Remember the post I made a few days ago about the website with terrible security?
So after poking around their system a but more (and accidentally shutting down one of their databases using SQL injection), I decided to make another attempt to contact them and warn them about the issues with their security.
I managed to find the number for their support desk and I called it.
Amazingly, I immediately got a
real person! (I was so shocked I just stood there in disbelief for a few seconds before saying anything.)
So I told them that there was an issue with security and that I wanted to speak with someone from their IT staff. Their tone instantly became one of concern, and they went to find the person I needed to speak with.
Unfortunately the person I needed wasn't available, but they told me where to send an email and assured me that they would get it where it needed to go (Yes I was skeptical of that too).
So I wrote an email giving a detailed description of my concerns and the issues I had encountered.
I waited a couple days to hear back. But finally, I got a reply.

After receiving this I waited a few more days for the issues to be resolved.
Today when I checked, they had disabled all but TLSv1.2 (Unfortunately, the sever they're running doesn't currently support TLSv1.3.), and the SQL injection code, no longer worked.
This is the sort of thing I love to see.
While I wouldn't say that they fixed everything, this is certainly a step in the right direction.
All it took, was for someone to speak up.