Post your tech glitches, errors, issues, etc. here.

1119120122124125144

Comments

  • AliceBastable
    AliceBastable Member Posts: 3,461
    edited May 2022

    Over two months of crap, and only a few minor improvements but countless new screw-ups. I think it's time for BCO to ditch the forums completely and stop pretending and stringing everyone along.

  • Beesie
    Beesie Member Posts: 12,240
    edited May 2022

    AliceBastable, as I've been reading the recent posts on this thread, I came to the same conclusion as you. BCO should just stop this, now. The situation is getting worse, not better.

    I can't imagine how frustrating this must be to newbies who really need help and advice and support now, and instead find all their diagnosis information to be screwed up and find few if any people responding to their posts. As we all know, it's extremely stressful going through the diagnostic process and being newly diagnosed; it is irresponsible of BCO to have a discussion board that patients come to expecting support, only to find that being on the site increases their stress and frustration.

    Perhaps the best option is to close all but the 'social' threads and the Stage IV forums and to use these forums to gauge how the site is doing. Once everything is running smoothly in these forums (if that ever happens), the rest of the site can be reopened.

  • MinusTwo
    MinusTwo Member Posts: 16,634
    edited May 2022

    Interesting idea Beesie. I hope BCO will at least consider it. Oh - and edited to say - let us know what they think, or even better what they plan.

  • Spookiesmom
    Spookiesmom Member Posts: 9,568
    edited May 2022

    The best made plans of men and mice go down the sewer.Why would BCO be honest and share?

  • katg
    katg Member Posts: 108
    edited May 2022

    I am not sure what tech people they used to help on this website, but I only joined i think in September of 2021. I registered as k-gobby. I cannot log into that one, as ti does not recognize my emails. So it made me join again as kgob. Now as i said it lets me post and i have a K next to my name, but when i try to change my diagnosis info it says to log in.

    I hope a moderator will come on and give me some answers. I sent a message already.I agree with what has been said, as this is a mess. I am not going to join for a third time. I will just keep posting with 1/2 the wrong info under my name!!!

  • Spookiesmom
    Spookiesmom Member Posts: 9,568
    edited May 2022

    Does anyone know what city BCO is in? And is anyone from that city? Had a thought that if someone could contact the local news, ask them to check into BCO failure and donation request. Then, if that happens, put it on air. Maybe the national media would pick it up.

    Bet this site would be fixed in a rad zaps time.

  • Anonymous
    Anonymous Member Posts: 1,376
    edited May 2022

    Mods (in Philadelphia),


    You haven’t posted to this thread since Thursday morning. It’s been 4 days with people posting issues and no response from you.



    I noticed the “Work in progress” pop up is gone entirely. With the release notes rescheduled to every 2 weeks rather than weekly, have you stopped working on the “glitches”? Is the faulty website “as is” until the new platform? Is this your way of saying you’ve moved on? Should we?



    On images -I noticed a few members are able to post images. Please specify what is allowed because most members cannot post images.
  • Anonymous
    Anonymous Member Posts: 1,376
    edited May 2022

    🤬🤬🤬

    I just learned why they disabled images. A data safety org found BCO had our images exposed (possibly for years), but they didn’t respond to notifications for over 5 months!

    Here’s the text. The safety org recommends filing a consumer complaint to the Pennsylvania Attorney General.

    ————

    Breast Cancer Support Organization Leaks Data Despite Multiple Notifications?

    Update: After posting this, tweeting this story, and getting retweets on it, it appears that as of late yesterday, the bucket was finally secured. Thanks to SafeyDetectives who kept re-checking the bucket and to everyone who tried to call attention to this to get the data locked down. DataBreaches did not get any acknowledgement or response from BreastCancer.org — at least not yet. DataBreaches has not changed its opinion that an investigation is needed to determine for how long these data were exposed, whether they were accessed and downloaded, and why BreastCancer.org failed to respond to multiple notifications over a period of five months.

    SafetyDetectives recently reported that Breastcancer.org has been exposing sensitive information in a misconfigured AWS bucket. According to their report, exposed data included more than 50,000 registered user avatars and more than 300,000 post images with EXIF data.

    Some post images featured sensitive content that felt as though it was intended for private viewing. For example, there were results from medical tests and images of nudity (most likely taken for medical purposes) included among the files — contents that a user would not typically post publicly.

    The data may have been exposed for years.

    Read more on SafetyDetectives.

    One point that wasn't clear from SafetyDetectives' report was whether the bucket had been secured. SafetyDetective started reaching out to BreastCancer.org in November of 2021. They describe their multiple efforts but no outcome was reported. DataBreaches reached out to SafetyDetectives and received the following reply:

    … unfortunately the bucket is still unsecured, we tried reaching the organization several times to different email addresses (including their privacy email, CEO, and basically all the people on their about page), we even reached out via social media (we tried reaching them publishing a post, because they don't accept private messages), but they haven't reply back. We reached out to the US CERT but they didn't reply and AWS did reply, but the thing is that they cannot actually secure the bucket, but to tell the owner that they need to secure it.
    We published our report hoping that they would reach out to us to secure it but they haven't gotten back to us yet.

    So more than 5 months after responsible disclosure attempts began, the bucket was still unsecured. DataBreaches reached out to BreastCancer.org through their website contact form, and like SafetyDetectives, got no reply.

    DataBreaches left them a second message on their site telling them that we would be reporting in 48 hours and to lock down their data. There was no reply and the bucket was not secured.

    At 8:00 am this morning, DataBreaches left a voicemail on their office phone. It reiterated that people had been notifying them for months but they had failed to lock down their Amazon storage bucket and that DataBreaches would be reporting on it this afternoon.

    Still nothing, it seems.

    The organization's privacy policy page contains this statement:

    How We Protect Your Information

    We use reasonable and appropriate administrative, technical, and physical safeguards to protect the information that we have about you from loss, theft, and unauthorized use, access, modification, or destruction. We also require third-party service providers acting on our behalf or with whom we share your information to maintain security measures in accordance with industry standards.
    Although we have security safeguards in place, we cannot guarantee absolute security in all situations. If you have any questions about our security practices, please contact us as described in the "Contact Us" section. For your own security, please do not send any confidential personal information to us outside of our Services. It is also important that you maintain the security and control of your account credentials, and not share your password with anyone.

    Except that they don't respond to contacts.

    Pennsylvania regulators need to look into both the lack of security and BreastCancer.org's failure to respond to repeated notifications that they were exposing personal and sensitive information.

    If you wish to contact the Pennsylvania Attorney General's Office to file a consumer complaint, you can find information and an online complaint form linked from here.

    If anyone has a contact at BreastCancer.org or has influence with them, perhaps you could reach out, contact them, and tell them to lock down all that sensitive information already!

    And if you ever used their site and shared personal and/or sensitive data, perhaps you should contact them and demand that they secure your data.

  • Anonymous
    Anonymous Member Posts: 1,376
    edited May 2022

    BCO,

    We require a response on this data breach and why you failed to respond to their repeated notifications.

    Please drop your plans for us to give you our medical data.

  • Anonymous
    Anonymous Member Posts: 1,376
    edited May 2022

    Everyone,

    I encourage you to try to delete your diagnosis and treatment details.

    I use the Signature to display my info. It’s harder to use for them because it’s a free form text field. Add emojis because they make it even harder to parse.

  • exbrnxgrl
    exbrnxgrl Member Posts: 12,424
    edited May 2022

    Thank you, serenity. If anyone ever seriously considered releasing their medical data to bco, which is beyond my imagination, this is serious reason to reconsider. The obfuscation and outright lying by bco is getting very difficult for me to deal with.

  • wrenn
    wrenn Member Posts: 2,707
    edited May 2022

    We've been Dr. Ozed


  • Anonymous
    Anonymous Member Posts: 1,376
    edited May 2022

    BCO,

    Answer this below:

    DataBreaches did not get any acknowledgement or response from BreastCancer.org — at least not yet. DataBreaches has not changed its opinion that an investigation is needed to determine for how long these data were exposed, whether they were accessed and downloaded, and why BreastCancer.org failed to respond to multiple notifications over a period of five months.

  • wrenn
    wrenn Member Posts: 2,707
    edited May 2022

    I still believe their intention was to do away with the forum and focus on the data sharing and be seen as a health provider. Forums don't bring in much $$$ and are a nuisance. This one will never bring in cash now so they gave up.

    If anyone wants to set up a proboards I will help with it. I don't trust my brain with set up. You can PM me if their is a simple way to start.

  • Cowgirl13
    Cowgirl13 Member Posts: 1,936
    edited May 2022

    spookiesmom, I totally agree. Contacting the media and having them run with it is the only action, I believe, that will generate a solution to this mess. Anyone have media contacts?

  • Anonymous
    Anonymous Member Posts: 1,376
    edited May 2022

    I’ve asked the writer who did the glowing article about the redesign to follow up on the data breach.

    https://twitter.com/serenity_soon/status/1523703862724481024?s=21&t=x7lnNFqpfZO2bVraC9KOGQ


  • Moderators
    Moderators Member Posts: 25,912
    edited May 2022
    Hello everyone, we reported on the image issue last week, took immediate action to address any potential security risk to Breastcancer.org, and are close to restoring access to images. We do understand your frustration, and hope you know that we are putting our resources toward making improvements as quickly as we can.
  • Anonymous
    Anonymous Member Posts: 1,376
    edited May 2022

    FIVE MONTHS OF NO RESPONSE IS NOT IMMEDIATE ACTION!

    AANSWER THEIR QUESTIONS!

  • Moderators
    Moderators Member Posts: 25,912
    edited May 2022

    We're continuing to track and report technical bugs. The team is working to repair issues and the Release Notes page will be updated every two weeks. Meanwhile, the mods will be here to help you and keep you posted. We're here for you.

  • Anonymous
    Anonymous Member Posts: 1,376
    edited May 2022

    Mods,

    Are you in touch with anyone in this Twitter thread to help lock in our data?

    https://twitter.com/trevorgiffen/status/1522243930565324804?s=21&t=PgF9UwXbXVAmc7W1agOmuA

    “For healthcare and similarly sensitive entities, next time reach out to @CuratedIntel before publishing a blog, and we'll take care of it. Cheers! “

    If not, you should be. I see some people are able to post images. If that’s not intentional, then we still have serious issues.



  • Anonymous
    Anonymous Member Posts: 1,376
    edited May 2022

    You’re gaslighting me.

  • Anonymous
    Anonymous Member Posts: 1,376
    edited May 2022

    Why did no one from BCO respond when notified of the data breach? They tried to contact you for over 5 months. Multiple times.

    Why?

  • AliceBastable
    AliceBastable Member Posts: 3,461
    edited May 2022

    BCO credibility is completely shredded but they're having the Mods (otherwise known as the Mouth of Sauron) repeatedly post "It's only a flesh wound."

    Sorry for mixing my fantasy metaphors.

    I wouldn't trust them with my dog's vet records.

  • Anonymous
    Anonymous Member Posts: 1,376
    edited May 2022

    Your tech team does not appear to have the expertise required to lock in our data.

    Accept the help from the experts.

  • Anonymous
    Anonymous Member Posts: 1,376
    edited May 2022

    “Pennsylvania regulators need to look into both the lack of security and BreastCancer.org's failure to respond to repeated notifications that they were exposing personal and sensitive information.

    If you wish to contact the Pennsylvania Attorney General's Office to file a consumer complaint, you can find information and an online complaint form linked from here.

    If anyone has a contact at BreastCancer.org or has influence with them, perhaps you could reach out, contact them, and tell them to lock down all that sensitive information already!

    And if you ever used their site and shared personal and/or sensitive data, perhaps you should contact them and demand that they secure your data.”

  • Anonymous
    Anonymous Member Posts: 1,376
    edited May 2022

    Mods,

    If you can’t admit that you failed to respond to their data breach notifications, then I will fill out a complaint form. I’m in Canada, so I don’t know if it will make a difference. But most of us are in the US.


  • Beesie
    Beesie Member Posts: 12,240
    edited May 2022

    Well, holy crap, Batman. The $#!+ has certainly hit the fan since I last visited the site.

    It's interesting to learn that members of the discussion board are not the only ones who've been ignored by BCO when we complain. We've only been at it for 2 + months. This very serious security breach was ignored for 5 months. I suppose we should feel better then, knowing it's not just us. Seriously, this is both unbelievable and frightening.

    I have already removed all my personal information from the site, except for my posts. I'm tempted to delete my membership but that would delete all my posts, which would be a shame.

    BCO executives better step up to the plate soon, before BCO's reputation and website is completely destroyed. And to be honest, it sounds like a clean sweep of the executive offices may be the only way to recover from this.


  • wrenn
    wrenn Member Posts: 2,707
    edited May 2022

    I wonder if the same level of gaslighting would occur if the topic was brought to their Facebook, Instagram and Twitter sites

  • Anonymous
    Anonymous Member Posts: 1,376
    edited May 2022

    Beesie - We don't know how long our data have been exposed. BCO has not answered that question. Could be years. I don't really worry about my data. I deleted the few pics with my face years ago. But what about any images posted in the reconstruction threads? BCO has not answered if any images were downloaded. It's an extreme violation that they don't seem to understand and are brushing off as an “issue”.

  • Anonymous
    Anonymous Member Posts: 1,376
    edited May 2022

    I don’t have FB, but the mods did respond here when I posted a link that I asked on Twitter for Fast Company to follow up on the data breach.

Categories