Writer Sanctum

Writer's Haven => Quill and Feather Pub [Public] => Topic started by: ragdoll on November 02, 2018, 03:54:02 AM

Title: Bowker Hacked?
Post by: ragdoll on November 02, 2018, 03:54:02 AM
From SFWA twitter feed  (https://twitter.com/sfwa/status/1058041817151799296)

Quote
Indie writers, we are hearing early rumors that the recent Bowker outage was due to a hacking incident. If you use Bowker, please be aware that your credit card and passwords may be compromised, and be cautious if you receive ransom emails -- apparently they are bogus.

Don't use Bowker, so I have no other answers.
Title: Re: Bowker Hacked?
Post by: Tom Wood on November 02, 2018, 04:06:29 AM
Recent?

How about 'ongoing' since it's been down since October 23rd.
Title: Re: Bowker Hacked?
Post by: ragdoll on November 02, 2018, 04:17:19 AM
Recent?

How about 'ongoing' since it's been down since October 23rd.

Well, it is SFWA - they deal in millennia, don't they? :D

Hope your account details are ok!
Title: Re: Bowker Hacked?
Post by: ilamont on November 02, 2018, 04:43:36 AM
This is potentially a huge problem. Bowker has been ripping off publishers and authors for years (https://in30minutes.com/bowkers-isbn-markup-new-authors/), and delivered substandard service with its buggy, outdated website. If true, it's not just ISBN purchasers who are impacted. Distribution channels, wholesalers, and other services which depend on accurate ISBN information will have to deal with the fallout.

Has anyone here received any clarification or confirmation from Bowker/ProQuest, or ransom demands?
Title: Re: Bowker Hacked?
Post by: Tom Wood on November 02, 2018, 09:06:21 PM
They now have an open letter up that acknowledges they were hacked. The payment and number management systems are still offline.
Title: Re: Bowker Hacked?
Post by: ilamont on November 02, 2018, 09:31:48 PM
"We want to assure our customers that protecting their information is one of our top priorities and we are taking this incident very seriously."

Yet "unauthorized code" was running for 6 months on its website?

What a crock.

Title: Re: Bowker Hacked?
Post by: Tom Wood on November 08, 2018, 01:29:03 AM
Two weeks and still counting...
Title: Re: Bowker Hacked?
Post by: A. N. Onymous on November 08, 2018, 05:34:14 AM
Management/assignment of ISBNs is available again, however, purchasing has still been suspended.
Title: Re: Bowker Hacked?
Post by: Pandorra on November 08, 2018, 05:54:54 AM
Oh charming.. I questioned its legitimacy when I saw how badly the site was put together but went with it because apparently, it's the only 'official' place to get ISBN's and now this .. am I wrong for saying lazy programmers/devs are going to be just as slack with security as they are with their other work? Money is the bottom line for them, not our privacy!
Title: Re: Bowker Hacked?
Post by: Dragovian on November 09, 2018, 07:58:22 AM
Watch them be "forced" to raise prices again due to this security breach. Bowker is a wonderful example of why monopolies are bad.
Title: Re: Bowker Hacked?
Post by: Attention on November 21, 2018, 10:04:16 PM
I tend to buy my ISBNs via Ingram Sparks and hope I won't get an email from them about some sort of hacking.

Recently got an email in my business spam informing me my computer/account was under the sender's control and that they'd gone through the naughty sites I'd visited blah blah blah.

These internet streets get rougher by the day.
Title: Re: Bowker Hacked?
Post by: Lysmata Debelius on November 22, 2018, 12:47:08 AM
We get our ISBNs from our national library for free, but I bet the information they store is pretty much the same. Name, email, mail address.
It's that last one that concerns me most, as the mail address I use is also my physical address. Maybe it's worth using a PO box? Not sure you can?

As far as I know the South African National Library hasn't been hacked, but I doubt the security is up to much if it does.
Title: Re: Bowker Hacked?
Post by: ragdoll on November 22, 2018, 06:38:59 AM
Maybe it's worth using a PO box? Not sure you can?

I wouldn't know about S.A. ISBN requirements, but I think you might be thinking of the US CAN-SPAM requirements or its international equivalents.

For the US, at least, a PO Box is acceptable.

From lexis-nexis


Quote
Sender’s Valid Physical Postal Address
The sender’s valid physical postal address must be included in a commercial e-mail message. To comply with this requirement, the message must include either of the following:

  • The sender’s current street address
    A Post Office box that the sender has accurately registered with the U.S. Postal Service
    A private mailbox that the sender has accurately registered with a commercial mail receiving agency established pursuant to U.S. Postal Service regulations

Title: Re: Bowker Hacked?
Post by: Tom Wood on December 01, 2018, 01:10:57 AM
The ISBN shopping cart at MyIdentifiers is back online.
Title: Re: Bowker Hacked?
Post by: LilyBLily on December 01, 2018, 10:40:08 AM
The ISBN shopping cart at MyIdentifiers is back online.

Now if they'd only do a sale. Their prices are ridiculously high. If anybody hears of one, let me know.
Title: Re: Bowker Hacked?
Post by: Tom Wood on December 01, 2018, 10:50:33 AM
The ISBN shopping cart at MyIdentifiers is back online.

Now if they'd only do a sale. Their prices are ridiculously high. If anybody hears of one, let me know.

If you join the IBPA, one of the member benefits is 15% off at Bowker. IBPA membership also gets you free revisions (normally $25 EACH) and a waiver of the market access fee ($25/year) at IngramSpark. IBPA membership is in the $100/year+ range. Because of my particular situation, that math works for me to join. So it may be worth a look.