When I Contacted Carbonite to shut down my account...


Recommended Posts

Just contacted carbonite to have them delete all my data and close my account down, due to the lack of two factor authentication.....

 

I told him why I switched to something else, because of the lack of two-factor authentication. 

 

He said "When you say two-factor authentication what do you mean? Do you mean a security question?"

 

I got a gibsonian response that when you call them all you need to validate/ verify your identity with them is ..

 

The Last 4 of the credit card used with carbonite - which is Located and shown on your carbonite account

Name on Card - Which is Located and shown on carbonate account

Billing address Not located or shown on the account but my first and last name is, so they could just look my first and last name online, because in my case, there is only one of me  and then proceed to get my address.

 

They should really verify with information not located on the account.

 

If someone were to get into my account, they could contact carbonite with all the information and closed my account down.

 

The person over the phone let me know that they don't have access to the full card number. I said, well then on your end maybe show the last 6 and on the site show the last 4.

 

Just have some information which is not located on the persons account. After he closed my account, I told him that if someone got my email address and password THEY could have called on my behalf and shut my account down.

 

He said, well that's why your email address and password is important. I said, yes but you also issued a mandatory password  reset (by email with a clickable link no less), because you showed unauthorized logins to peoples accounts due to people using the same password everywhere.

 

 

3 minutes ago, xendrome said:

How would carbonite be able to verify information not on your account? That seems impossible for them to know information they don't have..

Like i said, on the carbonite account they mask all but the last 4 of the credit card ... at the carbonite office mask all but the last 6. That way anyone who logged into someones account would have to be in possession with the full credit card number to be able to validate the last 6 

Just now, warwagon said:

Like i said, on carbonite the mask all but the last 4 of the credit card ... at carbonite mask all but the last 6. That way anyone who logged into someones account would have to be in possession with the full credit card number to validate the last 6 

Oh you are speaking of the account information shown online to a user. If you mean they should have something in their CRM/Billing system like a pin that you would verify and not shown in the online account page, then I get it.

  • Like 2

Is carbonite the only online backup solution that actually restores files back to their proper place ? (as opposed to letting you download your system32 folder that was backed up prior, but it just creates a dump folder and puts things in there - not putting recovered files back in their original location)

I've had experience with Carbonite in the past, and it was a train wreck. They like to make themselves out as an Enterprise-grade data storage and disaster-proof recovery and backup solution, and they charge as such; but what I found was ineptitude and a complete lack of some fairly routine security and data handling measures that we here at Neowin (and pretty much anyone who's ever worked in IT) would do by default. Their Client Software is garbage. 

 

Yep. :( They're junk.

17 minutes ago, xendrome said:

Oh you are speaking of the account information shown online to a user. If you mean they should have something in their CRM/Billing system like a pin that you would verify and not shown in the online account page, then I get it.

There was also no way for me to remove my information from the site. I deleted the client from my computer. I talked with him and the only way, is to let the account expire, at which point after a certain number of days of weeks the data gets deleted. But because I switch to a more secure service which did offer two-factor I wanted my info GONE OFF THE CARBONITE, but there is no "Delete all my data" option.

 

Someone mentioned that if a bad guy got into your account they could also do that. Which is true, but as demonstrated above they can also just call them up on the phone. But as @xendrome mentioned have a pin setup at the time of the creation of the account, or password or really anything that you would then store somewhere, which would let you authenticate to the site, to Permanently delete your data.

 

and oh gee, if they would have had two-factor those accounts probably wouldn't have been compromised. Because of the lack of two-factor their security collapsed just like I thought it would.

We had this thread before when you were looking for solution with MFA?  Seems you found one - which one is it?

 

I am still curious to what exactly are you storing online that you feel requires MFA... I mean come on... Someone after your recipes and cat videos?  If there is any concern to this data, why would it not be encrypted before you even put it online?  So what exactly does MFA get you other than headache getting to your own freaking data?

 

I am using crashplan that has had MFA for quite some time.. I just don't have it turned on because while I have my home videos backed up - if anyone wants to watch them I don't really care if someone see's my grand daughters kindergarten graduation.., etc..  If you can guess the 12 character random have at watching her drool on herself when she was couple months old, etc.

  • Like 3
7 minutes ago, BudMan said:

I am still curious to what exactly are you storing online that you feel requires MFA... I mean come on... Someone after your recipes and cat videos?  If there is any concern to this data, why would it not be encrypted before you even put it online?  So what exactly does MFA get you other than headache getting to your own freaking data?

 

I bet he's sitting of TBs worth of deadly jokes. We wouldn't want that in anyone's hands.

  • Like 1
2 hours ago, BudMan said:

We had this thread before when you were looking for solution with MFA?  Seems you found one - which one is it?

 

I am still curious to what exactly are you storing online that you feel requires MFA... I mean come on... Someone after your recipes and cat videos?  If there is any concern to this data, why would it not be encrypted before you even put it online?  So what exactly does MFA get you other than headache getting to your own freaking data?

 

I am using crashplan that has had MFA for quite some time.. I just don't have it turned on because while I have my home videos backed up - if anyone wants to watch them I don't really care if someone see's my grand daughters kindergarten graduation.., etc..  If you can guess the 12 character random have at watching her drool on herself when she was couple months old, etc.

I'm using 1TB of storage on one drive.

 

As far as why multi-factor authentication, if you look at what happened to carbonite which caused them to send out a mass password reset is because people got a hold of other peoples user names and passwords and that's all it took to log in to their personal data. Yes those people were using the same passwords everywhere, but still, to me it's the principle of the thing.

 

I personally think there should be a second factor. It's kind of cool the way google is doing it, and so is Microsoft.  When installing the Microsoft authenticator. When logging into my Microsoft account, after you submit your username and password it pops up on the phone saying "trying to log in" ... Yes or No ... you punch yes and BAM! you are in, same with google. So in this case it's not a headache at all.

 

As to what happens when you loose your phone, well I have all my accounts also authenticating to a backup phone in my house in case something happens to my main phone and I just purchased a cheap $39 Moto E for my safety deposit box that I have everything authenticating to that as well, in case something happens to my main phone and my backup phone... like the house burning down or something.

 

Just now, Shiranui said:

So, which company are you using now Mr. Wagon?

Microsoft onedrive 1 terabyte with an office 365 business subscription. I get the 1 terabyte of storage 5 installs of Microsoft Office. And two-factor authentication to boot

27 minutes ago, warwagon said:

Microsoft onedrive 1 terabyte with an office 365 business subscription. I get the 1 terabyte of storage 5 installs of Microsoft Office. And two-factor authentication to boot

Oh, I have that. Must start using Onedrive....

"pops up on the phone saying "trying to log in" ... Yes or No"

 

thats great until it doesn't work because you don't have coverage on you cell. Or that system is down, etc. etc.. Now you can't get to your recipes...

 

There is security, and then there is unneeded headache to secure nonsense..  that be nice when adding a new device.. But really you need mfa every time you turn on your computer and access your storage?

 

btw: 1 drive from an office subscription is not anything like what carbonite is for.. 1 is just online storage and sync, the other is backup of your stuff in cloud.

2 hours ago, BudMan said:

There is security, and then there is unneeded headache to secure nonsense..  that be nice when adding a new device.. But really you need mfa every time you turn on your computer and access your storage?

Its not every time, in a lot of cases of two factor it's when a new device connects it doesn't recognize.

 

Millions of normal people are using backup services like carbonite that takes it upon itself to backup their entire profile folder for them. Most of those people don't know how to encrypt. They just save it to the documents folder.

 

They save their Tax return to their documents directory and carbonite instantly uploads it.

 

They are also the same people who use the same username and password everywhere and not some strong random 12 character password.

 

So now there username and password get compromised in a different site hack and now people can log into carbonite as them and download all their data.

And you think these same people that use the same password everywhere are going to use MFA??

 

Yes when I add a new device to access my bank accounts it is MFA to auth that device.  When I access my lastpass from unknown location, again mfa..  Shoot I have any country other than US blocked anyway to my lastpass even if they have the MFA info..

 

I would assume your using strong random passwords that are different, I would assume anything of any sort of sensitive information you have encrypted before you place in the cloud.  So again what does MFA get YOU???  We are not discussing the usefulness of it in specific scenarios..  We are talking about its usefulness for YOU that are backing up your cat videos..   In what world does this warrant MFA??  Your 12+ random password is not enough?  Knowing you its prob 32+ random..

 

So while the whole subscription and 1TB seems like a reasonable price for their office suite..  Your talking apples and oranges for "backup" software..  Your 1 drive setup does not backup anything for this user that is using the same password everywhere and storing their tax return and other sensitive info just in their my docs that now gets sync'd to the cloud with them prob not even understanding it is..

 

You had to go out of your way to setup some form of backup plan which I am guessing is other files not in the auto sync folders of 1 drive?  Is normal user going to do that?  Does this plan of your have file versions ore revisions of your backups?  Has 1 drive enabled this for anything other than office docs?  I do not believe that had that?  So what happens when you get hit with ransomware and all your files get encrypted and then copy you have in the cloud is overwritten with the encrypted version.

 

How does this setup help the stupid user using the same password everywhere, no backup, no file versioning of their tax return copy that is a pdf or some tax software format - maybe they did their taxes in excel? ;)  But hey they have MFA that they don't even understand what that means ;)

18 minutes ago, BudMan said:

 So again what does MFA get YOU???  

My personal feeling is that I should have to go through an additional step to authenticate myself when accessing my personal online backup vs logging into Neowin. That's just how I feel.

And your tinfoil hat is too freaking tight is how I feel ;)  MFA serves no real purpose "backup" or even sync of normal home users files.. It just doesn't.. If you like pain in accessing your stuff have at it.. What I would suggest is you create a 64 character password random and then store this in 4 different places around your house in 6 point font with only 16 characters of the password.  So then every time you need to log in you can go find the pieces put them together view them with your magnifying glass and type them in by hand.

 

And then make sure you change this password every other day..  Also make sure that your timeout is like 1 minute so if you turn your head for a second or go to the bathroom you will have to start the process of login all over again ;)

 

You seem to like pain in accessing your own ######, because your worried someone is going to give 2 ###### about your cat videos?  So you don't have the business plan of 1 drive?  Is that stuff even encrypted at rest on their servers?  Pretty sure that is only for business users.  More than likely you have everyone working for MS with free rain access to all your cat videos and recipes for pesto..

8 minutes ago, HawkMan said:

Why would you make so much trouble for yourself reading your mail ? just use a secure password. 

What are you talking about? It's no trouble at all to read my emails

 

on my phone I added my google account and only had to authenticate with two-factor only once .. Done.. 

I have it on my thunderbird via app specific password  ... Done

I have it on my couch computer via thunderbird via app specific password Done

 

I can read my emails just fine. if I did want to log into the site itself, I type in the username and password, my phone says are you trying to log in, I say yes, ...Done.

 

Why is everyone making two factor out as this horrible, excruciating, Pain full, troublesome process?

 

Also, The google account isn't just for reading email, it's also your google account for an Android phone, which stores much more than just email.

OK Wagon - I have to chime in here too.
I appreciate the fact you are a nerd, like me and most others on here.

But, if you are protecting the nation's launch codes - I'd like to borrow them.
Are you storing client's data on your OneDrive ?  (I'd like to borrow that too)
Or are you just geeking out and your tinfoil is cutting off circulation ?  hehe


That deal for Office365 and 1TB OneDrive is awesome.

Got the $49 deal for 5 installs, 5TB OneDrive - and used that as gifts for family members (they think I spent a ton of money on them :)

 

46 minutes ago, T3X4S said:

OK Wagon - I have to chime in here too.
I appreciate the fact you are a nerd, like me and most others on here.

But, if you are protecting the nation's launch codes - I'd like to borrow them.
Are you storing client's data on your OneDrive ?  (I'd like to borrow that too)
Or are you just geeking out and your tinfoil is cutting off circulation ?  hehe


That deal for Office365 and 1TB OneDrive is awesome.

Got the $49 deal for 5 installs, 5TB OneDrive - and used that as gifts for family members (they think I spent a ton of money on them :)

 

sorry to say, no launch codes. But after thinking about hawkman's comment again, an email address is usually the one place password reset links are sent so that is the one service I would want locked down.

  • Like 2
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Go for a Echo Dot or Pop instead. These Echo shows just advertise to you.
    • NetSpeedTray 1.3.3 by Razvan Serea NetSpeedTray is a lightweight, open-source Windows network monitor that shows live upload and download speeds directly on the Taskbar. Designed for efficiency, it quietly sits in the system tray, conserving CPU and battery with dynamic updates. It blends seamlessly with Windows 10/11, adapts to light/dark themes, and auto-positions to avoid overlaps. Features include accurate interface detection, customizable display, optional mini-graph, color coding, granular font and unit control, detailed per-interface history graphs, safe data management, and easy CSV export—bringing the network monitoring Windows forgot. NetSpeedTray key features: Lightweight & Efficient Runs quietly in your system tray without consuming resources. Features a "Dynamic Update Rate" that lowers refresh frequency when the network is idle to save CPU and battery life. Native Look & Feel Blends seamlessly with Windows 10/11 UI. Smart detection for light and dark taskbar themes ensures text is always visible. Intelligent & Adaptive Positioning Automatically finds empty space next to your system tray and shifts to make room for new icons, preventing overlaps. Seamless OS Integration Behaves like a native Windows component. Hides instantly with auto-hiding taskbar Hides when a fullscreen app is active Smart Network Monitoring Accurate by Default: Auto mode identifies your main internet connection and ignores noise from VPNs or virtual adapters. Easy Interface Selection: Switch effortlessly between Auto, All, or Selected network interfaces via intuitive radio buttons. Total Visual Customization Free Move Mode: Unlock and place the widget anywhere on your screen. Optional Mini-Graph: Real-time graph of recent network activity with adjustable opacity. Color Coding: Customize colors and speed thresholds to quickly see network status. Granular Display Control Text & Font: Adjust font family, size, weight, and alignment. Units: Automatic (B/s, KB/s, MB/s) or fixed Mbps display. Precision: Set decimal places and always show them for uniform appearance. Detailed & Intelligent History Graph Smart Scale: Logarithmic scale shows low-level traffic and large spikes clearly. Per-Interface Filtering: View speed history for specific adapters (Wi-Fi, Ethernet, VPN). Safe & Efficient Data Management: Adjustable retention, automatic cleanup, optimized database. Easy Data Export: Export raw data to .csv or save high-quality graphs for reports. NetSpeedTray v1.3.3: The Updater Fix A stabilization release that repairs a critical regression in v1.3.2: the app shipped without OpenSSL, which silently broke every HTTPS request — including the built-in update checker (the "Could not check for updates" error many of you hit). This release restores it, hardens the build so it can't happen again, and fixes a startup crash plus four other reported bugs. Changes: Fixed update checking — Resolved a critical issue that prevented the app from checking for updates ("Could not check for updates"). Fixed startup crash with Auto-Cycling — The app no longer crashes on launch after enabling Cycle display mode. Fixed incorrect network speeds on 10GbE adapters — Multi-gigabit network cards now display speeds correctly instead of being stuck at 0. Improved color coding — Default color is shown when idle, and color/threshold changes now apply immediately without restarting. Fullscreen visibility fix — The widget now correctly stays visible over fullscreen apps when Keep Visible is enabled. Improved AMD Ryzen temperature detection — More reliable CPU temperature monitoring for Ryzen processors. Cleaner upgrades — Installer now removes outdated application files during upgrades, preventing DLL/version conflicts while preserving user settings. Improved stability — Fixed potential DLL loading issues by excluding critical OpenSSL and NumPy components from UPX compression. Better settings window — Scrollbars removed and layout improved for a cleaner experience. Localization improvements — Updated translations and completed missing UI text across all supported languages. More reliable releases — Added regression tests covering recent critical fixes, bringing the test suite to 196 passing tests. [full release notes] Download: NetSpeedTray 1.3.3 | 87.9 MB (Open Source) Download: NetSpeedTray Portable | 101.0 MB View: NetSpeedTray Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Why Delta Chat is the best decentralized messenger you have probably never tried by Paul Hill There is no shortage of messaging apps out there; we have WhatsApp, Messenger, and Telegram, just to name a few. While Meta has taken steps to incorporate encryption into Messenger and WhatsApp, they still leave a lot to be desired. If you are in the market for a messaging app that promotes security, privacy, and optional anonymity, you'll want to read what I have to say about Delta Chat. For those not familiar with Delta Chat, rather than relying on centralized servers as you do with Facebook Messenger, it relies on email. Essentially, it is a chat interface that feels like a messaging app, but secretly in the background, it is firing off emails. In the past, you used to have to sign in with your email account. When you sent messages to people, it would just be sending encrypted messages to their inbox, which their Delta Chat client would decrypt. When I first learned about Delta Chat, it required users to sign in with an email account, but I was pleasantly surprised upon trying it in 2026 that this is no longer a requirement, or the preferred method was to use the app. Recently, I’ve tried UAD-ng on my old Nokia 3.4 to disable most of the Google apps because the bootloader is locked, and this is the next best option. While finding replacement apps in F-Droid, I came across Delta Chat again, and it has undergone quite a big change since I last used it, with its new chatmail relays, which no longer require you to sign in to your own email account, providing anonymity, and they offer greater security. Android and Desktop Delta Chat apps. Not only does it run on my de-googled phone, but it also works on desktop computers and iOS, making it truly ubiquitous. For me, Delta Chat is a wonderful alternative messenger because it gives you more control. It supports switching between different profiles, which you can set up super quickly; you don’t register a username, you don’t register a password. The only thing you do have is a random string email address on a chatmail relay (which you don’t have to memorize). To maintain access to your profile, you just need to add a second device to your account via QR code or make a backup of your account, which you can restore later. Fail to do these, your account is gone - as it should be if you don’t want to leave accounts that could get hacked later on. My decision to block Google stuff on my Nokia was done for practical reasons; the device sucked when it launched, and it sucks even more now. The nice thing about F-Droid and the apps within is that they’re usually lightweight, free of bloat, and work well on that device. What was inconvenient for me was that it was hard to send messages from that device, say if I wanted to copy a code over to my main phone or send family members a link from that device. That’s when I decided to look at the available chat apps and saw Delta Chat. Another nice thing about Delta Chat is its notifications. Some messaging apps rely on Google’s ecosystem for notification transport on Android; however, with Delta Chat, it can use Google’s solutions if you have Play Services or MicroG installed. Otherwise, it is able to keep a background connection to the chatmail relay server so that you can get notified when you receive a message. As free software, the code of Delta Chat is open for all who want to take it and build upon it. In the future, if the developers of Delta Chat make a catastrophically bad decision and take the app in an undesirable direction, users can take the code and fork the project. This contrasts with closed-source apps from corporations that can take their products in any direction they like. By relying on free software instead of closed-source programs, you actually control your computing. I’ve spoken at length about how running this type of software is like owning your own home rather than renting it. The same applies here; if you use Delta Chat, you don’t need to worry about it going away in the future. Whether it is Telegram, WhatsApp, or Messenger, you are required to register a username and password to use these services. A major flaw in this design is that anyone can try various passwords and potentially break into your account with your complete chat history intact. Sure, there is encryption in Messenger, where you need a second PIN and two-factor authentication in Telegram, but breaches happen all the time. Unlike before, when you used to sign in to your email account to send and receive messages, the primary way to do it now is to create an account on a chatmail relay. The resulting email address is a random string followed by the name of the relay you pick. This means you can start and begin adding contacts Without a username and password, you either need to ensure you have a backup or at least one device running your Delta Chat profile. The primary way to log in on another device is to go to the settings and add a second device. Then, you’ll just scan a QR code with your new device, and it’ll log in to your account and sync all your chat history and contacts. To end users, Delta Chat just looks like any instant messenger; however, it is really sending your messages as encrypted emails to your contact. This is pretty cool from a censorship perspective, as it makes the service more difficult to block. Previously, the main way to use the app was by logging in with email, but nowadays, it’s recommended that you use chatmail relays. Chatmail relays temporarily hold messages in case your device is offline. They are cheap, simple servers that don’t store data as group states. Other information, like your name and avatar, only exists on your device and the devices of those you share your contact information with. The relays are also decentralized and operated by various groups and individuals. It is even possible to set up your own chatmail relay, but most people will want to use one hosted elsewhere. To keep your messages secure, Delta Chat uses a secure subset of the OpenPGP standard that gives you automatic end-to-end encryption. It also uses Secure-Join to exchange encryption setup information through QR-code scanning or invite links. Autocrypt is also used to automatically establish end-to-end encryption between contacts and all members of group chat, but sometime this year Autocrypt v2 will be rolled out, bringing post-quantum resistant encryption and forward secrecy. The Delta Chat FAQ is an interesting read that explains many more details about the app. Credit: Pexels Delta Chat is unique among messaging apps because it is built on email, a technology that’s decades old and isn’t going anywhere soon. What’s more is that email is not centralized either, so it’s far more difficult for any authoritarian regime to disrupt the Delta Chat app. I haven’t spoken too much about features yet, so I will do that now. Delta Chat allows you to do one-on-one chats, group chats, and create channels. It also supports file sharing and making audio and video calls when chatting one-to-one, but it’s not available for group chats right now. At the time of writing, the calling functionality is disabled and can be enabled in Settings > Advanced > Debug Calls. I have used the video calling feature, and the quality is excellent. It works over WebRTC, another open standard. The app also lets you send voice notes, enables disappearing messages, and has its own app ecosystem. I did try playing chess one time there, but it was a bit spotty; though, we did manage to complete the game with a victory for me. To add people to Delta Chat, you can either give them your Delta Chat link or your QR code to scan. These are the only ways to add users, so you won't have any spam bots bothering you. If the people you want to chat with don't have the app yet, just send them your link, and it will take them to a webpage where they can install the app and then add you. It's really quick for them to install it and get started, which is nice. Credit: Microsoft. The Majorana 2 quantum chip unveiled in 2026. I do not think quantum computers are too far out now, and I do hope that Delta Chat is able to push out Autocrypt v2 sooner, rather than later, so bad actors do not attempt to collect encrypted communications and then decrypt them in the future using quantum computers. By getting people’s messages post-quantum-safe now, users won’t have to worry when quantum computers start cracking legacy encryption. Overall, I would recommend this app to people who are already past WhatsApp and Messenger and have perhaps begun using apps like Telegram or Session. It shares a lot of characteristics with these apps and goes a lot further than Telegram in terms of security. By being based on email, it is also resistant to censorship, and the lack of a username and password makes you anonymous (if you want to be) and safe from brute force password cracking attempts. Let me know in the comments if you’ve tried Delta Chat recently. Do you think it's a good bulwark against governments that are tightening their grip on the internet?
  • Recent Achievements

    • One Year In
      bernmeister earned a badge
      One Year In
    • Week One Done
      Scoobystu earned a badge
      Week One Done
    • Week One Done
      tuben earned a badge
      Week One Done
    • First Post
      OffsetAbs earned a badge
      First Post
    • Reacting Well
      OffsetAbs earned a badge
      Reacting Well
  • Popular Contributors

    1. 1
      +primortal
      471
    2. 2
      +Edouard
      217
    3. 3
      PsYcHoKiLLa
      156
    4. 4
      Steven P.
      73
    5. 5
      FloatingFatMan
      71
  • Tell a friend

    Love Neowin? Tell a friend!