-s.html
[5] http://careers.photobox.co.uk/security-officer-moonpig/
[edited for clarity]
Unrelated horror unfolded a couple of years later when for some peculiar reason he had to move the site to a godaddy VPS. An unencrypted customer database sitting at /db.sql, fully accessible to the world. Apache had been configured to show directory indexes and, to take the site offline, /index.php had been removed. I think at the time I even needed to explain the possible consequences. I just remember being told that the database was restoring and it wouldn't take too much longer!
I think any remaining part of me that implicitly trusted interesting websites with personal data died that day.