Caravan and Motorhome Club's website down!

Everything will be voip shortly no analogue or digital. All BT exchanges will be switched off.

A disaster waiting to happen when there are power outages. Very worrying for vulnerable old people who rely on pushing their Careline red button in an emergency and can't use smartphones.
 
Had an email today from the CCC to say that they are closing their forum and interactive discussions should be through Facebook! Not that their forum was very active. I wonder if the CAMC will take this opportunity to close the CT forum?
 
CAMC never hold card details, they are processed by I think World Pay. If the deposit is all thats paid, then that financial transaction has been and gone and the card details not held. If you are paying the balance on arrival I presume you pay at reception or via the App. According the their privacy Policy they do not hold card details but do hold bank account details. They state that they are PCI DSS Compliant.

How does the Club manage to take the balance before I arrive on site if it doesn't hold my card details for several weeks?
 
The costs of recovery can be significant and some systems/ data may never be recovered. Backups, whilst often taken, are rarely tested and often fail on attempted recovery. Any online networked backups will have been targeted by ransomware in any case, they always are.

The access pathways for such attacks are generally always the same, it's either an exploit of unpatched systems, use of insecure protocols/ weak ciphers, misconfiguration of controls, or wetware failure (e.g. clicking a phishing link).

Personally, my money's on the wetware.

I feel for the IT guys at the sharp end trying to clean up the mess - always a tough gig.
so do i. not

Subscribers  do not see these advertisements

 
How does the Club manage to take the balance before I arrive on site if it doesn't hold my card details for several weeks?
They don't keep the card details, they keep a transaction reference to a code held by Worldpay who hold your card details. The reference is then used to initiate a payment. The code is unique to you but meaningless to anyone who manages to see it, if indeed they are able to see it.
 
Unless you are using the same email/password across multiple services then you are relatively safe unless you are on one of those service. If you use the same password then slap your own wrists and get working.

Can't be arsed with a million different passwords to remember. I know you can get password safes etc but it's another layer of hassle. I use Google password manager but it is not always fool proof when moving devices and doesn't work on some sites.

Anyway, all my important passwords are 2 step verification, banking ones have even more steps to go through, most of my stuff is fingerprint verification. I don't see the loss of
one password as a major risk.
 
I don't see the loss of
one password as a major risk.
Your choice. But if that one password escapes you would need to go through every single site and change every single password. with a unique password on each site you only need to update one.
I have had zero problems with password managers. BUT I also use a YubiKey wherever I can as an additional layer of protection.
 
Your choice. But if that one password escapes you would need to go through every single site and change every single password. with a unique password on each site you only need to update one.
I have had zero problems with password managers. BUT I also use a YubiKey wherever I can as an additional layer of protection.
Ditto, use a password manager = saves time long term

Yubikeys are great and I'd caveat that one with - don't do what I did and lose a YubiKey -> I've learnt from experience and now have 3 with one being in safe as a backup, one being on my keyring, and the third travelling in my emergency "bag" for if I need to grab and go somewhere, which makes me not forget it when going somewhere on a plane where I don't carry my keys .... :) Getting access back when you lose (and you only have one) is a right pain. But now I have 3, I always have one "close" to me.
 
I don't think there's anything to worry about on the delayed booking payment side. I suspect it's this http://support.worldpay.com/support/kb/bg/businessmanager/wh0145.htm

(Note the WorldPay URL isn't on a SSL certificate which is really shocking)

So the card payment is pre-authorised at point of order but left in a pending state. They can then finish the transaction at a later point in time. So there's no risk of payments going to the wrong place it would seem. It'll go to the clubs merchant account as if you'd paid there and then.

Subscribers  do not see these advertisements

 
I don't think there's anything to worry about on the delayed booking payment side. I suspect it's this http://support.worldpay.com/support/kb/bg/businessmanager/wh0145.htm

(Note the WorldPay URL isn't on a SSL certificate which is really shocking)

So the card payment is pre-authorised at point of order but left in a pending state. They can then finish the transaction at a later point in time. So there's no risk of payments going to the wrong place it would seem. It'll go to the clubs merchant account as if you'd paid there and then.
Thats an old link I think. Worldpay comes under the FISGlobal brand now since around 2019.
 
(Note the WorldPay URL isn't on a SSL certificate which is really shocking)
I agree, that is Shocking and negiligent. Letsencrypt certificates are free and there is absolutely ZERO excuse not to SSL everything these days.
 
I agree, that is Shocking and negiligent. Letsencrypt certificates are free and there is absolutely ZERO excuse not to SSL everything these days.
It is an old link. Worldpay is owned by FISGlobal since 2019. Looks like the old Worldpay pages are still up and running which is bad news I agree.

If you go to http://support.worldpay.com/ it will direct you to FISGlobal help pages.
 
Anyone with an iPhone can generate new passwords for each site they visit and they are stored in your KeyChain.

Subscribers  do not see these advertisements

 
It is an old link. Worldpay is owned by FISGlobal since 2019. Looks like the old Worldpay pages are still up and running which is bad news I agree.

If you go to http://support.worldpay.com/ it will direct you to FISGlobal help pages.
They had three viable options. And they chose none of them,
1) A URL rewrite in the webserver. where each page is redirected to the new one.
2) A 404 page or even taking down the site.
3) Installing a free letsencrypt cert.

They chose 4
4) Host it as non encrypted.

Even in 2019 free letsencrypt certs were available. I have been using them on my hobby site since at least 2015.

They should know better and do better.
 
Last edited:
They had three viable options. And they chose none of them,
1) A URL rewrite in the webserver. where each page is redirected to the new one.
2) A 404 page or even taking down the site.
3) Installing a free letsencrypt cert.

They chose 4
4) Host it as non encrypted.

Even in 2019 free letsencrypt certs were available. I have been using them on my hobby site since at least 2015.

The should know better and do better.
Absolutely agree, They have redirected the TLD worldpay.com to FISGlobal and left everything else behind. Poor show from a secure payments company.
 
In simple terms how does this work? Ta
I don't use Lastpass but Bitwarden.
In very basic terms -
  • you get the Bitwarden app and install onto mobile / computer / laptop / etc (https://bitwarden.com/)
  • you create a master password (this opens the Bitwarden app)
  • you create individual entries / passwords in Bitwarden
  • this means you only have to remember one master password (to open Bitwarden)
  • you use the entries in Bitwarden to open / access websites / etc
 
I don't use Lastpass but Bitwarden.
In very basic terms -
  • you get the Bitwarden app and install onto mobile / computer / laptop / etc (https://bitwarden.com/)
  • you create a master password (this opens the Bitwarden app)
  • you create individual entries / passwords in Bitwarden
  • this means you only have to remember one master password (to open Bitwarden)
  • you use the entries in Bitwarden to open / access websites / etc
Thanks, so can i use same passwords on pc/ phone/ tablet etc?
 
Thanks, so can i use same passwords on pc/ phone/ tablet etc?
Depends which password manager you choose.
I used lastpass but now use Nordpass and it’s across all my devices

Subscribers  do not see these advertisements

 
Thanks, so can i use same passwords on pc/ phone/ tablet etc?
I've got it installed on two desktops (Windows 10 and Linux Mint) , three laptops (Windows 10, Windows 11 and Linux Mint) and a mobile phone (Android).
One master password for all and they all sync via internet.

edit: ps you can set it up as an add-on to various web browsers and there's a MacOS version.
 
I used to use lastpass but moved to Bitwarden. Took a bit of getting used to but excellent in my view.
I'm still using lastpass until my (current) subscription expires. But like everyone it's synced across phone, tablets, PC. Means I don't have to worry, as wherever I change a password the rest get it.
 
I'm still using lastpass until my (current) subscription expires. But like everyone it's synced across phone, tablets, PC. Means I don't have to worry, as wherever I change a password the rest get it.
I moved from lastpass because of their security breach and rip off pricing for what they actually do. Bitwarden is 1/3rd the price.
 
I moved from lastpass because of their security breach and rip off pricing for what they actually do. Bitwarden is 1/3rd the price.
Was about to change from KeePass to Lastpass until I heard of their security breach so went with Bitwarden. Free, as well, if the Personal version fits your needs. (y) Obviously, a Business version for yourself required.

Subscribers  do not see these advertisements

 
Was about to change from KeePass to Lastpass until I heard of their security breach so went with Bitwarden. Free, as well, if the Personal version fits your needs. (y) Obviously, a Business version for yourself required.
I don't require the business version. But I appreciate their offering so pay for it. I do this a lot with opensource and freeware software. A small sum each year helps them keep going. And to be honest at $10 a year it would be churlish not to contribute.
 
I don't require the business version. But I appreciate their offering so pay for it. I do this a lot with opensource and freeware software. A small sum each year helps them keep going. And to be honest at $10 a year it would be churlish not to contribute.
You make a very valid point and maybe, given the minimal cost, I should have a wee look at that. (y)
 
Is the caravan and motorhome club web site still down ?
 

Join us or log in to post a reply.

To join in you must be a member of MotorhomeFun

Join MotorhomeFun

Join us, it quick and easy!

Log in

Already a member? Log in here.

Latest journal entries

Back
Top