Silk Road forums

Support => Customer support => Topic started by: slymike on August 06, 2013, 08:56 am

Title: High Carts Disabled Vendor - sum1 just tried to get me to record keep?
Post by: slymike on August 06, 2013, 08:56 am
but i still have orders Processing can sum1 cancel them?
Title: Re: High Carts Disabled Vendor
Post by: samesamebutdifferent on August 06, 2013, 09:06 am
I'm not sure what you are asking? please elaborate.
Title: Re: High Carts Disabled Vendor
Post by: slymike on August 06, 2013, 09:26 am
i have 2 orders with highcarts
they have been sitting for 2 days
he 1st took all his stuff off now when i click on him it goes send message
so im assuming hes disabled his vending
was wondering if my orders would be able to get canceld
or would i have to wait for time to run out to cancel them
Title: Re: High Carts Disabled Vendor
Post by: samesamebutdifferent on August 06, 2013, 10:06 am
Have the orders been confirmed? i.e. marked 'in transit'?

If not you can cancel them yourselves after 4 days, if they were confirmed you will need to contact SR support and/or take them into the resolution center when you are able and resolve the matter there.
Title: Re: High Carts Disabled Vendor
Post by: slymike on August 06, 2013, 10:52 am
i just got a message from sum1 named BlueGiraff on silkroad site saying this
Dear BlueGiraffe Client,

This is an urgent notice.

There has been a massive breach of security due to the conjunctions listed below - further information here http://dkn255hz262ypmii.onion/index.php?topic=196608.0 (Please minimize further talk about it on the forums - as I wish to not give information that might further compromise things - happy to answer questions here).

1. I keep a document with all shipping addresses as verification for any re-ships. I know this is specifically against Silk Road’s terms, but I have always kept this totally protected (properly encrypted and completely hidden). I’ve been meaning to remove all personal information and just keep the stats, but had not gotten around to that yet.

2. I very recently hired a new assistant to help me process orders. She is totally trustworthy and has access to all documentation. However she made a profound error of judgement a couple of days ago. She was meant to email me the shipping information for the day – PGP encrypted and from one Tormail account to another. There was an issue with her PGP and she failed to get it sorted and so, as it was late in the day and she didn't want to miss the shipment deadline, decided to send it another way that she believed was totally secure, but which was not (I do not want to give further detail on the forum as these may compromise things further). She also somehow mistakenly managed to send all the history rather than just the day's orders.
3. Tormail was compromised shortly afterwards.

The circumstances and the timing could not have been more horrifically aligned, and I consider the shipping information compromised.

I take full personal responsibility for this. Whatever role my assistant played, I allowed it to happen. I am a professional and I have never been responsible for such a degree of fuck up in all my life, and I feel utterly gutted and destroyed from the betrayal of trust and care that I have just caused. I am deeply sorry.

The data does link names and addresses to SR usernames but does not refer to any specific product. While I consider it low probability that there will be any direct follow-up, I do highly recommend that you clean house and do whatever else is required to protect yourself.

Our account itself was not compromised from the Javascript exploit and everything is functional and secure. And of course the learning from the most painful kind of lesson is already being applied. I have already shared the details of this with DPR and have offered to walk the plank - and may yet depending on how this plays out.

Though we will never meet in person, you are part of a great family that I love and care for very much. And I have done the worst thing and compromised your safety. I am so sorry.

BlueGiraffe (neck hung in shame)
______________________________________
ive never brought from him before?
Title: Re: High Carts Disabled Vendor - sum1 just tried to get me to record keep?
Post by: samesamebutdifferent on August 06, 2013, 12:14 pm
I have no idea why you were sent that warning if you have not bought from that vendor. They did post that message in the forums earlier today, I suspect their admission to keeping buyers details resulted in their immediate demotion too.

I would suggest you contact SR support via the market site and inquire if there are any links between BlueGiraffe and the vendors you use. At the very least you should inform SR support you received this message, you may consider it necessary to take some precautionary measures all the same and assume your details have been compromised. Better to be safe than sorry, I would clean house if I were you.

Title: Re: High Carts Disabled Vendor - sum1 just tried to get me to record keep?
Post by: slymike on August 06, 2013, 12:39 pm
haha lucky i didnt use tormail xD
and changed all my sht when i saw that
Title: Re: High Carts Disabled Vendor - sum1 just tried to get me to record keep?
Post by: larry2times on August 06, 2013, 03:14 pm
is high carts related to that vendor who comprmoised information or not?