• SONAR
  • Cakewalk, Single Sign On and You (p.6)
2014/07/27 11:34:27
Willy Jones [Cakewalk]
Hi azslow,
 
Great points and valid concerns. I'll try to address each of them - if I miss anything or just totally missed the entire point please let us know.
 

But what I always try to understand are consequences. What a hacker gets in case Cakewalk Store account is hacked? 

 
Yes that is correct - if someone was to gain access to your account or our entire system the only thing they would have access to is serial numbers, registration codes, downloads, your email address and a shipping address if your purchased products through the store. Yeah that is a problem, your email address and shipping address is personal and sensitive data. We encrypt it whenever in transit to prevent man in the middle type of attacks and go to great lengths to keep it secure. When working with third parties for example that require a sample of our customer data to test functionality - we always use fake or dummy data. Most every Cakewalk employee's data is in our system as well, we take it seriously and treat it as if it was our own because well - it is.
 
Registration codes!

Honestly - I'm ok with that. That's a piracy problem for us, not a 'your banking or financial data was compromised' nightmare for you. 
 

what will happened in case throw hacked account my registration numbers become public?

 
Once it was identified (either by the user reporting it to us or through one of our security audits) that an account was compromised we would:
  1. Reset your account password and lock your account until someone from Customer Service spoke with you or you reset your password and re-validated your email address
  2. All of your serial numbers would be added to our 'known pirated blacklist'. This would prevent them from being used for updates, tech support or registering
  3. We would re-issue serial numbers for your products
This is no different than what we do today right now if a similar situation arises with a user's account.
 

Will Cakewalk accuse me for publishing these number, and so make me responsible for illegal distribution of the products?

No of course not. What could we possibly gain by upsetting a user who was the victim of fraud or hacking? That would neither help the victim or help us retain a happy customer.
 

That is why I am not permanently logged into my banking, PayPal, etc. But with account merging, Cakewalk a kind of forcing me to stay logged in.

Alex touched on it earlier but staying perma-logged into an account isn't insecure provided you're doing it from your own computer. Most financial/banking sites will auto-log you out after a certain period of time, that's not because its insecure to be logged in it's because they don't trust that you're using a personal computer and aren't at a library or anything.
 
Specific to Cakewalk Accounts - nothing that we are changing requires you to stay logged into PayPal or your banking services. If you would prefer to not stay perma-logged in to those services then by all means sign out. This change has nothing to do with that.
2014/07/27 11:42:44
Willy Jones [Cakewalk]
bapu
 
Willy,
 
This forum account of mine is email1, my store account is email2. What exactly is going to happen to either accounts email address after I migrate?
 
For the moment, leave out the fact that I do have other "band" forum accounts and that misguided "The Bapu" forum account. 
 
Oh, BTW, my passwords are password1 and password2. That's to make the hackers' job easier.



Bapu ol' pal - how did your post count get so high? I'll get on that now. 
 
In your situation what you'll want to do when migrating your forum account is simply provide your store email address. Your forum email address will remain unchanged from it's current one. We are intentionally not syncing email addresses between your forum and Cakewalk Account. This will allow folks to use a different email address for forum notifications, subscriptions etc than their primary shopping and contact email address.
 
Great call on the passwords I've been using 'abc123' and '123abc' - I'll update mine immediately to your more secure variants!
2014/07/27 11:46:15
bapu
Willy Jones [Cakewalk]
Bapu ol' pal - how did your post count get so high?

I was unemployed for about a year.
 
Willy Jones [Cakewalk]
I'll get on that now. 

Oh no, not again.....
 
Good to see you back Willy.
 
Now how can we get Seth and Ryan back?
2014/07/27 11:48:01
Willy Jones [Cakewalk]
Beepster
 
I'd also like to offer my opinion on the twitter, G+, FB syncing. Please keep that crap WELL separated from the main account. 



Thanks for the feedback and we hear you loud and clear. We're still looking into those other log in providers but we would not use them for any 'sync' features. We would only use it strictly as a login provider to make things easier for folks who use those services - we wouldn't scrape your fb contacts or anything annoying like that.
2014/07/27 13:40:03
Beepster
Thanks for the reply, Willy. I unfortunately am not grasping the nuances of your answer though (I can be a little slow on the uptake at times). I have sent a PM to avoid causing any extra confusion in the thread but you may be busy dealing with the implementation of all this. If there are any other Bakers monitoring this thread and know Mr. Jones is too preoccupied to answer my specific silliness then perhaps they can help get me sorted out instead. Otherwise I will just keep an eye on my inbox. I would however like to get this figured out before the deadline tomorrow (preferably this afternoon). Sorry to be a pain.
 
Thanks.
2014/07/27 14:44:16
Splat
The only thing I disagree with is the situation with the coffee house. In my opinion it should be seperate, abolished, cast away onto a lonely island somewhere (Australia?). A massive firewall built inbetween. Regular forums posters will need to agree via terms and conditions never to speak about it again...
2014/07/27 15:01:35
Beepster
It's getting a little late in the day here, guys. Hoping to fix this before tomorrow. I will have to stop logging into either account if the changes happen before I get an answer. Granted ya'll wouldn't have to listen to my incessant blathering here on the forum however it would kind of suxxor for the ol Beep here.
 
:-/
2014/07/28 09:05:20
UbiquitousBubba
CakeAlexS, 
 
I was thinking Antarctica might be a better choice. I mean, that's a pretty cruel thing to do to Australia. Unleashing that mess on the local population is probably against International Law. I'm not sure how well all of the pretentious elitists who reside upstairs will like the cold, but I'm sure they'll convince themselves that they prefer it that way. I look forward to all of the posts about the acoustic superiority of studios carved out of the ice. The pictures should be amazing.
 
Oh. On second thought, you probably meant that you'd like to banish the Coffee House instead. Right. It's a good thing that we've got all the coffee and becan. 
2014/07/28 09:13:22
Splat
Lol agreed :)
2014/07/28 09:17:03
Beepster
Don't look now Bubba but you're upstairs right now too.
 
TWO PLACES AT ONCE!! TRANSDIMENSIONAL HAMSTERS!!! THE END IS NIGH!!!
© 2026 APG vNext Commercial Version 5.1

Use My Existing Forum Account

Use My Social Media Account