Results 1 to 15 of 15
  1. #1
    AE-Martyn is offline Former AM
    Join Date
    March 2008
    Location
    Manchester
    Posts
    2,050
    Blog Entries
    3
    Thanks
    637
    Thanked 763 Times in 434 Posts

    Exclamation Affiliate Account Security

    Hi all, following on from recent affiliate account hijackings, I've arranged a meeting with our techies tomorrow.

    What I am looking for is suggestions from you guys and girls as to what you'd like to see in place to help us protect you better. Even if your password is compromised, what can we do to stop them changing your payment info?

    We've got a list of ideas here to discuss on top of the security measures that we have in place, but as AE was built with the input from affiliates I'm throwing it out there for your suggestions.

    Whatever you think of, throw it out there and we'll see what we can do.

    We hate these guys as much as you do, so lets defeat them so they never get the chance to hijack your commissions again.

    Let me know by posting below and hopefully we can get some good ideas flowing and implement some of your suggestions very soon.

    Begin.......

  2. The Following 3 Users Say Thank You to AE-Martyn For This Useful Post:

    Anthony (10 September 2014), Anthony-Coral (11 September 2014), dfiocch (10 September 2014)

  3. #2
    -Shay- is offline Public Member
    Join Date
    November 2012
    Posts
    3,061
    Thanks
    12,175
    Thanked 3,133 Times in 1,685 Posts

    Default

    Renee's company seems to be on the lead lap with their precautions. I personally like that your company is taking the time to beef up security as well.

    Well done, MartYn!

  4. The Following 3 Users Say Thank You to -Shay- For This Useful Post:

    AE-Martyn (10 September 2014), Anthony-Coral (11 September 2014), Renee (10 September 2014)

  5. #3
    thebookiesoffers is offline Former Member
    Join Date
    November 2009
    Location
    Leicester, UK
    Posts
    3,225
    Thanks
    412
    Thanked 1,764 Times in 1,009 Posts

    Default

    have contact details separate like a phone number, if payments change the person must be rang, answer a security question and asked they made the change.

    fair plays to bet365 they emailed straight away when my payment info was changed by me

  6. The Following 2 Users Say Thank You to thebookiesoffers For This Useful Post:

    -Shay- (10 September 2014), AE-Martyn (10 September 2014)

  7. #4
    JackTenSuited is offline Private Member
    Join Date
    March 2004
    Posts
    1,013
    Thanks
    23
    Thanked 334 Times in 207 Posts

    Default

    simply sending an email to confirm payment info/personal details updates would help.

  8. The Following 2 Users Say Thank You to JackTenSuited For This Useful Post:

    AE-Martyn (10 September 2014), Sherlock (12 November 2014)

  9. #5
    AE-Martyn is offline Former AM
    Join Date
    March 2008
    Location
    Manchester
    Posts
    2,050
    Blog Entries
    3
    Thanks
    637
    Thanked 763 Times in 434 Posts

    Default

    Don't get me wrong, we have measures in place to help protect affiliates. Affiliates should be contacted every time details are changed, we have IP restrictions, automated emails and details must be confirmed by us before details are changed/confirmed. But on the rare occasion that one slips through the net we want more ways of snagging the baddies.

    Phone calls are a great idea, we just need the affiliate to provide us the correct details, not everyone does.

    Keep them coming though, all good stuff to think about.

  10. The Following User Says Thank You to AE-Martyn For This Useful Post:

    -Shay- (10 September 2014)

  11. #6
    dfiocch's Avatar
    dfiocch is offline Private Member
    Join Date
    September 2006
    Posts
    875
    Thanks
    787
    Thanked 565 Times in 348 Posts

    Default

    SMS

    Obviously after a phone number verification

  12. The Following User Says Thank You to dfiocch For This Useful Post:

    AE-Martyn (11 September 2014)

  13. #7
    dfiocch's Avatar
    dfiocch is offline Private Member
    Join Date
    September 2006
    Posts
    875
    Thanks
    787
    Thanked 565 Times in 348 Posts

    Default

    -or/and-

    a pin number (secret) before any change in affiliate profile

    Neteller uses a system like this and I see it very effective

  14. The Following User Says Thank You to dfiocch For This Useful Post:

    AE-Martyn (11 September 2014)

  15. #8
    TheGooner's Avatar
    TheGooner is offline Private Member
    Join Date
    March 2007
    Location
    New Zealand
    Posts
    4,563
    Thanks
    2,092
    Thanked 4,533 Times in 2,175 Posts

    Default

    While passwords should be secure they are used often by an affiliate (daily stats checks?) and so can be compromised by keyboard loggers, and/or exposed by router hacks, or even simply broken at another affiliate site and then used here ... because despite warnings many people still use duplicate login details at multiple places.

    So - additional security for important changes is a good idea :
    1/ Having a separate passcode or challenge question for important changes (account payment details / contact details) seems a good step.
    2/ Providing an SMS text challenge number (that must be entered to accept changes) is also an option - if people provide cellphone details.

    Depending on the volume of changes though - the best option may be a simple manual check.

    If changes are made to (account payment details / contact details) then if the affiliate program send an manual email to the old address to confirm the changes are genuine. These changes are not made often - and it might be a good thing for AM and affiliate to actually communicate?

  16. The Following 5 Users Say Thank You to TheGooner For This Useful Post:

    -Shay- (10 September 2014), AE-Martyn (11 September 2014), Anthony-Coral (11 September 2014), Renee (10 September 2014), universal4 (10 September 2014)

  17. #9
    Anthony-Coral is offline Former Employee of Coral
    Join Date
    September 2008
    Location
    Gibraltar
    Posts
    1,217
    Thanks
    904
    Thanked 717 Times in 443 Posts

    Default

    We're looking at this issue as well at the moment. We haven't had any breaches but seeing the discussions and suggestions here means its an issue we want to address. Been impressed with Rewards Affiliate's set up, and the suggestions from Gooner are all things we'll be taking into consideration.

    Its probably long over due that the decent operators/programmes got some agreement on security best-practice in this area.

  18. The Following 2 Users Say Thank You to Anthony-Coral For This Useful Post:

    -Shay- (11 September 2014), Renee (11 September 2014)

  19. #10
    MMM
    MMM is offline Private Member
    Join Date
    October 2014
    Posts
    1,757
    Thanks
    463
    Thanked 715 Times in 499 Posts

    Default

    I think 2 simple steps will prevent actually sending money to someone else:
    the main email on the account should be locked and could be changed only by you guys. If we would like to change the mail- we will contact you. I don't think it will complicate things much.
    Second: alert on new payment method entered- by email to us and also some notification for you to notice.

    Pay special attention to webmoney - their fraud dep is not the best, to say the least and it's almost impossible to do something after the payment is sent.
    Best casinos to play slot machines online for real money. Reviews of best Real Money Casinos online.
    Check OnlineBlackjackExplorer for ratings of the best casinos to play blackjack online. Which games offer the lowest house edge, as well as free blackjack games, live dealer and mobile blackjack sites.

  20. #11
    Renee's Avatar
    Renee is offline Sponsor Affiliate Program
    Join Date
    August 2005
    Posts
    9,072
    Blog Entries
    6
    Thanks
    6,642
    Thanked 3,543 Times in 2,206 Posts

    Default

    Quote Originally Posted by MMM View Post
    I think 2 simple steps will prevent actually sending money to someone else:
    the main email on the account should be locked and could be changed only by you guys. If we would like to change the mail- we will contact you. I don't think it will complicate things much.
    Second: alert on new payment method entered- by email to us and also some notification for you to notice.
    This is exactly how our system works, except the affiliate will receive either one or two emails, depending on whether we can verify the info. If the details they enter are not a match for the details they had in their account (eg they changed to a neteller account in a different email to the one in their account) they will get 1 email when they change the details and another email from either myself of Celia asking them to confirm the changes. As the email on file cannot be changed by the affiliate, we know we are emailing the right person.

    If we cannot get the affiliate to confirm they made the changes, we don't pay.

    We have copped flack for it from affs previously who don't bother replying to our emails about it saying we held their payment on purpose because we don't want to pay, but I'd rather hold the payment than pay to the wrong account. And really, if we are writing an email with subject payment changes, you should really be reading those.
    __________________
    Renee, Affiliate Program Manager
    http://www.RewardsAffiliates.com
    Affiliate Program for CasinoRewards.com
    Best Affiliate Manager - CAP Awards 2008
    Best Casino Affiliate Manager - CAP Awards 2009
    Best Casino Affiliate Manager - iGB Affiliate Awards 2010

  21. #12
    Sherlock's Avatar
    Sherlock is offline Public Member
    Join Date
    December 2013
    Location
    WC
    Posts
    4,943
    Thanks
    1,410
    Thanked 3,811 Times in 2,154 Posts

    Default

    Quote Originally Posted by deanimus View Post
    simply sending an email to confirm payment info/personal details updates would help.
    Just that please. Not additional phone verifications or sms or at least not obligatory.

    - The email should be covered at least with some *******, e.g. myemail@gmail.com would be like m*****l@g***l.com inside affiliate interface. Then even if the affiliate account is hacked, and same/similar password would be used, the email would not be known to attacker.

    - Disable account after few login attempts for few minutes.

    - Show last IP's from which affiliate account was acessed.

    No need to invent wheel, be inspired by domain registrars.
    If you talk to God, you are praying; If God talks to you, you have schizophrenia.

  22. #13
    Casino Online Rating's Avatar
    Casino Online Rating is offline Private Member
    Join Date
    March 2014
    Posts
    322
    Thanks
    85
    Thanked 115 Times in 86 Posts

    Default

    Quote Originally Posted by Sherlock View Post
    Just that please. Not additional phone verifications or sms or at least not obligatory.
    I think voluntary 2-step verification would be a good thing, be it by sms or e.g. a token app (one time password generator). I know some people find it to be a hassle, but it significantly raises account security.

    A pretty good system that I also saw used in some MMO video games is that when you log in for the first time the system asks you if this is your main IP and you want it to be saved. Then, every time you or someone else log in or even tries from a different IP, you get an email informing you of that to ensure this was you.

  23. #14
    Sherlock's Avatar
    Sherlock is offline Public Member
    Join Date
    December 2013
    Location
    WC
    Posts
    4,943
    Thanks
    1,410
    Thanked 3,811 Times in 2,154 Posts

    Default

    Yes the logging of IP's and whitelisting is very good measure as well. We use it in our internal system. No problems so far.
    If you talk to God, you are praying; If God talks to you, you have schizophrenia.

  24. #15
    TomPregon's Avatar
    TomPregon is offline Public Member
    Join Date
    November 2014
    Location
    UK
    Posts
    56
    Thanks
    10
    Thanked 21 Times in 16 Posts

    Default

    Quote Originally Posted by Renee View Post

    If we cannot get the affiliate to confirm they made the changes, we don't pay.
    That is really good in itself. But, in a worse case scenario: should the email address in this case be confiscated as well (which could be possible), the criminal could still have a chance. The only 100% water / fool proof system would be 'personal contact' either by Skype or preferably by phone. (Especially after a payment change request) Not often will these numbers 'get confiscated' the way email accounts and passwords etc. do. So perhaps don't pay until confirmation by either Skype or preferably by phone.

    Personally I have great relationships with the affiliate managers I work with. They would notify me of anything out of the ordinary before taking any action on my accounts. Should any details be changed, I'd know about it before anything serious can happen from it. I also have the agreement that I'd notify them on either Skype or phone about such big changes, if I were to ever make any. And, they'd know it is me talking to them too, at any time. We've become friends in many occasions, so: A good line of communication. I guess it is very important too.

    I (we) can not appreciate all of your security measures enough of course, they are of immense importance.

    Thank you.
    Online Video Poker: Play Single Hand Video Poker, 3 Hand Video Poker, 10 Hand Video Poker, or 52 Hand Video Poker. Today's top video poker games: Deuces Wild - Double Jackpot - Bonus Deuces Wild - Aces and Eights - Double Double Jackpot - For free or play real money video poker

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •