When I Contacted Carbonite to shut down my account...


Recommended Posts

Just contacted carbonite to have them delete all my data and close my account down, due to the lack of two factor authentication.....

 

I told him why I switched to something else, because of the lack of two-factor authentication. 

 

He said "When you say two-factor authentication what do you mean? Do you mean a security question?"

 

I got a gibsonian response that when you call them all you need to validate/ verify your identity with them is ..

 

The Last 4 of the credit card used with carbonite - which is Located and shown on your carbonite account

Name on Card - Which is Located and shown on carbonate account

Billing address Not located or shown on the account but my first and last name is, so they could just look my first and last name online, because in my case, there is only one of me  and then proceed to get my address.

 

They should really verify with information not located on the account.

 

If someone were to get into my account, they could contact carbonite with all the information and closed my account down.

 

The person over the phone let me know that they don't have access to the full card number. I said, well then on your end maybe show the last 6 and on the site show the last 4.

 

Just have some information which is not located on the persons account. After he closed my account, I told him that if someone got my email address and password THEY could have called on my behalf and shut my account down.

 

He said, well that's why your email address and password is important. I said, yes but you also issued a mandatory password  reset (by email with a clickable link no less), because you showed unauthorized logins to peoples accounts due to people using the same password everywhere.

 

 

3 minutes ago, xendrome said:

How would carbonite be able to verify information not on your account? That seems impossible for them to know information they don't have..

Like i said, on the carbonite account they mask all but the last 4 of the credit card ... at the carbonite office mask all but the last 6. That way anyone who logged into someones account would have to be in possession with the full credit card number to be able to validate the last 6 

Just now, warwagon said:

Like i said, on carbonite the mask all but the last 4 of the credit card ... at carbonite mask all but the last 6. That way anyone who logged into someones account would have to be in possession with the full credit card number to validate the last 6 

Oh you are speaking of the account information shown online to a user. If you mean they should have something in their CRM/Billing system like a pin that you would verify and not shown in the online account page, then I get it.

  • Like 2

Is carbonite the only online backup solution that actually restores files back to their proper place ? (as opposed to letting you download your system32 folder that was backed up prior, but it just creates a dump folder and puts things in there - not putting recovered files back in their original location)

I've had experience with Carbonite in the past, and it was a train wreck. They like to make themselves out as an Enterprise-grade data storage and disaster-proof recovery and backup solution, and they charge as such; but what I found was ineptitude and a complete lack of some fairly routine security and data handling measures that we here at Neowin (and pretty much anyone who's ever worked in IT) would do by default. Their Client Software is garbage. 

 

Yep. :( They're junk.

17 minutes ago, xendrome said:

Oh you are speaking of the account information shown online to a user. If you mean they should have something in their CRM/Billing system like a pin that you would verify and not shown in the online account page, then I get it.

There was also no way for me to remove my information from the site. I deleted the client from my computer. I talked with him and the only way, is to let the account expire, at which point after a certain number of days of weeks the data gets deleted. But because I switch to a more secure service which did offer two-factor I wanted my info GONE OFF THE CARBONITE, but there is no "Delete all my data" option.

 

Someone mentioned that if a bad guy got into your account they could also do that. Which is true, but as demonstrated above they can also just call them up on the phone. But as @xendrome mentioned have a pin setup at the time of the creation of the account, or password or really anything that you would then store somewhere, which would let you authenticate to the site, to Permanently delete your data.

 

and oh gee, if they would have had two-factor those accounts probably wouldn't have been compromised. Because of the lack of two-factor their security collapsed just like I thought it would.

We had this thread before when you were looking for solution with MFA?  Seems you found one - which one is it?

 

I am still curious to what exactly are you storing online that you feel requires MFA... I mean come on... Someone after your recipes and cat videos?  If there is any concern to this data, why would it not be encrypted before you even put it online?  So what exactly does MFA get you other than headache getting to your own freaking data?

 

I am using crashplan that has had MFA for quite some time.. I just don't have it turned on because while I have my home videos backed up - if anyone wants to watch them I don't really care if someone see's my grand daughters kindergarten graduation.., etc..  If you can guess the 12 character random have at watching her drool on herself when she was couple months old, etc.

  • Like 3
7 minutes ago, BudMan said:

I am still curious to what exactly are you storing online that you feel requires MFA... I mean come on... Someone after your recipes and cat videos?  If there is any concern to this data, why would it not be encrypted before you even put it online?  So what exactly does MFA get you other than headache getting to your own freaking data?

 

I bet he's sitting of TBs worth of deadly jokes. We wouldn't want that in anyone's hands.

  • Like 1
2 hours ago, BudMan said:

We had this thread before when you were looking for solution with MFA?  Seems you found one - which one is it?

 

I am still curious to what exactly are you storing online that you feel requires MFA... I mean come on... Someone after your recipes and cat videos?  If there is any concern to this data, why would it not be encrypted before you even put it online?  So what exactly does MFA get you other than headache getting to your own freaking data?

 

I am using crashplan that has had MFA for quite some time.. I just don't have it turned on because while I have my home videos backed up - if anyone wants to watch them I don't really care if someone see's my grand daughters kindergarten graduation.., etc..  If you can guess the 12 character random have at watching her drool on herself when she was couple months old, etc.

I'm using 1TB of storage on one drive.

 

As far as why multi-factor authentication, if you look at what happened to carbonite which caused them to send out a mass password reset is because people got a hold of other peoples user names and passwords and that's all it took to log in to their personal data. Yes those people were using the same passwords everywhere, but still, to me it's the principle of the thing.

 

I personally think there should be a second factor. It's kind of cool the way google is doing it, and so is Microsoft.  When installing the Microsoft authenticator. When logging into my Microsoft account, after you submit your username and password it pops up on the phone saying "trying to log in" ... Yes or No ... you punch yes and BAM! you are in, same with google. So in this case it's not a headache at all.

 

As to what happens when you loose your phone, well I have all my accounts also authenticating to a backup phone in my house in case something happens to my main phone and I just purchased a cheap $39 Moto E for my safety deposit box that I have everything authenticating to that as well, in case something happens to my main phone and my backup phone... like the house burning down or something.

 

Just now, Shiranui said:

So, which company are you using now Mr. Wagon?

Microsoft onedrive 1 terabyte with an office 365 business subscription. I get the 1 terabyte of storage 5 installs of Microsoft Office. And two-factor authentication to boot

27 minutes ago, warwagon said:

Microsoft onedrive 1 terabyte with an office 365 business subscription. I get the 1 terabyte of storage 5 installs of Microsoft Office. And two-factor authentication to boot

Oh, I have that. Must start using Onedrive....

"pops up on the phone saying "trying to log in" ... Yes or No"

 

thats great until it doesn't work because you don't have coverage on you cell. Or that system is down, etc. etc.. Now you can't get to your recipes...

 

There is security, and then there is unneeded headache to secure nonsense..  that be nice when adding a new device.. But really you need mfa every time you turn on your computer and access your storage?

 

btw: 1 drive from an office subscription is not anything like what carbonite is for.. 1 is just online storage and sync, the other is backup of your stuff in cloud.

2 hours ago, BudMan said:

There is security, and then there is unneeded headache to secure nonsense..  that be nice when adding a new device.. But really you need mfa every time you turn on your computer and access your storage?

Its not every time, in a lot of cases of two factor it's when a new device connects it doesn't recognize.

 

Millions of normal people are using backup services like carbonite that takes it upon itself to backup their entire profile folder for them. Most of those people don't know how to encrypt. They just save it to the documents folder.

 

They save their Tax return to their documents directory and carbonite instantly uploads it.

 

They are also the same people who use the same username and password everywhere and not some strong random 12 character password.

 

So now there username and password get compromised in a different site hack and now people can log into carbonite as them and download all their data.

And you think these same people that use the same password everywhere are going to use MFA??

 

Yes when I add a new device to access my bank accounts it is MFA to auth that device.  When I access my lastpass from unknown location, again mfa..  Shoot I have any country other than US blocked anyway to my lastpass even if they have the MFA info..

 

I would assume your using strong random passwords that are different, I would assume anything of any sort of sensitive information you have encrypted before you place in the cloud.  So again what does MFA get YOU???  We are not discussing the usefulness of it in specific scenarios..  We are talking about its usefulness for YOU that are backing up your cat videos..   In what world does this warrant MFA??  Your 12+ random password is not enough?  Knowing you its prob 32+ random..

 

So while the whole subscription and 1TB seems like a reasonable price for their office suite..  Your talking apples and oranges for "backup" software..  Your 1 drive setup does not backup anything for this user that is using the same password everywhere and storing their tax return and other sensitive info just in their my docs that now gets sync'd to the cloud with them prob not even understanding it is..

 

You had to go out of your way to setup some form of backup plan which I am guessing is other files not in the auto sync folders of 1 drive?  Is normal user going to do that?  Does this plan of your have file versions ore revisions of your backups?  Has 1 drive enabled this for anything other than office docs?  I do not believe that had that?  So what happens when you get hit with ransomware and all your files get encrypted and then copy you have in the cloud is overwritten with the encrypted version.

 

How does this setup help the stupid user using the same password everywhere, no backup, no file versioning of their tax return copy that is a pdf or some tax software format - maybe they did their taxes in excel? ;)  But hey they have MFA that they don't even understand what that means ;)

18 minutes ago, BudMan said:

 So again what does MFA get YOU???  

My personal feeling is that I should have to go through an additional step to authenticate myself when accessing my personal online backup vs logging into Neowin. That's just how I feel.

And your tinfoil hat is too freaking tight is how I feel ;)  MFA serves no real purpose "backup" or even sync of normal home users files.. It just doesn't.. If you like pain in accessing your stuff have at it.. What I would suggest is you create a 64 character password random and then store this in 4 different places around your house in 6 point font with only 16 characters of the password.  So then every time you need to log in you can go find the pieces put them together view them with your magnifying glass and type them in by hand.

 

And then make sure you change this password every other day..  Also make sure that your timeout is like 1 minute so if you turn your head for a second or go to the bathroom you will have to start the process of login all over again ;)

 

You seem to like pain in accessing your own ######, because your worried someone is going to give 2 ###### about your cat videos?  So you don't have the business plan of 1 drive?  Is that stuff even encrypted at rest on their servers?  Pretty sure that is only for business users.  More than likely you have everyone working for MS with free rain access to all your cat videos and recipes for pesto..

8 minutes ago, HawkMan said:

Why would you make so much trouble for yourself reading your mail ? just use a secure password. 

What are you talking about? It's no trouble at all to read my emails

 

on my phone I added my google account and only had to authenticate with two-factor only once .. Done.. 

I have it on my thunderbird via app specific password  ... Done

I have it on my couch computer via thunderbird via app specific password Done

 

I can read my emails just fine. if I did want to log into the site itself, I type in the username and password, my phone says are you trying to log in, I say yes, ...Done.

 

Why is everyone making two factor out as this horrible, excruciating, Pain full, troublesome process?

 

Also, The google account isn't just for reading email, it's also your google account for an Android phone, which stores much more than just email.

OK Wagon - I have to chime in here too.
I appreciate the fact you are a nerd, like me and most others on here.

But, if you are protecting the nation's launch codes - I'd like to borrow them.
Are you storing client's data on your OneDrive ?  (I'd like to borrow that too)
Or are you just geeking out and your tinfoil is cutting off circulation ?  hehe


That deal for Office365 and 1TB OneDrive is awesome.

Got the $49 deal for 5 installs, 5TB OneDrive - and used that as gifts for family members (they think I spent a ton of money on them :)

 

46 minutes ago, T3X4S said:

OK Wagon - I have to chime in here too.
I appreciate the fact you are a nerd, like me and most others on here.

But, if you are protecting the nation's launch codes - I'd like to borrow them.
Are you storing client's data on your OneDrive ?  (I'd like to borrow that too)
Or are you just geeking out and your tinfoil is cutting off circulation ?  hehe


That deal for Office365 and 1TB OneDrive is awesome.

Got the $49 deal for 5 installs, 5TB OneDrive - and used that as gifts for family members (they think I spent a ton of money on them :)

 

sorry to say, no launch codes. But after thinking about hawkman's comment again, an email address is usually the one place password reset links are sent so that is the one service I would want locked down.

  • Like 2
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Prime Day Deals: Save up to 50% on Samsung, Sandisk, and Lexar microSD cards by Fiza Ali Amazon Prime Day has brought discounts on a wide range of microSD cards from brands including Samsung, Sandisk and Lexar, with savings of up to 50% across both the UK and US. Below, we've rounded up the best Prime Day microSD deals currently available, including discounted Samsung's T7, T9, and P9 Express series, SanDisk Ultra, Extreme, and Extreme PRO models, as well as Lexar PLAY PRO and PLAY BLUE cards. 512GB Lexar PLAY PRO MicroSDXC Express Card: £94.98 (Amazon UK) - 41% off 64GB SANDISK Extreme microSDXC Card + SD adapter: £17.99 (Amazon UK) - 25% off 128GB SANDISK Extreme microSDXC Card + SD Adapter: £26.99 (Amazon UK) - 14% off 256GB SANDISK Extreme PRO microSD Card + SD adapter: £50.99 (Amazon UK) - 22% off 128GB Samsung T7 microSDXC Card: $32.99 (Amazon US) - 35% off 256GB Samsung T7 microSDXC Card: $51.99 (Amazon US) - 35% off 512GB Samsung T7 microSDXC Card: $94.99 (Amazon US) - 41% off 1TB Samsung T7 microSDXC Card: $239.99 (Amazon US) - 25% off 128GB Samsung T9 microSDXC Card: $36.99 (Amazon US) - 41% off 256GB Samsung T9 microSDXC Card: $57.99 (Amazon US) - 42% off 512GB Samsung T9 microSDXC Card: $104.99 (Amazon US) - 48% off 256GB Samsung P9 Express microSD Card: $39.99 (Amazon US) - 50% off 256GB SANDISK Ultra microSDXC UHS-I Card with Adapter: $41.78 (Amazon US) - 21% off 512GB Lexar PLAY BLUE microSDXC UHS-I Card: $79.99 (Amazon US) - 38% off 1TB Lexar PLAY BLUE microSDXC UHS-I Card: $159.99 (Amazon US) - 30% off 2TB Lexar PLAY BLUE microSDXC UHS-I Card: $279.99 (Amazon US) - 35% off Good to know This Amazon deal is U.S. and U.K. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • But they will be the first asking for a bail out the moment crap goes sideways. Its just a matter of time with this AI thing unless skynet gets us first.
    • I'm so conflicted with the Google Search AI summaries. On one hand I don't like how it's harming smaller websites by greatly reducing traffic which will harm us all in the long run but on the other hand those AI summaries often give me the information I'm after. I have never once clicked on 'show me more' though and never will.
    • Not a single company as small or large it may be is obligated to subsidize its products and sell them at a loss. Your way of thinking is socialist and as a West German with a German brother state but impoverished by state dictatorship and a socialist command economy situated to the East i can tell you - this kind of thinking very quickly leads to products not being produced anymore at all. EDIT: That does not mean that I find state support for social needs unreasonable. Quite the contrary. Together with solid workers' rights we exactly had exactly that in Germany for decades in the form of the Sozialstaat which was as the scandinavian social democratic very successful - until the number of people who drew from those resources dramatically increased (ironically a project of social democrat and green proponents).
    • Apple reportedly has a second-generation iPhone Fold planned for 2027 by Hamid Ganji The iPhone Fold is one of the most anticipated tech products expected to debut this fall. It will be Apple’s first foldable iPhone, ushering in a new product category for the company. While the first generation has yet to hit the shelves, a new leak suggests Apple has already begun work on its successor. Chinese leaker Digital Chat Station claims that the second-generation iPhone Fold has already been confirmed, meaning Apple could launch a successor in fall 2027. The foldable iPhone is also reportedly referred to as the “iPhone Ultra,” though it remains unclear whether Apple will ultimately choose that branding, especially as Samsung is rumored to rename the Galaxy Z Fold 8 as the Galaxy Z Fold Ultra this year. The leaker also claims that the second-generation foldable will feature a wider folding display while reusing the same screen found in the first generation. Apple’s first foldable iPhone is expected to feature a 7.8-inch inner display and a 5.3-inch outer screen in a passport-style form factor. It has already been reported that Apple plans to change its iPhone release cycle in 2026 to spread launches throughout the year. Under this strategy, the iPhone Fold is expected to debut this fall alongside the iPhone 18 Pro and iPhone 18 Pro Max. The standard iPhone 18 and iPhone Air 2 are expected to arrive later in 2026 or in early 2027. Speaking of the iPhone Air, Digital Chat Station says Apple remains undecided about a third-generation model. The company is reportedly waiting to see how the iPhone Air 2 performs in the market, and if sales disappoint, a successor may never materialize. As we reported this week, the iPhone Air has not been scrapped from Apple’s plans. The second-generation model is reportedly scheduled for spring 2027 and could introduce upgrades such as an additional rear camera for ultrawide photography and improved battery life.
  • Recent Achievements

    • One Year In
      Vistor earned a badge
      One Year In
    • First Post
      kinowa earned a badge
      First Post
    • Rookie
      krychek57 went up a rank
      Rookie
    • Grand Master
      Jaybonaut went up a rank
      Grand Master
    • One Year In
      Philsl earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      405
    2. 2
      +Edouard
      170
    3. 3
      PsYcHoKiLLa
      131
    4. 4
      Xenon
      72
    5. 5
      neufuse
      69
  • Tell a friend

    Love Neowin? Tell a friend!