{"id":5213,"date":"2011-10-03T19:57:55","date_gmt":"2011-10-04T03:57:55","guid":{"rendered":"http:\/\/www.oeconomist.com\/blogs\/daniel\/?p=5213"},"modified":"2011-10-15T06:17:03","modified_gmt":"2011-10-15T14:17:03","slug":"an-f-for-fred-flare","status":"publish","type":"post","link":"https:\/\/www.oeconomist.com\/blogs\/daniel\/?p=5213","title":{"rendered":"An <q>F<\/q> for <span style=\"font-style: italic ;\">F<\/span>red <span style=\"font-style: italic ;\">F<\/span>lare"},"content":{"rendered":"<p><a href=\"http:\/\/www.bbb.org\/NYC\/business-reviews\/clothing-retail\/fred-flare-inc-in-brooklyn-ny-128441\/\">Fred Flare, Inc, has received the not-so-coveted rating of <q>F<\/q> from the Better Business Bureau.<\/a> <a href=\"http:\/\/www.bbb.org\/NYC\/business-reviews\/clothing-retail\/fred-flare-inc-in-brooklyn-ny-128441\/\"><img loading=\"lazy\" decoding=\"async\" src=\"wp-content\/uploads\/2011\/10\/bbb_f.png\" alt=\"\" width=\"57\" height=\"57\" style=\"border: 0 ; display: block ; margin-top: 1em ; margin-bottom: 1em ; margin-left: auto ; margin-right: auto ;\" \/><\/a><\/p> <p>Readers may recall <a href=\"?p=4996\">my entry of 12 August on how Flare had allowed some of the information that I'd provided to them to be used by spammers<\/a>. (I had cre&auml;ted an e.mail address exactly for business with <a href=\"http:\/\/www.fredflare.com\/\">Fred Flare<\/a> and provided it uniquely to <a href=\"http:\/\/www.fredflare.com\/\">them<\/a>.) Not long after I'd posted <a href=\"?p=4996\">that entry<\/a>, I contacted <a href=\"http:\/\/www.bbb.org\/\">the <abbr title=\"Better Business Bureau\">BBB<\/abbr><\/a>; <a href=\"http:\/\/www.fredflare.com\/\">Flare<\/a> should have been responding to the issue of a hacked customer <abbr title=\"database\">dB<\/abbr> with a sense of <em>urgency<\/em>, but there was no evidence of such a sense.<\/p> <p>On 6 September, <a href=\"?p=4996&cpage=1#comment-14677\">a representative from Flare commented to the &#39;blog<\/a>, and also sent e.mail: <blockquote>Please forgive our late response to customer complaint #8703538 from Daniel Kian M cKiernan.<br \/>We are investigating whether our email service provider iContact might have been hacked.<br \/>We haven't found any evidence confirming this as of yet but are being extra thorough.<br \/>Rest assured, no credit card information has been compromised. We DO NOT save cc details for that very reason.<br \/>I will update you as I learn more. Thank you for your patience.<\/blockquote><\/p> <p>Now, <a href=\"?p=4996&cpage=1#comment-14687\">as I implied in reply to the &#39;blog comment<\/a>, the theory in <a href=\"?p=4996&cpage=1#comment-14677\">that comment<\/a> casting suspicion on <a href=\"http:\/\/www.ups.com\/\"><abbr title=\"United Parcel Service\">UPS<\/abbr><\/a> is a poor one.  There's no particularly good reason for the spammer to spoof the name of their source (indeed, there is good reason for them <em>not<\/em> to do this), other spam from this breach spoofs other senders, and <a href=\"http:\/\/www.ups.com\/\"><abbr title=\"United Parcel Service\">UPS<\/abbr><\/a> (along with <a href=\"http:\/\/www.fedex.com\/\"><abbr title=\"Federal Express\">FedEx<\/abbr><\/a> and <a href=\"\"><abbr title=\"Dalsey Hillblom Lynn\">DHL<\/abbr><\/a>) has for many years routinely been spoofed by spammers.<\/p> <p>The second theory (that in the e.mail) has some plausibility, but was, at that point, just a theory.<\/p> <p>The promise (in <a href=\"?p=4996&cpage=1#comment-14677\">the &#39;blog comment<\/a>) of <q>More soon!<\/q> went simply unfulfilled.  Meanwhile, spam continued to be sent to the address, at least one piece using my full name.<\/p> <p>When <a href=\"http:\/\/www.bbb.org\/\">the <abbr title=\"Better Business Bureau\">BBB<\/abbr><\/a> dead-line for communication from <a href=\"http:\/\/www.fredflare.com\/\">Flare<\/a> was imminent, they sent no more than a copy of <a href=\"?p=4996&cpage=1#comment-14677\">that original &#39;blog comment<\/a> and of that theorizing e.mail.  <a href=\"http:\/\/www.bbb.org\/\">The <abbr title=\"Better Business Bureau\">BBB<\/abbr><\/a>, following <abbr title=\"standard operating procedure\">SOP<\/abbr>, asked me if this resolved my complaint, and I explained why it didn't.<\/p> <p>What that communication <em>did<\/em> was reset the clock.  But this time it just ticked-down to zero with no further communication from <a href=\"http:\/\/www.fredflare.com\/\">Flare<\/a>, and <a href=\"http:\/\/www.bbb.org\/\">the <abbr title=\"Better Business Bureau\">BBB<\/abbr><\/a> regards such silence as unacceptable; hence the <q>F<\/q><\/p> <p>I don't know how <a href=\"http:\/\/newyork.bbb.org\/\">the <abbr title=\"New York City\">NYC<\/abbr> <abbr title=\"Better Business Bureau\">BBB<\/abbr><\/a> handles attempts at a ratings change; <a href=\"http:\/\/sandiego.bbb.org\/\">the San Diego <abbr title=\"Better Business Bureau\">BBB<\/abbr><\/a> has been known to allow merchants to revive cases after many months (and known then to completely discard the rating if the customer does not respond). (If <a href=\"http:\/\/www.fredflare.com\/\">Fred Flare<\/a> does <em>not<\/em> act on this case, it will eventually be considered sufficiently ancient as not to be used in rating.)<\/p> <p>For my part, I guess that my next step is <a href=\"https:\/\/www.ftccomplaintassistant.gov\/\">to file a complaint with the <abbr title=\"Federal Trade Commission\">FTC<\/abbr><\/a>.  I don't know that a lot will come of that, though.<\/p> <p>I'm really saddened by this whole course of events.  There is no question that <a href=\"http:\/\/www.fredflare.com\/\">Fred Flare<\/a> offers some cool and whimsical stuff that is difficult or impossible to get elsewhere; I think that they should be rewarded for that much even setting aside whatever desire I might have for any of that stuff, and <span style=\"font-style: italic ;\">ceteris paribus<\/span> I would want such an enterprise to prosper.<\/p> <p>But it's imperative, in these days where information once loosed flows so freely, to take responsibility for the databases that we keep of information <em>on other people<\/em> (including the <q>addressbooks<\/q> of our e.mail handlers).  Mistakes will happen, but we need to <em>own<\/em> any mistakes that we make, and to <em>off-set<\/em> their effects.<\/p> <p>I had hoped that I'd get a reply <em>within hours<\/em> after I'd first contacted <a href=\"http:\/\/www.fredflare.com\/\">Flare<\/a>.  I should have been <em>quickly<\/em> told (as I was <em>eventually<\/em> told) that no credit-card information had been released.  And <a href=\"http:\/\/www.fredflare.com\/\">Flare<\/a> still needs to do <em>something<\/em> for those victims who, unlike me, provided addresses that are not easily discarded.<\/p> ","protected":false},"excerpt":{"rendered":"Fred Flare, Inc, has received the not-so-coveted rating of F from the Better Business Bureau. Readers may recall my entry of 12 August on how Flare had allowed some of the information that I'd provided to them to be used by spammers. (I had cre&auml;ted an e.mail address exactly for business with Fred Flare and [&hellip;]","protected":false},"author":1,"featured_media":5214,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0,"footnotes":""},"categories":[6,318,69,5,4],"tags":[1037,49],"class_list":["post-5213","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-commentary","category-ethics-philosophy","category-information-technology","category-personal","category-public","tag-fred-flare","tag-spam"],"_links":{"self":[{"href":"https:\/\/www.oeconomist.com\/blogs\/daniel\/index.php?rest_route=\/wp\/v2\/posts\/5213","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.oeconomist.com\/blogs\/daniel\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.oeconomist.com\/blogs\/daniel\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.oeconomist.com\/blogs\/daniel\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.oeconomist.com\/blogs\/daniel\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5213"}],"version-history":[{"count":0,"href":"https:\/\/www.oeconomist.com\/blogs\/daniel\/index.php?rest_route=\/wp\/v2\/posts\/5213\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.oeconomist.com\/blogs\/daniel\/index.php?rest_route=\/wp\/v2\/media\/5214"}],"wp:attachment":[{"href":"https:\/\/www.oeconomist.com\/blogs\/daniel\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5213"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.oeconomist.com\/blogs\/daniel\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5213"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.oeconomist.com\/blogs\/daniel\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5213"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}