SDE - payment issues? (excised from Who's Next announcement thread)

QuadraphonicQuad

Help Support QuadraphonicQuad:

This site may earn a commission from merchant affiliate links, including eBay, Amazon, and others.
I used my credit card for the first time on SDE (ordering the Avalon/LLT bundle), hoping that this had stopped being a thing. Can't say I'm less concerned now...
 
Out of interest... What's the benefit of installing the Shop app?
The only advantage is that one automatically gets all purchases, in different stores, fed directly into the Shop app, by the app using the connected e-mail address (if one isn't using the app to buy directly from the stores) - if you have given them permission to do so. I obviously did it the first time I used the app, without thinking carefully what I was saying "yes" to. Any time the app noticed I'd made an order with Amazon (because Amazon sends me an email, confirming my order), it would put the order into the app, even though I never use the Shop app for Amazon purchases. The app subsequently tracks the orders and sends push notices, when orders are shipped and delivered. However, as I discovered, the app is not very good at tracking. And the app shares your email and purchase history with other sites. Thus, the email and credit card you've used with them are vulnerable to malicious use.

A few hours, after I changed my email password, I received a push notice from Shop app, notifying me that they no longer had access to my email password and could no longer provide me with updates! I subsequently deleted the app, as I realised it is basically monitoring my emails all the time - not just when making a purchase!

Even more alarming - when I logged into my profile on the Shop website and went into the "Settings - Data & Privacy - Opt out of data sharing", it said that "Your request to opt out has been submitted. It can take up to 7 days for this change to take effect". I have never before experienced any website, which states that it will take a week to opt out of data sharing!
 
The only advantage is that one automatically gets all purchases, in different stores, fed directly into the Shop app, by the app using the connected e-mail address (if one isn't using the app to buy directly from the stores) - if you have given them permission to do so. I obviously did it the first time I used the app, without thinking carefully what I was saying "yes" to. Any time the app noticed I'd made an order with Amazon (because Amazon sends me an email, confirming my order), it would put the order into the app, even though I never use the Shop app for Amazon purchases. The app subsequently tracks the orders and sends push notices, when orders are shipped and delivered. However, as I discovered, the app is not very good at tracking. And the app shares your email and purchase history with other sites. Thus, the email and credit card you've used with them are vulnerable to malicious use.

A few hours, after I changed my email password, I received a push notice from Shop app, notifying me that they no longer had access to my email password and could no longer provide me with updates! I subsequently deleted the app, as I realised it is basically monitoring my emails all the time - not just when making a purchase!

Even more alarming - when I logged into my profile on the Shop website and went into the "Settings - Data & Privacy - Opt out of data sharing", it said that "Your request to opt out has been submitted. It can take up to 7 days for this change to take effect". I have never before experienced any website, which states that it will take a week to opt out of data sharing!
Wow, that's super creepy. So, Shop basically have access to your email password? I always try to deal direct with the vendor if possible and avoid Paypal and Shop.
Just to update my post from November, I never had any fraudulent on either of those credit card orders with SDE but I paid via credit card directly to them. I've placed several orders since then and no issues so far (knock on wood).
 
As I only became aware of Shopify/Shop after buying stuff from SDE I think I'll deleted the app. I pay for goods using PayPal anyway... And fortunately (by the sounds of it) I haven't given Shopify/Shop my credit card details.
 
Last edited:
I've made 12 purchases from the SDE website, using the Shop website, since 2022 and this is the first time I've been hacked. I read about this happening to other Quadraphonic.com members last year, so Shop app was my prime suspect when it happened to me. I found out that Shop app had a stored-in passkey for my credit card, so this has obviously enabled scammers to use it on Booking.com. I have now deleted my credit card from Shop app and have frozen my credit card for a period.
 
I was using Shop for a while (got drawn in by the universal tracking component) but after 2 credit card hacks that appeared to be directly related to using Shop, I deleted it. It was then that I started to realize how intrusive this service/app is, and generally risky to use. Now when I order from SDE, I use Google Pay. No issues.
 
It's worth noting that SDE.com promotes the Shop app, which is why I trustingly started using it. They even provide a barcode for your phone to make it easy. So SDE charge a higher delivery cost that includes tracking, whether you want it or not (I haven't, until this recent purchase going to a different address) and then promote a dodgy tracking app. :( I hope they are reading this latest discussion and alter that practice!
 
Y'all know it's possible to use the Shop app without granting it permission to scan your emails, right? Orders made with ShopPay, as well as most made at any online stores using Shopify for which you use the same email address as your ShopPay account, will still show up automatically in the app. Other tracking numbers can be added manually, which is great for carriers that don't have their own app or whose app is simply poor. I have been using the app this way for years now, and have never had an issue with credit card information leaking. I really don't think the app—or Shopify in general—is the culprit. Insecure, vulnerable, or compromised websites are likely to blame. That, and perhaps weak user account passwords.
 
Last edited:
You know it's possible to use the Shop app without granting it permission to scan your emails, right? Orders made with ShopPay, as well at most made at any online stores using Shopify for which you use the same email address as your ShopPay account, will still show up automatically in the app. Other tracking numbers can be added manually, which is great for carriers that don't have their own app or whose app is simply poor. I have been using the app this way for years now, and have never had an issue with credit card information leaking. I really don't think the app—or Shopify in general—is the culprit. Insecure, vulnerable, or compromised websites are likely to blame. That, and perhaps weak user account passwords.
I know man. All I can say is, I've been using Shop as a means to acquire SDE titles and I've purchased 100% of them and I never have any issues. So, what's different for me? Well, OK, there was that one time that someone bought a Mercedes on my behalf, but other than that. I'm good.
 
You know it's possible to use the Shop app without granting it permission to scan your emails, right? Orders made with ShopPay, as well at most made at any online stores using Shopify for which you use the same email address as your ShopPay account, will still show up automatically in the app. Other tracking numbers can be added manually, which is great for carriers that don't have their own app or whose app is simply poor. I have been using the app this way for years now, and have never had an issue with credit card information leaking. I really don't think the app—or Shopify in general—is the culprit. Insecure, vulnerable, or compromised websites are likely to blame. That, and perhaps weak user account passwords.

I never gave SHOP permission to scan my emails. Nonetheless, now that I think about it, I don't like the idea of even being asked to give this permission. How do you know that app won't "mistakenly" do it anyway?
I can use my credit card if needed, Paypal, Amazon Pay sometimes. Better to be safe than sorry. This is one that I missed until I came across this thread.
 
Y'all know it's possible to use the Shop app without granting it permission to scan your emails, right? Orders made with ShopPay, as well as most made at any online stores using Shopify for which you use the same email address as your ShopPay account, will still show up automatically in the app. Other tracking numbers can be added manually, which is great for carriers that don't have their own app or whose app is simply poor. I have been using the app this way for years now, and have never had an issue with credit card information leaking. I really don't think the app—or Shopify in general—is the culprit. Insecure, vulnerable, or compromised websites are likely to blame. That, and perhaps weak user account passwords.
I've used the Shop app for three years - the A24 website, as well as I few others I purchase media from, only use the Shop app for shipping internationally. I haven't had a problem until now. I obviously gave permissions for emails and stuff, when I first used it, but I'm usually alert about giving carte blanche permissions like like that (I'm one of those people who always denies permissions for tracking cookies on websites). My password was a 19-digit random Apple OS-generated password. It was the first time I've been hacked. The Shop app has the passkey for the credit card built in (which I obviously OK'd for convenience somewhere), which is what enabled my credit card to be used. If I had used two-step authentication, I would not have had my card compromised. The Shop app website is insecure, vulnerable and compromised. I'm not the only one who has experienced fraud, after using their website, so it is a serious issue.
 
If Shopify ever gets hacked, it'll be on the nightly TV news. There's 10's of millions of users and lots more than just one or two users will get hit if they have found a way in. It's most likely the device that you made the purchase on, or your internet connection (Wi-Fi?), was compromised. I would encourage you to do a full malware/virus scan or best case a reinstallation of your computer/device operating system to remove any possible malware or viruses being used to collect your data.

.....and if you are 110% convinced the Shop app is dodgy, just removing it from your device will likely do zero. It's too late as it will have likely done other things like installing malware separately from the app. A malware scan is essential to prevent further problems.
 
The Shop app website is insecure, vulnerable and compromised. I'm not the only one who has experienced fraud, after using their website, so it is a serious issue.
You are conflating two different things, here. The Shop mobile app is not a website. The ShopPay payment processing web portal is embedded in the websites that use it. Therefore, if one of those websites is compromised at the time of purchase, user interactions there may be intercepted by a third party. If ShopPay/Shopify itself were compromised, that breach would be all over the online news.
 
You are conflating two different things, here. The Shop mobile app is not a website. The ShopPay payment processing web portal is embedded in the websites that use it. Therefore, if one of those websites is compromised at the time of purchase, user interactions there may be intercepted by a third party. If ShopPay/Shopify itself were compromised, that breach would be all over the online news.
The website is also called shop.app

https://shop.app/
 
Back
Top