WARNING! Aspire and Anyvape bad practice

If you have had an account on Aspire-Wholesale.com or Ecigaspire.co.uk it was left wide open with the company Anyvape publicly displaying a password.

Screenshot-2018-6-19%20Anyvape%20-%20Professional%20E%20Cigarettes%20Designer%20Manufacturer%20Aspire%20Official%20Partner

My account, if you knew my email, was left wide open so I decided to use their live chat to message them

Screenshot-2018-6-19-My-Account

Bad practice IMO, very very silly

8 Likes

Did they ever respond to you?

3 Likes

Nope, chat timed out…

We are talking about wholesale accounts as well as your regular customer… Terrible

5 Likes

Wow…this category is important, the only way you can get the attention of these companies is hurting their bottom line, and that’s pretty sad

5 Likes

It worked, too. Found out some stuff about Grubby I didn’t know!

5 Likes

But seriously though… While it may be a difficult task to guess a user’s email to sneak in there, it isn’t impossible. Especially say you’re a mod at a vaping forum, with access to all the registered user’s email addresses. You could just blast your way in, if you felt like it. This is a Security 101 blunder bigtime.

4 Likes

The original site had a lot of users, it was a big site for aspire UK, I used to use it a lot, this day and age they could have mass emailed all individuals quite easily requesting a password reset, this happened in 2017… :confounded:

4 Likes