Discussion Forum: Administrative
Redisplay Messages: Compact | Brief | All | Full      Show Messages: All | Without Replies

 Author: Gorshkov View Messages Posted By Gorshkov
 Posted: Mar 30, 2023 17:11
 Subject: Re: Important update reg. Ukraine and Russia
 Viewed: 165 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, CE_Tanja writes:
  Dear BrickLink members,

The LEGO Group released the following statement regarding the war in Ukraine.

Our thoughts are with all the children and families suffering as a result of
the war in Ukraine.
Our priority is the safety of all our colleagues. We are in contact with our
Ukrainian team and are providing ongoing support to ensure their safety. We are
also working to support other colleagues around the world impacted by the escalating
crisis including our team in Russia.

We have paused shipments of products to Russia given the extensive disruption
to the operating environment.

We care deeply about the lasting impact on children and together with the LEGO
Foundation and Ole Kirk’s Fond, we will donate DKK 110 million (approx. USD 16.5
million) to emergency relief efforts, with a focus on providing support for children
and families. The donation will be made to existing partners, including the United
Nations Children’s Fund (UNICEF), Save the Children, and the Danish Red Cross.

This is a volatile and constantly evolving situation which we are monitoring
closely.
What does this mean for BrickLink?

The global payment platforms we use on BrickLink are currently not available
in Russia and deliveries to and from the country are severely disrupted. Given
this, buying and selling activities in Russia will be temporarily deactivated.
Members impacted by this will be informed individually.

We are grateful for everyone in our community and never imagined we would face
a situation such as this or witness the heartbreak and devastation we’re seeing
in Ukraine.

Please continue to adhere to our community guidelines and show each other respect
and support.

Thank you for your understanding.
The BrickLink team
 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Mar 8, 2023 15:02
 Subject: Re: We are live with BDP Voting
 Viewed: 74 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, CE_Tanja writes:
  In Administrative, SylvainLS writes:
  In Administrative, Classicsmiley writes:
  […]
Thank you!
When I started voting on the models yesterday, there were voting buttons right
on each item on the list page, and I could see which ones I'd voted for.
Today, those buttons seem to be gone.
Could we please at least get an icon on each model in the list to show how we
voted? Also, being able to sort the list by "most-liked" or "least-liked"
would be useful in helping to navigate the list.

Thanks again.

-Joel

“Filtering out models that are already voted on is a good idea. Likely to be
added for Series 2. We had to remove the gallery view voting feature due to traffic
issues but will be added again shortly.” — Alex (BDP) https://forum.bricklink.com/viewtopic.php?f=13&t=8759#p27560



Thank you Sylvain. I definitely agree to the suggestion about the filtering,
keep the suggestions coming.

suggestion. host a pizza party to boost morale in the fight against the mustard
gang
 Author: CE_Tanja View Messages Posted By CE_Tanja
 Posted: Mar 8, 2023 15:01
 Subject: Re: We are live with BDP Voting
 Viewed: 62 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, SylvainLS writes:
  In Administrative, Classicsmiley writes:
  […]
Thank you!
When I started voting on the models yesterday, there were voting buttons right
on each item on the list page, and I could see which ones I'd voted for.
Today, those buttons seem to be gone.
Could we please at least get an icon on each model in the list to show how we
voted? Also, being able to sort the list by "most-liked" or "least-liked"
would be useful in helping to navigate the list.

Thanks again.

-Joel

“Filtering out models that are already voted on is a good idea. Likely to be
added for Series 2. We had to remove the gallery view voting feature due to traffic
issues but will be added again shortly.” — Alex (BDP) https://forum.bricklink.com/viewtopic.php?f=13&t=8759#p27560



Thank you Sylvain. I definitely agree to the suggestion about the filtering,
keep the suggestions coming.
 Author: SylvainLS View Messages Posted By SylvainLS
 Posted: Mar 8, 2023 14:51
 Subject: Re: We are live with BDP Voting
 Viewed: 42 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, Classicsmiley writes:
  […]
Thank you!
When I started voting on the models yesterday, there were voting buttons right
on each item on the list page, and I could see which ones I'd voted for.
Today, those buttons seem to be gone.
Could we please at least get an icon on each model in the list to show how we
voted? Also, being able to sort the list by "most-liked" or "least-liked"
would be useful in helping to navigate the list.

Thanks again.

-Joel

“Filtering out models that are already voted on is a good idea. Likely to be
added for Series 2. We had to remove the gallery view voting feature due to traffic
issues but will be added again shortly.” — Alex (BDP) https://forum.bricklink.com/viewtopic.php?f=13&t=8759#p27560

 Author: Classicsmiley View Messages Posted By Classicsmiley
 Posted: Mar 8, 2023 14:41
 Subject: Re: We are live with BDP Voting
 Viewed: 46 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, CE_Tanja writes:
  Dear all,

We started BDP Series 1 Voting yesterday.

We are completely blown away by the amazing designs that were submitted during
the intake last month.

375 designs made it through to voting!

Don't miss your chance to support the designs that you like the best.
https://www.bricklink.com/v3/designer-program/main.page

Thank you!
When I started voting on the models yesterday, there were voting buttons right
on each item on the list page, and I could see which ones I'd voted for.
Today, those buttons seem to be gone.
Could we please at least get an icon on each model in the list to show how we
voted? Also, being able to sort the list by "most-liked" or "least-liked"
would be useful in helping to navigate the list.

Thanks again.

-Joel
 Author: CE_Tanja View Messages Posted By CE_Tanja
 Posted: Mar 8, 2023 14:30
 Subject: We are live with BDP Voting
 Viewed: 379 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
Dear all,

We started BDP Series 1 Voting yesterday.

We are completely blown away by the amazing designs that were submitted during
the intake last month.

375 designs made it through to voting!

Don't miss your chance to support the designs that you like the best.
https://www.bricklink.com/v3/designer-program/main.page
 Author: manganschlamm View Messages Posted By manganschlamm
 Posted: Mar 4, 2023 08:24
 Subject: Re: Important update reg. Ukraine and Russia
 Viewed: 117 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, Nikonov writes:
  It's difficult to believe that you have decided to deactivate russian brickLink
stores after so many years of cobusiness. (((


Only if the average Russians start to be affected by the actions of their president
something may change in the course of current actions.
 Author: maximus9991982 View Messages Posted By maximus9991982
 Posted: Mar 4, 2023 07:59
 Subject: Re: Important update reg. Ukraine and Russia
 Viewed: 163 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
Hi, dear BrickLink team! I am from Belarus. I can't make the order. Is it
because the Ukraine war? Belarus people don't support this war and we want
to buy our lovely Lego minifigures. How and when can we buy here?
 Author: morsormail View Messages Posted By morsormail
 Posted: Feb 21, 2023 17:09
 Subject: Re: New Seller Verification changes for the EU
 Viewed: 115 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, cs_anastasia writes:
  Dear BrickLink members,

Due to legal compliance with DAC-7 rules, we are required to collect additional
information from new business sellers in the European Union starting from the
middle of next week. Refer to Article 8ac of the document to find out if you
have the documentation to qualify as a business seller.

https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021L0514


Please assist with understanding your term 'business seller'.

In the linked document it uses 'individual' and 'Entity' for
the definition of 'Active Seller'. So is the 'business seller'
used here to be understood as only being 'Entity'? Or does it also include
'individual'?

And if it does include the type 'individual', and the member state does
not require a business registration, what will the be required to provide to
bricklink? Is it name, address, place of birth and date of birth?

/ Morten
 Author: Nordleng07 View Messages Posted By Nordleng07
 Posted: Feb 20, 2023 07:47
 Subject: Re: Important update reg. Ukraine and Russia
 Viewed: 175 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
why are you deleting messages? You don't like them? But where is your freedom
of speech? which you are protecting! which you are fighting for!
 Author: randyf View Messages Posted By randyf
 Posted: Feb 18, 2023 14:28
 Subject: Re: Reserve your LEGO® account nickname today!
 Viewed: 116 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
It is definitely happening, but most likely at a later time than they initially
thought.

Cheers,
Randy


In Administrative, BricksOfFaith writes:
  What ever happened to this?? Did they decide not to do it??? I’ve been waiting
stressfully hoping they don’t mess EVERYTHING up….






In Administrative, Admin writes:
  Dear BrickLink member,

We’ll be making some changes to the LEGO® Account system in 2023 that’ll make
things a bit easier for you and other BrickLink® members. We’re introducing a
universal LEGO nickname that will work in all online LEGO experiences, including
BrickLink. This means that your username on BrickLink will be the same as your
LEGO Account nickname. That way, you’ll only have to keep track of one nickname,
and it’ll be easier for others to follow you and enjoy your LEGO content.

Right now, we’re giving our BrickLink and LEGO Ideas members a chance to create
and reserve their preferred nickname before we open the service to other LEGO
account holders. If you already have a LEGO Account, we’ll ask you to do a quick
setup on that account by following the link below. All you must do is submit
your BrickLink username as your new LEGO Account nickname. That’s how we’ll make
sure you get the nickname you prefer, on BrickLink, LEGO Ideas and everywhere
else!

If you do not have an account already, follow the link below to create an account
and to select your own nickname.

We understand how important it is to you that other BrickLink members recognize
you on our site, so we encourage you to complete the nickname setup as soon as
you can.

There’s one more thing, though. For trademark and copyright reasons, nicknames
can’t contain words like “LEGO” or “BrickLink” We appreciate all our BrickLink
members, and we understand that changing your nickname isn’t necessarily something
you’d like to do. It’s all part of our work to provide our BrickLink members
with the best possible way to connect with the LEGO brand and each other, and
we hope you’ll feel the benefits of this going forward.

If you find your nickname is rejected for this reason, we encourage you to use
other words related to the LEGO brand like “brick” or “build.” See what fun and
personal combinations you can make!

Anyway, here’s what you need to do:

• Follow this link to log in to your LEGO Account or to create a new LEGO account

https://identity.lego.com/en-US/profile?returnUrl=https%3A%2F%2Fwww.bricklink.com%2F&clientid=0fd7ca3b-3a33-48e3-a747-8ec6f09557c1&appContext=false&adultexperience=true&hideheader=true&hideclosebutton=false&hideexternallogin=false&childsignupexperience=

• Click the Edit icon next to your avatar
• Choose your preferred nickname in the field
• Click Submit and wait a few seconds for your nickname to be approved
• That’s it! You’re all set!

Please select your preferred nickname by the 16th of January 2023. If you’re
not able to change it by this time, we’ll give you an auto-generated nickname.


PLEASE CHECK THESE GUIDELINES BEFORE SUBMITTING A NEW NICKNAME

A nickname...

• can be created in the languages available within a LEGO experience, e.g., LEGO.com
or LEGO Life.
• must be between 4-25 characters in length
• can contain both upper- and lower-case letters
• can be a mix of characters and numbers
• can include a maximum of 4 numbers
• can only include the following special signs: ‘.’ and/or ‘-‘and/or ‘_’
• can include spaces, but not two or more consecutive spaces
• can’t contain the LEGO wordmark including any variations that make it look
as if the name indicates an individual representing the LEGO Group
• can’t contain a LEGO franchise that is a trademark owned by the LEGO Group
• can’t contain a name from another intellectual property not owned by the LEGO
Group (example: Star Wars)
• can’t contain an email address or other contact info
• can’t contain references to other social platforms
• must adhere to the standard LEGO moderation guidelines including but not limited
to political or religious topics, drugs and alcohol, weapon references, hate
speech, profanities, violence, or abusive language


FREQUENTLY ASKED QUESTIONS

Please visit our Help Center for a list of Freqeuntly Asked Questions

https://www.bricklink.com/help.asp?helpID=2576

If you would like to recieve information about this type of topic in the future,
you can sign up for Personalized Marketting here

https://www.bricklink.com/pref_contact.asp
 Author: BricksOfFaith View Messages Posted By BricksOfFaith
 Posted: Feb 18, 2023 06:53
 Subject: Re: Reserve your LEGO® account nickname today!
 Viewed: 97 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
What ever happened to this?? Did they decide not to do it??? I’ve been waiting
stressfully hoping they don’t mess EVERYTHING up….






In Administrative, Admin writes:
  Dear BrickLink member,

We’ll be making some changes to the LEGO® Account system in 2023 that’ll make
things a bit easier for you and other BrickLink® members. We’re introducing a
universal LEGO nickname that will work in all online LEGO experiences, including
BrickLink. This means that your username on BrickLink will be the same as your
LEGO Account nickname. That way, you’ll only have to keep track of one nickname,
and it’ll be easier for others to follow you and enjoy your LEGO content.

Right now, we’re giving our BrickLink and LEGO Ideas members a chance to create
and reserve their preferred nickname before we open the service to other LEGO
account holders. If you already have a LEGO Account, we’ll ask you to do a quick
setup on that account by following the link below. All you must do is submit
your BrickLink username as your new LEGO Account nickname. That’s how we’ll make
sure you get the nickname you prefer, on BrickLink, LEGO Ideas and everywhere
else!

If you do not have an account already, follow the link below to create an account
and to select your own nickname.

We understand how important it is to you that other BrickLink members recognize
you on our site, so we encourage you to complete the nickname setup as soon as
you can.

There’s one more thing, though. For trademark and copyright reasons, nicknames
can’t contain words like “LEGO” or “BrickLink” We appreciate all our BrickLink
members, and we understand that changing your nickname isn’t necessarily something
you’d like to do. It’s all part of our work to provide our BrickLink members
with the best possible way to connect with the LEGO brand and each other, and
we hope you’ll feel the benefits of this going forward.

If you find your nickname is rejected for this reason, we encourage you to use
other words related to the LEGO brand like “brick” or “build.” See what fun and
personal combinations you can make!

Anyway, here’s what you need to do:

• Follow this link to log in to your LEGO Account or to create a new LEGO account

https://identity.lego.com/en-US/profile?returnUrl=https%3A%2F%2Fwww.bricklink.com%2F&clientid=0fd7ca3b-3a33-48e3-a747-8ec6f09557c1&appContext=false&adultexperience=true&hideheader=true&hideclosebutton=false&hideexternallogin=false&childsignupexperience=

• Click the Edit icon next to your avatar
• Choose your preferred nickname in the field
• Click Submit and wait a few seconds for your nickname to be approved
• That’s it! You’re all set!

Please select your preferred nickname by the 16th of January 2023. If you’re
not able to change it by this time, we’ll give you an auto-generated nickname.


PLEASE CHECK THESE GUIDELINES BEFORE SUBMITTING A NEW NICKNAME

A nickname...

• can be created in the languages available within a LEGO experience, e.g., LEGO.com
or LEGO Life.
• must be between 4-25 characters in length
• can contain both upper- and lower-case letters
• can be a mix of characters and numbers
• can include a maximum of 4 numbers
• can only include the following special signs: ‘.’ and/or ‘-‘and/or ‘_’
• can include spaces, but not two or more consecutive spaces
• can’t contain the LEGO wordmark including any variations that make it look
as if the name indicates an individual representing the LEGO Group
• can’t contain a LEGO franchise that is a trademark owned by the LEGO Group
• can’t contain a name from another intellectual property not owned by the LEGO
Group (example: Star Wars)
• can’t contain an email address or other contact info
• can’t contain references to other social platforms
• must adhere to the standard LEGO moderation guidelines including but not limited
to political or religious topics, drugs and alcohol, weapon references, hate
speech, profanities, violence, or abusive language


FREQUENTLY ASKED QUESTIONS

Please visit our Help Center for a list of Freqeuntly Asked Questions

https://www.bricklink.com/help.asp?helpID=2576

If you would like to recieve information about this type of topic in the future,
you can sign up for Personalized Marketting here

https://www.bricklink.com/pref_contact.asp
 Author: ihave36paws View Messages Posted By ihave36paws
 Posted: Feb 5, 2023 08:45
 Subject: Re: Seller Terms of Service Update Feb 2, 2023
 Viewed: 111 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
I can not figure out how to update my seller terms and I am unable to pay my
Fee's for the month. It says they must be paid by the 15th before I am terminated
but it won't let me pay.






In Administrative, Admin_Russell writes:
  Hello everybody,

Yesterday we updated the Seller Terms of Service. Here is a summary of the changes
that were made.

• Opening section - Removed one restrictive phrase

If you do not agree to the revised Seller Terms, then BrickLink is entitled
to terminate these Seller Terms as they apply to you, and disable your
Seller account.

• 1.2.8 - Replaced the term “on hand” with more explicit language

Exact quantity: The quantity of the item that you are listing for sale must
not be greater than the quantity you have physical possession of in the country
in which your BrickLink store is registered. Drop shipping is not permitted.


• 1.2.11 and 1.2.12 - Removed these sections regarding the MOC Shop

MOC Packages. If you offer for sale in your store bricks and build instructions
for a design made available by a Designer (a “MOC Package”), then you must (i)
offer to sell all the bricks that are necessary to build the model represented
by the MOC Package and (ii) deliver or otherwise make available to the Buyers
of the MOC Package the build instructions for the MOC Package.


Designers’ MOCs and Designs. Without written consent of a Designer, or except
as otherwise permitted herein, you may not sell, reproduce or create derivative
works of any Designer's models, images or designs published on the Site,
including at moc.BrickLink.com or within the Studio Gallery portion of the Site.
]

• 1.3 - Removed various other mentions of the MOC Shop

• 1.3.11 - New language was added regarding complimentary use of the site

Complimentary use in Select Countries: LEGO BrickLink, Inc. is required to
register with the tax authorities in the countries from which BrickLink collects
Store Fees. For certain countries with few BrickLink sellers, or where the overall
BrickLink sales volume is low, the cost to LEGO BrickLink, Inc. of registering
for tax purposes can exceed the anticipated revenue from Store Fees. In such
cases, BrickLink may not charge Store Fees for sellers in countries where the
cost of registration with local tax authorities would make it economically advantageous
for BrickLink to not charge Store Fees. The list of countries for which BrickLink
will not charge Store Fees is subject to change from time to time as economic
conditions change, at BrickLink's sole discretion. The current list of exempted
countries may be found here.


**************************************

You can easily see the exact differences by opening two tabs for this page:

https://www.bricklink.com/v3/terms_of_service_seller.page

On the dropdown menu in the upper right corner, select July 1, 2021 and for the
other keep it at the default Feb 2, 2023.

None of the changes to the TOS were considered critical enough to require consent
from our sellers. However, communication was sent to various groups of sellers
who may be affected by these changes.

Thank you,

The BrickLink Team
 Author: wildchicken13 View Messages Posted By wildchicken13
 Posted: Feb 4, 2023 21:28
 Subject: Re: Seller Terms of Service Update Feb 2, 2023
 Viewed: 98 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, BricksOfFaith writes:
  Why exactly did we get rid of the Moc shop? The concept seemed cool…

I don't remember exactly when MOC Shop was retired, but it was sometime around
1-2 years ago.

I was fairly active on MOC Shop, both as a designer and as a seller for other
people's MOCs. However, I found the amount of effort required to produce
kits to be too much for the amount of money involved, and not many buyers were
willing to pay the full price. I ended up selling many kits at a loss.

In retrospect, it was not very well thought out. Why pay someone else to do something
you enjoy?

That being said, some MOCs did sell well, such as the Nintendo Entertainment
System. Funny enough, the LEGO Group released their own version just a few years
later!
 
Set No: 71374  Name: Nintendo Entertainment System
* 
71374-1 (Inv) Nintendo Entertainment System
2645 Parts, 1 Minifigure, 2020
Sets: Super Mario

Not sure if it can fit a Raspberry Pi, though.

My personal favorite was the pegasus, I even kept a copy just for myself. It
was also my best selling MOC. The instructions are for sale on Rebrickable:
https://rebrickable.com/mocs/MOC-74921/Amida_Na/pegasus/#details

Now, I just sell instructions for my own MOCs, since buyers can easily upload
the parts list to BrickLink and order the parts on their own. Buyer does all
the hard work, much easier for me…
 Author: SylvainLS View Messages Posted By SylvainLS
 Posted: Feb 4, 2023 15:09
 Subject: Re: Seller Terms of Service Update Feb 2, 2023
 Viewed: 94 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, BricksOfFaith writes:
  Why exactly did we get rid of the Moc shop? The concept seemed cool…

It didn’t work out.  Nobody used it.  No demand, no offer; no offer, no demand.
 Author: 1001bricks View Messages Posted By 1001bricks
 Posted: Feb 4, 2023 15:08
 Subject: Re: Seller Terms of Service Update Feb 2, 2023
 Viewed: 90 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, BricksOfFaith writes:
  Why exactly did we get rid of the Moc shop?

Much work, zero profit.
 Author: BricksOfFaith View Messages Posted By BricksOfFaith
 Posted: Feb 4, 2023 14:52
 Subject: Re: Seller Terms of Service Update Feb 2, 2023
 Viewed: 111 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
Why exactly did we get rid of the Moc shop? The concept seemed cool…
 Author: yorbrick View Messages Posted By yorbrick
 Posted: Feb 3, 2023 18:00
 Subject: Re: Important update reg. Ukraine and Russia
 Viewed: 124 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
  
PayPal works in Belarus even with local credit cards from banks that are not
under sanctions, so no problem with payment. I think the real reason is that
Lego left our market, so Bricklink left it as a part of Lego group.

I thought paypal had stopped operating in Belarus as Western governments have
applied the same financial sanctions on Belarus as Russia. And yes, LEGO pulled
out of both countries, as have many other Western based international companies.
 Author: Admin_Russell View Messages Posted By Admin_Russell
 Posted: Feb 3, 2023 15:56
 Subject: Seller Terms of Service Update Feb 2, 2023
 Viewed: 492 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
Hello everybody,

Yesterday we updated the Seller Terms of Service. Here is a summary of the changes
that were made.

• Opening section - Removed one restrictive phrase

If you do not agree to the revised Seller Terms, then BrickLink is entitled
to terminate these Seller Terms as they apply to you, and disable your
Seller account.

• 1.2.8 - Replaced the term “on hand” with more explicit language

Exact quantity: The quantity of the item that you are listing for sale must
not be greater than the quantity you have physical possession of in the country
in which your BrickLink store is registered. Drop shipping is not permitted.


• 1.2.11 and 1.2.12 - Removed these sections regarding the MOC Shop

MOC Packages. If you offer for sale in your store bricks and build instructions
for a design made available by a Designer (a “MOC Package”), then you must (i)
offer to sell all the bricks that are necessary to build the model represented
by the MOC Package and (ii) deliver or otherwise make available to the Buyers
of the MOC Package the build instructions for the MOC Package.


Designers’ MOCs and Designs. Without written consent of a Designer, or except
as otherwise permitted herein, you may not sell, reproduce or create derivative
works of any Designer's models, images or designs published on the Site,
including at moc.BrickLink.com or within the Studio Gallery portion of the Site.
]

• 1.3 - Removed various other mentions of the MOC Shop

• 1.3.11 - New language was added regarding complimentary use of the site

Complimentary use in Select Countries: LEGO BrickLink, Inc. is required to
register with the tax authorities in the countries from which BrickLink collects
Store Fees. For certain countries with few BrickLink sellers, or where the overall
BrickLink sales volume is low, the cost to LEGO BrickLink, Inc. of registering
for tax purposes can exceed the anticipated revenue from Store Fees. In such
cases, BrickLink may not charge Store Fees for sellers in countries where the
cost of registration with local tax authorities would make it economically advantageous
for BrickLink to not charge Store Fees. The list of countries for which BrickLink
will not charge Store Fees is subject to change from time to time as economic
conditions change, at BrickLink's sole discretion. The current list of exempted
countries may be found here.


**************************************

You can easily see the exact differences by opening two tabs for this page:

https://www.bricklink.com/v3/terms_of_service_seller.page

On the dropdown menu in the upper right corner, select July 1, 2021 and for the
other keep it at the default Feb 2, 2023.

None of the changes to the TOS were considered critical enough to require consent
from our sellers. However, communication was sent to various groups of sellers
who may be affected by these changes.

Thank you,

The BrickLink Team
 Author: axaday View Messages Posted By axaday
 Posted: Feb 3, 2023 09:48
 Subject: Re: Important update reg. Ukraine and Russia
 Viewed: 155 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, TaGsAlex writes:
  good afternoon, what is happening in Ukraine is certainly terrible, and we all
hope for a speedy solution to the world, but how are Belarusians to blame in
this situation? why should they be deprived of the opportunity to buy a children's
designer?

The Belarusian foreign minister confirmed last week that Belarus is doing joint
exercises with Russian troops building up in Belarus. Russia is freely using
Belarusian air space for missile and drone attacks on Ukraine. I don't think
YOU or any of your friends are to blame, but your government is entirely allied
with Russia in this.
 Author: yorbrick View Messages Posted By yorbrick
 Posted: Feb 3, 2023 09:20
 Subject: Re: Important update reg. Ukraine and Russia
 Viewed: 140 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, TaGsAlex writes:
  good afternoon, what is happening in Ukraine is certainly terrible, and we all
hope for a speedy solution to the world, but how are Belarusians to blame in
this situation? why should they be deprived of the opportunity to buy a children's
designer?

Because the many western countries have imposed financial and trade sanctions
against Belarus because of your government's support for Russia and their
invasion of Ukraine. Importantly, PayPal have stopped operating in Russia and
Belarus because of the financial sanctions, so there are no payment options to
pay fees.
 Author: TaGsAlex View Messages Posted By TaGsAlex
 Posted: Feb 3, 2023 09:04
 Subject: Re: Important update reg. Ukraine and Russia
 Viewed: 206 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
good afternoon, what is happening in Ukraine is certainly terrible, and we all
hope for a speedy solution to the world, but how are Belarusians to blame in
this situation? why should they be deprived of the opportunity to buy a children's
designer?
 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Jan 24, 2023 15:14
 Subject: Re: Important update reg. Ukraine and Russia
 Viewed: 155 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, yorbrick writes:
  In Administrative, Nubs_Select writes:
  In Administrative, SylvainLS writes:
  In Administrative, Nubs_Select writes:
  In Administrative, jay5836 writes:
  а если русский магазин?

pretty sure Russians can still buy from russian stores

The Russian stores don’t have any way to pay their fees to BrickLink.

oh ok i was confused since they still show up in feeds of items for sale such
as this one
https://store.bricklink.com/TemKo?sID=1133887&itemID=322210214#/shop

No feedback since June 2022 suggests they can't sell.

ya its still weird how they still show up in the price guide and you think you
can buy from them but then cant
 Author: yorbrick View Messages Posted By yorbrick
 Posted: Jan 24, 2023 14:52
 Subject: Re: Important update reg. Ukraine and Russia
 Viewed: 137 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, Nubs_Select writes:
  In Administrative, SylvainLS writes:
  In Administrative, Nubs_Select writes:
  In Administrative, jay5836 writes:
  а если русский магазин?

pretty sure Russians can still buy from russian stores

The Russian stores don’t have any way to pay their fees to BrickLink.

oh ok i was confused since they still show up in feeds of items for sale such
as this one
https://store.bricklink.com/TemKo?sID=1133887&itemID=322210214#/shop

No feedback since June 2022 suggests they can't sell.
 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Jan 24, 2023 14:49
 Subject: Re: Important update reg. Ukraine and Russia
 Viewed: 109 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, SylvainLS writes:
  In Administrative, Nubs_Select writes:
  In Administrative, jay5836 writes:
  а если русский магазин?

pretty sure Russians can still buy from russian stores

The Russian stores don’t have any way to pay their fees to BrickLink.

oh ok i was confused since they still show up in feeds of items for sale such
as this one
https://store.bricklink.com/TemKo?sID=1133887&itemID=322210214#/shop
 Author: SylvainLS View Messages Posted By SylvainLS
 Posted: Jan 24, 2023 14:17
 Subject: Re: Important update reg. Ukraine and Russia
 Viewed: 128 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, Nubs_Select writes:
  In Administrative, jay5836 writes:
  а если русский магазин?

pretty sure Russians can still buy from russian stores

The Russian stores don’t have any way to pay their fees to BrickLink.
 Author: jay5836 View Messages Posted By jay5836
 Posted: Jan 24, 2023 13:42
 Subject: Re: Important update reg. Ukraine and Russia
 Viewed: 170 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
а если русский магазин?
 Author: jay5836 View Messages Posted By jay5836
 Posted: Jan 24, 2023 13:39
 Subject: Re: Important update reg. Ukraine and Russia
 Viewed: 155 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, CE_Tanja writes:
  Dear BrickLink members,

The LEGO Group released the following statement regarding the war in Ukraine.

Our thoughts are with all the children and families suffering as a result of
the war in Ukraine.
Our priority is the safety of all our colleagues. We are in contact with our
Ukrainian team and are providing ongoing support to ensure their safety. We are
also working to support other colleagues around the world impacted by the escalating
crisis including our team in Russia.

We have paused shipments of products to Russia given the extensive disruption
to the operating environment.

We care deeply about the lasting impact on children and together with the LEGO
Foundation and Ole Kirk’s Fond, we will donate DKK 110 million (approx. USD 16.5
million) to emergency relief efforts, with a focus on providing support for children
and families. The donation will be made to existing partners, including the United
Nations Children’s Fund (UNICEF), Save the Children, and the Danish Red Cross.

This is a volatile and constantly evolving situation which we are monitoring
closely.
What does this mean for BrickLink?

The global payment platforms we use on BrickLink are currently not available
in Russia and deliveries to and from the country are severely disrupted. Given
this, buying and selling activities in Russia will be temporarily deactivated.
Members impacted by this will be informed individually.

We are grateful for everyone in our community and never imagined we would face
a situation such as this or witness the heartbreak and devastation we’re seeing
in Ukraine.

Please continue to adhere to our community guidelines and show each other respect
and support.

Thank you for your understanding.
The BrickLink team
 Author: rmfloris View Messages Posted By rmfloris
 Posted: Jan 2, 2023 06:57
 Subject: Re: NSV changes for business sellers in EU-DUTCH ONLY!
 Viewed: 148 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
I believe in the announcement, it does both. So I need to verify myself, which
can be done without breaking the GDPR laws. But Bricklink will also need to report
the information to the tax authorities, hence it need to store the information.

There is a threshold for DAC-7, so not all sellers are reported towards the tax
authorities. In that case holding the information goes against GDPR guidelines,
as it store's PII data with no clear use case.

I believe the information should only be requested with the sellers once the
threshold is reached and there is a justification for storing the sensitive data.


In Administrative, SylvainLS writes:
  In Administrative, rmfloris writes:
  I believe DAC-7 requires also private entities to be reported. There is a threshold
before the need to report to the tax authorities. How will Bricklink handle these
cases as requesting the needed information, can be seen as a breach of GDPR regulations,
requesting more private information then it needs to do their daily business.

AFAIU, the GDPR forbids keeping the info, not asking for it, especially when
you need the info to obey other laws.

As an example, a shop owner can ask you to prove your identity (ID card, passport…)
when you pay by cheque but the GDPR forbids them to take a photo(copy).


  The link provided ends up at a 404 page.

It’s missing a ‘4’ at the end.
 Author: SylvainLS View Messages Posted By SylvainLS
 Posted: Dec 27, 2022 12:43
 Subject: Re: NSV changes for business sellers in EU-DUTCH ONLY!
 Viewed: 110 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, rmfloris writes:
  I believe DAC-7 requires also private entities to be reported. There is a threshold
before the need to report to the tax authorities. How will Bricklink handle these
cases as requesting the needed information, can be seen as a breach of GDPR regulations,
requesting more private information then it needs to do their daily business.

AFAIU, the GDPR forbids keeping the info, not asking for it, especially when
you need the info to obey other laws.

As an example, a shop owner can ask you to prove your identity (ID card, passport…)
when you pay by cheque but the GDPR forbids them to take a photo(copy).


  The link provided ends up at a 404 page.

It’s missing a ‘4’ at the end.
 Author: rmfloris View Messages Posted By rmfloris
 Posted: Dec 27, 2022 11:54
 Subject: Re: NSV changes for business sellers in EU-DUTCH ONLY!
 Viewed: 119 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
I believe DAC-7 requires also private entities to be reported. There is a threshold
before the need to report to the tax authorities. How will Bricklink handle these
cases as requesting the needed information, can be seen as a breach of GDPR regulations,
requesting more private information then it needs to do their daily business.

The link provided ends up at a 404 page.

With kind regards

Ralf


In Administrative, StarBrick writes:
  Voor de NL members hier, dit lees ik op Blz 19 (definities) van de NL versie
van het document naar wordt verwezen door BL.

B. Te rapporteren verkopers

1. “Verkoper”: een gebruiker van een platform, hetzij een natuurlijke persoon,
hetzij een entiteit, die op enig ogenblik tijdens de rapportageperiode op het
platform is geregistreerd en een relevante activiteit verricht.

Dat betekent dat ook private personen gemeld moeten worden door BL. Of lees ik
dat verkeerd?

Verderop:

De rapporterende platformexploitant verzamelt alle volgende inlichtingen voor
elke verkoper die een natuurlijke persoon en geen uitgesloten verkoper is: (en
dan volgt een hele waslijst).


En dit is wat BL moet verstrekken over de verkopers:

e) de totale tegenprestatie die is betaald of gecrediteerd tijdens elk kwartaal
van de rapportageperiode, en het aantal relevante activiteiten waarvoor deze
is betaald of gecrediteerd;
f) alle honoraria, commissielonen of belastingen die door de rapporterende platformexploitant
tijdens elk kwartaal van de rapportageperiode ingehouden of geheven werden.


Feedback welkom
 Author: ImperialFleet View Messages Posted By ImperialFleet
 Posted: Dec 24, 2022 12:45
 Subject: Re: Article about a BrickLink data breach
 Viewed: 111 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
Heheh, so true

MBA
 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Dec 24, 2022 12:40
 Subject: Re: Article about a BrickLink data breach
 Viewed: 84 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, macebobo writes:
  In Administrative, CE_Tanja writes:
  Dear all,

Thanks for your comments and curiosity around the details of this incident.

On reflection, our statement could have been clearer. In this instance, a member
of the community got in touch with us regarding their research findings. Based
on this, we took all precautionary measures to address the vulnerability they
raised and rolled out a fix in early November.

We appreciate they got in touch, but also want to assure everyone that at no
time was any data at risk.

We’re very serious about the security of Bricklink and will continue to take
all necessary steps to make sure the site and users’ data is safe

OMG, BL needs a good PR person stat, this statement is so full of BS.

Comic guy (Mark) said it best...

http://v4ei.com/comics/index.php?id=moutarde

those comics are the best!
 Author: macebobo View Messages Posted By macebobo
 Posted: Dec 24, 2022 12:08
 Subject: Re: Article about a BrickLink data breach
 Viewed: 108 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, CE_Tanja writes:
  Dear all,

Thanks for your comments and curiosity around the details of this incident.

On reflection, our statement could have been clearer. In this instance, a member
of the community got in touch with us regarding their research findings. Based
on this, we took all precautionary measures to address the vulnerability they
raised and rolled out a fix in early November.

We appreciate they got in touch, but also want to assure everyone that at no
time was any data at risk.

We’re very serious about the security of Bricklink and will continue to take
all necessary steps to make sure the site and users’ data is safe

OMG, BL needs a good PR person stat, this statement is so full of BS.

Comic guy (Mark) said it best...

http://v4ei.com/comics/index.php?id=moutarde
 Author: StarBrick View Messages Posted By StarBrick
 Posted: Dec 23, 2022 12:00
 Subject: Re: How sharp are your eyes?
 Viewed: 53 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, Admin_Russell writes:
  Hello everyone,

There is a thin yellow banner that pops up to remind you about the upcoming monthly
maintenance. Please notice that the date on the banner is exactly one week later
than usual:

[REMINDER] The site will be down during the monthly maintenance scheduled
at 12/28 from 01:00 AM to 02:00 AM EST.


Thank you.

Are there any new features to be launched in this maintenance window or just
regular activities?
Backing up my store on Dec 27th to be safe
 Author: StarBrick View Messages Posted By StarBrick
 Posted: Dec 23, 2022 11:51
 Subject: NSV changes for business sellers in EU-DUTCH ONLY!
 Viewed: 145 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
Voor de NL members hier, dit lees ik op Blz 19 (definities) van de NL versie
van het document naar wordt verwezen door BL.

B. Te rapporteren verkopers

1. “Verkoper”: een gebruiker van een platform, hetzij een natuurlijke persoon,
hetzij een entiteit, die op enig ogenblik tijdens de rapportageperiode op het
platform is geregistreerd en een relevante activiteit verricht.

Dat betekent dat ook private personen gemeld moeten worden door BL. Of lees ik
dat verkeerd?

Verderop:

De rapporterende platformexploitant verzamelt alle volgende inlichtingen voor
elke verkoper die een natuurlijke persoon en geen uitgesloten verkoper is: (en
dan volgt een hele waslijst).


En dit is wat BL moet verstrekken over de verkopers:

e) de totale tegenprestatie die is betaald of gecrediteerd tijdens elk kwartaal
van de rapportageperiode, en het aantal relevante activiteiten waarvoor deze
is betaald of gecrediteerd;
f) alle honoraria, commissielonen of belastingen die door de rapporterende platformexploitant
tijdens elk kwartaal van de rapportageperiode ingehouden of geheven werden.


Feedback welkom
 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Dec 23, 2022 11:23
 Subject: Re: NSV changes for business sellers in EU
 Viewed: 113 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
Cough cough still waiting for the Canada tax update that was supposed to be out
almost half a year ago…
 Author: SylvainLS View Messages Posted By SylvainLS
 Posted: Dec 23, 2022 11:15
 Subject: Re: NSV changes for business sellers in EU
 Viewed: 126 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, cs_anastasia writes:
  Dear BrickLink members,

Due to legal compliance with DAC-7 rules, we are required to collect additional
information from new business sellers in the European Union starting from the
middle of next week. Refer to Article 8ac of the document to find out if you
have the documentation to qualify as a business seller.

https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021L051

Missing a digit at the end:
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021L0514
 Author: CE_Anastasia View Messages Posted By CE_Anastasia
 Posted: Dec 23, 2022 10:59
 Subject: New Seller Verification changes for the EU
 Viewed: 1085 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
Dear BrickLink members,

Due to legal compliance with DAC-7 rules, we are required to collect additional
information from new business sellers in the European Union starting from the
middle of next week. Refer to Article 8ac of the document to find out if you
have the documentation to qualify as a business seller.

https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021L0514

Additional information that we will be collecting includes the following:

- Name of business
- Business registration number, including a supporting document. As different
rules apply for each EU member state, refer to your local authority for more
information
- Tax Identification Number (TIN), including a supporting document:
https://ec.europa.eu/taxation_customs/tin/#/check-tin
- OSS Number and/ or VAT ID for each country of registration:
https://taxation-customs.ec.europa.eu/online-sellers_en

At the moment, only new business sellers who are registering after the launch
are going to be affected by the new procedure. However, if a current EU seller
changes their country, they will be required to provide additional documentation
as well.

All existing EU business sellers should be aware that these rules will also apply
to them starting from 2024, when the re-verification of existing details will
happen. Until then, we will continue working closely with authorities to establish
the best process for this next step.

Thank you,
BrickLink Team
 Author: CE_Tanja View Messages Posted By CE_Tanja
 Posted: Dec 21, 2022 15:05
 Subject: Re: Article about a BrickLink data breach
 Viewed: 239 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
Dear all,

Thanks for your comments and curiosity around the details of this incident.

On reflection, our statement could have been clearer. In this instance, a member
of the community got in touch with us regarding their research findings. Based
on this, we took all precautionary measures to address the vulnerability they
raised and rolled out a fix in early November.

We appreciate they got in touch, but also want to assure everyone that at no
time was any data at risk.

We’re very serious about the security of Bricklink and will continue to take
all necessary steps to make sure the site and users’ data is safe

The BrickLink Team


In Administrative, CE_Tanja writes:
  Dear BrickLink members,

A report has recently surfaced of a possible data breach on our website, BrickLink.com.
We can assure you, our members, that we have seen no evidence of any breach of
our systems and have no reason to believe that the data you entrust us with has
been compromised.

A short while ago, we were approached by a third party who offered their services
to fix several potential security loopholes they had identified. This third party
is not one of our suppliers and we did not request them to provide any analysis
or diagnosis of our systems.

When we did not engage the services of this third party, they apparently released
this “news” that a security breach could have happened on our site. Whereas it
is true that there is always a small possibility that data could be compromised
on any site, we feel this report unfairly portrays our website as unsafe.

We have invested substantially in our security system and are confident in its
ability to keep your data safe. In addition, we strictly follow the LEGO Group
standards for GDPR compliance and other legal requirements regarding the data
of our users.

Thanks for you attention, and please feel free to contact the Help Desk with
any questions you might have.

The BrickLink Team
 Author: macebobo View Messages Posted By macebobo
 Posted: Dec 20, 2022 19:47
 Subject: Re: Article about a BrickLink data breach
 Viewed: 127 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, 1001bricks writes:
  I'd guess it's a reply to "that we have seen no evidence of any breach
of our systems"?

Yeah, I deleted it when I realized who I was replying to. Had my head deep in
a dryer repair today, a popped into the forum during lunch.

Here is a blog post written by Shiran: https://salt.security/blog/missing-bricks-finding-security-holes-in-lego-apis
 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Dec 20, 2022 19:34
 Subject: Re: How sharp are your eyes?
 Viewed: 72 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, Adjour writes:
  If it helps, I never read that thing and today my brain def noticed it. Was something
different this time? Color. *shrug*

 Author: Adjour View Messages Posted By Adjour
 Posted: Dec 20, 2022 19:32
 Subject: Re: How sharp are your eyes?
 Viewed: 47 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
If it helps, I never read that thing and today my brain def noticed it. Was something
different this time? Color. *shrug*
 Author: peregrinator View Messages Posted By peregrinator
 Posted: Dec 20, 2022 19:31
 Subject: Re: How sharp are your eyes?
 Viewed: 41 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, TheCuteGiraffe writes:
  Pffft error 404 for everyone, not me

Yes, but you can only order MegaBlox
 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Dec 20, 2022 19:07
 Subject: Re: How sharp are your eyes?
 Viewed: 47 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, TheCuteGiraffe writes:
  Pffft error 404 for everyone, not me

 Author: TheCuteGiraffe View Messages Posted By TheCuteGiraffe
 Posted: Dec 20, 2022 18:53
 Subject: Re: How sharp are your eyes?
 Viewed: 48 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
Pffft error 404 for everyone, not me
 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Dec 20, 2022 18:46
 Subject: Re: How sharp are your eyes?
 Viewed: 45 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, TheCuteGiraffe writes:
  Yeah, it says 1.00am to 2.00am but here, (ɐᴉlɐɹʇsn∀ uᴉ) its 5-6 in the afternoon.

 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Dec 20, 2022 18:46
 Subject: Re: How sharp are your eyes?
 Viewed: 47 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, SylvainLS writes:
  In Administrative, TheCuteGiraffe writes:
  Yeah, it says 1.00am to 2.00am but here, (ɐᴉlɐɹʇsn∀ uᴉ) its 5-6 in the afternoon.

Hmm, as everything is reversed in Australia, shouldn’t that mean that BrickLink
is only working for you when it doesn’t for us?

 Author: SylvainLS View Messages Posted By SylvainLS
 Posted: Dec 20, 2022 18:28
 Subject: Re: How sharp are your eyes?
 Viewed: 53 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, TheCuteGiraffe writes:
  Yeah, it says 1.00am to 2.00am but here, (ɐᴉlɐɹʇsn∀ uᴉ) its 5-6 in the afternoon.

Hmm, as everything is reversed in Australia, shouldn’t that mean that BrickLink
is only working for you when it doesn’t for us?
 Author: TheCuteGiraffe View Messages Posted By TheCuteGiraffe
 Posted: Dec 20, 2022 18:25
 Subject: Re: How sharp are your eyes?
 Viewed: 51 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
Yeah, it says 1.00am to 2.00am but here, (ɐᴉlɐɹʇsn∀ uᴉ) its 5-6 in the afternoon.
 Author: TheCuteGiraffe View Messages Posted By TheCuteGiraffe
 Posted: Dec 20, 2022 16:31
 Subject: Re: How sharp are your eyes?
 Viewed: 59 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
+1 HUUH people eh.?
 Author: StarBrick View Messages Posted By StarBrick
 Posted: Dec 20, 2022 15:45
 Subject: Re: Article about a BrickLink data breach - Thanks
 Viewed: 84 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
Glad you did what you (guys?) did!
And thanks for posting it here too.
Doesn't take the feeling away Lego should have responded differently, but
my take is that you are 'on our side'. If there are any, that is....
 Author: 1001bricks View Messages Posted By 1001bricks
 Posted: Dec 20, 2022 15:33
 Subject: Re: Article about a BrickLink data breach
 Viewed: 95 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
  What's your point or is this just an ego flex?

I'd guess it's a reply to "that we have seen no evidence of any breach
of our systems"?
 Author: 1001bricks View Messages Posted By 1001bricks
 Posted: Dec 20, 2022 15:31
 Subject: Re: Article about a BrickLink data breach
 Viewed: 84 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, Shiran writes:
  Well well...
Not only that is an utter lie and nobody offered you any "service to fix
several potential security loopholes they had identified", but simply disclosed
the issues to you guys before publishment. Which is the responsible way to do
a coordinated disclosure.

Moreover, when I did the security research on your website I only touched the
tip of the iceberg and found those vulnerabilities. I bet that if I had continued
I'd find ten times more and could've taken over your administrative account
and given any statement I want to the BrickLink community.

Unfortunately for you, I'm already on my next venture to keep the world safe
and will not conduct any further research nor disclose any other vulnerabilities
to BrickLink.

As a concerned Lego fan myself, and especially after witnessing the level of
security in your website I'd strongly advise you guys do some serious work
securing your website instead of giving false statements to your community.

Agreed - unfortunately - and thanks for your work and communication with TLG
as shown in your article in https://salt.security Shiran!

We need people like you.
 Author: Shiran View Messages Posted By Shiran
 Posted: Dec 20, 2022 15:27
 Subject: Re: Article about a BrickLink data breach
 Viewed: 206 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
Well well...
Not only that is an utter lie and nobody offered you any "service to fix
several potential security loopholes they had identified", but simply disclosed
the issues to you guys before publishment. Which is the responsible way to do
a coordinated disclosure.

Moreover, when I did the security research on your website I only touched the
tip of the iceberg and found those vulnerabilities. I bet that if I had continued
I'd find ten times more and could've taken over your administrative account
and given any statement I want to the BrickLink community.

Unfortunately for you, I'm already on my next venture to keep the world safe
and will not conduct any further research nor disclose any other vulnerabilities
to BrickLink.

As a concerned Lego fan myself, and especially after witnessing the level of
security in your website I'd strongly advise you guys do some serious work
securing your website instead of giving false statements to your community.

Cheers


In Administrative, CE_Tanja writes:
  Dear BrickLink members,

A report has recently surfaced of a possible data breach on our website, BrickLink.com.
We can assure you, our members, that we have seen no evidence of any breach of
our systems and have no reason to believe that the data you entrust us with has
been compromised.

A short while ago, we were approached by a third party who offered their services
to fix several potential security loopholes they had identified. This third party
is not one of our suppliers and we did not request them to provide any analysis
or diagnosis of our systems.

When we did not engage the services of this third party, they apparently released
this “news” that a security breach could have happened on our site. Whereas it
is true that there is always a small possibility that data could be compromised
on any site, we feel this report unfairly portrays our website as unsafe.

We have invested substantially in our security system and are confident in its
ability to keep your data safe. In addition, we strictly follow the LEGO Group
standards for GDPR compliance and other legal requirements regarding the data
of our users.

Thanks for you attention, and please feel free to contact the Help Desk with
any questions you might have.

The BrickLink Team
 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Dec 20, 2022 12:29
 Subject: Re: How sharp are your eyes?
 Viewed: 49 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, Leftoverbricks writes:
  In Administrative, Leftoverbricks writes:
  In Administrative, Admin_Russell writes:
  Hello everyone,

There is a thin yellow banner that pops up to remind you about the upcoming monthly
maintenance. Please notice that the date on the banner is exactly one week later
than usual:

[REMINDER] The site will be down during the monthly maintenance scheduled
at 12/28 from 01:00 AM to 02:00 AM EST.


Thank you.

I have very bad eyesight for which I use various aids such as reading glasses
and I view websites in my browser at 120% or more. If the print is really small
I use a magnifying glass on top of that.

If the monthly maintenance differs from previous times, you would do better to
change the design of the banner, or even better: send all your customers
an email that this month is different from previous times.

I find the title of your post offensive to people with low vision and feel offended.

Surely you can do better ???

Russell, I'm still awaiting your reply.

Literally you are the only person who is. No one else cares about this is the
slightest. So why make is a bigger deal then it needs to be?
 Author: Leftoverbricks View Messages Posted By Leftoverbricks
 Posted: Dec 20, 2022 12:14
 Subject: Re: How sharp are your eyes?
 Viewed: 37 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, Leftoverbricks writes:
  In Administrative, Admin_Russell writes:
  Hello everyone,

There is a thin yellow banner that pops up to remind you about the upcoming monthly
maintenance. Please notice that the date on the banner is exactly one week later
than usual:

[REMINDER] The site will be down during the monthly maintenance scheduled
at 12/28 from 01:00 AM to 02:00 AM EST.


Thank you.

I have very bad eyesight for which I use various aids such as reading glasses
and I view websites in my browser at 120% or more. If the print is really small
I use a magnifying glass on top of that.

If the monthly maintenance differs from previous times, you would do better to
change the design of the banner, or even better: send all your customers
an email that this month is different from previous times.

I find the title of your post offensive to people with low vision and feel offended.

Surely you can do better ???

Russell, I'm still awaiting your reply.
 Author: rv6abob View Messages Posted By rv6abob
 Posted: Dec 18, 2022 16:34
 Subject: Re: Article about a BrickLink data breach
 Viewed: 109 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, jodawill writes:
  In Administrative, CE_Tanja writes:
  Dear BrickLink members,

A report has recently surfaced of a possible data breach on our website, BrickLink.com.
We can assure you, our members, that we have seen no evidence of any breach of
our systems and have no reason to believe that the data you entrust us with has
been compromised.

A short while ago, we were approached by a third party who offered their services
to fix several potential security loopholes they had identified. This third party
is not one of our suppliers and we did not request them to provide any analysis
or diagnosis of our systems.

When we did not engage the services of this third party, they apparently released
this “news” that a security breach could have happened on our site. Whereas it
is true that there is always a small possibility that data could be compromised
on any site, we feel this report unfairly portrays our website as unsafe.

We have invested substantially in our security system and are confident in its
ability to keep your data safe. In addition, we strictly follow the LEGO Group
standards for GDPR compliance and other legal requirements regarding the data
of our users.

Thanks for you attention, and please feel free to contact the Help Desk with
any questions you might have.

The BrickLink Team

That's not how this works. A security researcher isn't a "supplier."
The correct response when someone privately discloses a vulnerability is to say
thank you and fix it immediately. Reading between the lines here, it sounds like
Lego's response was simply to ignore them. The standard practice in the industry
is to publicly disclose vulnerabilities if the company doesn't respond because
sometimes (and apparently in this case) bad publicity is the only way to get
things fixed.

We owe a debt to security researchers for finding these vulnerabilities before
the bad guys do. Your post is incredibly disrespectful to the people who keep
us safe. If they hadn't reported this, someone else could have abused it.

Quite frankly, this is one of the worst responses I've ever seen to a security
finding. I expect more from The Lego Group.

I couldn't have said this better myself. I have worked in IT Security and
believe me, there are many of these type incidents. Most of these happen because
companies don't keep all there software updated with the latest security
fixes. The proper response to these incidents is to acknowledge the issue, disclose
the fix and move on.
 Author: wildchicken13 View Messages Posted By wildchicken13
 Posted: Dec 18, 2022 10:45
 Subject: Re: Article about a BrickLink data breach
 Viewed: 72 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, jodawill writes:
  The correct response when someone privately discloses a vulnerability is to say
thank you and fix it immediately. Reading between the lines here, it sounds like
Lego's response was simply to ignore them.

My impression of the article was the opposite:

The security researchers reported the discovered vulnerabilities to LEGO,
and the company took action to fix all issues.


Which is the "correct" response as you stated above.
 Author: 1001bricks View Messages Posted By 1001bricks
 Posted: Dec 18, 2022 00:57
 Subject: Re: Article about a BrickLink data breach
 Viewed: 82 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, macebobo writes:
  In Administrative, zorbanj writes:
  In Administrative, macebobo writes:
  In Administrative, CE_Tanja writes:
  Please rest assured that we are taking these things very seriously.

That was not my take away from your initial post. It felt to me like "No big
deal, these bozos are just trying to scam us into using their product/service."

I sit near the IT dept at my company (I'm not in IT myself) and vendors pull
this stunt all the time. The vendor hopes someone other than the person who decided
not to engage them sees the article and reconsiders them. Dirty pool.

Yes and no. If they are white hat hackers, then it is good. If they are a vendor
trying to get you to use their service, then it is indeed dirty pool. This seems
like it may have been the later. Still, not a good way for BL to respond in
a public forum.

Comic guy (Mark) is in top form today:

http://v4ei.com/comics/index.php?id=breach

The Unbelievable Truth.
Mark is so precious to us - I hope BrickLink deserves his talent.
 Author: Adjour View Messages Posted By Adjour
 Posted: Dec 18, 2022 00:47
 Subject: Re: Article about a BrickLink data breach
 Viewed: 75 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, zorbanj writes:
  In Administrative, macebobo writes:
  In Administrative, CE_Tanja writes:
  Please rest assured that we are taking these things very seriously.

That was not my take away from your initial post. It felt to me like "No big
deal, these bozos are just trying to scam us into using their product/service."

I sit near the IT dept at my company (I'm not in IT myself) and vendors pull
this stunt all the time. The vendor hopes someone other than the person who decided
not to engage them sees the article and reconsiders them. Dirty pool.

Came here to say this.

This occurs in all industries.
 Author: jodawill View Messages Posted By jodawill
 Posted: Dec 17, 2022 20:57
 Subject: Re: Article about a BrickLink data breach
 Viewed: 127 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, CE_Tanja writes:
  Dear BrickLink members,

A report has recently surfaced of a possible data breach on our website, BrickLink.com.
We can assure you, our members, that we have seen no evidence of any breach of
our systems and have no reason to believe that the data you entrust us with has
been compromised.

A short while ago, we were approached by a third party who offered their services
to fix several potential security loopholes they had identified. This third party
is not one of our suppliers and we did not request them to provide any analysis
or diagnosis of our systems.

When we did not engage the services of this third party, they apparently released
this “news” that a security breach could have happened on our site. Whereas it
is true that there is always a small possibility that data could be compromised
on any site, we feel this report unfairly portrays our website as unsafe.

We have invested substantially in our security system and are confident in its
ability to keep your data safe. In addition, we strictly follow the LEGO Group
standards for GDPR compliance and other legal requirements regarding the data
of our users.

Thanks for you attention, and please feel free to contact the Help Desk with
any questions you might have.

The BrickLink Team

That's not how this works. A security researcher isn't a "supplier."
The correct response when someone privately discloses a vulnerability is to say
thank you and fix it immediately. Reading between the lines here, it sounds like
Lego's response was simply to ignore them. The standard practice in the industry
is to publicly disclose vulnerabilities if the company doesn't respond because
sometimes (and apparently in this case) bad publicity is the only way to get
things fixed.

We owe a debt to security researchers for finding these vulnerabilities before
the bad guys do. Your post is incredibly disrespectful to the people who keep
us safe. If they hadn't reported this, someone else could have abused it.

Quite frankly, this is one of the worst responses I've ever seen to a security
finding. I expect more from The Lego Group.
 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Dec 17, 2022 19:07
 Subject: Re: Article about a BrickLink data breach
 Viewed: 91 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, macebobo writes:
  In Administrative, zorbanj writes:
  In Administrative, macebobo writes:
  In Administrative, CE_Tanja writes:
  Please rest assured that we are taking these things very seriously.

That was not my take away from your initial post. It felt to me like "No big
deal, these bozos are just trying to scam us into using their product/service."

I sit near the IT dept at my company (I'm not in IT myself) and vendors pull
this stunt all the time. The vendor hopes someone other than the person who decided
not to engage them sees the article and reconsiders them. Dirty pool.

Yes and no. If they are white hat hackers, then it is good. If they are a vendor
trying to get you to use their service, then it is indeed dirty pool. This seems
like it may have been the later. Still, not a good way for BL to respond in
a public forum.

Comic guy (Mark) is in top form today:

http://v4ei.com/comics/index.php?id=breach

 Author: macebobo View Messages Posted By macebobo
 Posted: Dec 17, 2022 19:01
 Subject: Re: Article about a BrickLink data breach
 Viewed: 88 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, zorbanj writes:
  In Administrative, macebobo writes:
  In Administrative, CE_Tanja writes:
  Please rest assured that we are taking these things very seriously.

That was not my take away from your initial post. It felt to me like "No big
deal, these bozos are just trying to scam us into using their product/service."

I sit near the IT dept at my company (I'm not in IT myself) and vendors pull
this stunt all the time. The vendor hopes someone other than the person who decided
not to engage them sees the article and reconsiders them. Dirty pool.

Yes and no. If they are white hat hackers, then it is good. If they are a vendor
trying to get you to use their service, then it is indeed dirty pool. This seems
like it may have been the later. Still, not a good way for BL to respond in
a public forum.

Comic guy (Mark) is in top form today:

http://v4ei.com/comics/index.php?id=breach
 Author: zorbanj View Messages Posted By zorbanj
 Posted: Dec 17, 2022 18:57
 Subject: Re: Article about a BrickLink data breach
 Viewed: 86 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, macebobo writes:
  In Administrative, CE_Tanja writes:
  Please rest assured that we are taking these things very seriously.

That was not my take away from your initial post. It felt to me like "No big
deal, these bozos are just trying to scam us into using their product/service."

I sit near the IT dept at my company (I'm not in IT myself) and vendors pull
this stunt all the time. The vendor hopes someone other than the person who decided
not to engage them sees the article and reconsiders them. Dirty pool.
 Author: zorbanj View Messages Posted By zorbanj
 Posted: Dec 17, 2022 18:49
 Subject: Re: How sharp are your eyes?
 Viewed: 54 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, Leftoverbricks writes:
  
If the monthly maintenance differs from previous times, you would do better to
change the design of the banner, or even better: send all your customers
an email that this month is different from previous times.

I find the title of your post offensive to people with low vision and feel offended.

Surely you can do better ???

I don't find Russell's title offensive at all, but you do have a good
idea in there about an email blast to sellers.
 Author: TheCuteGiraffe View Messages Posted By TheCuteGiraffe
 Posted: Dec 17, 2022 18:27
 Subject: Re: Article about a BrickLink data breach
 Viewed: 82 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
You giving em out?
 Author: 1001bricks View Messages Posted By 1001bricks
 Posted: Dec 17, 2022 17:44
 Subject: Re: Article about a BrickLink data breach
 Viewed: 82 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
  I am still professionally curious about the scans....

Yep - me too - but you must professionnally know it's not your business (until
you're eventually in contract with them)
 Author: 1001bricks View Messages Posted By 1001bricks
 Posted: Dec 17, 2022 17:40
 Subject: Re: Article about a BrickLink data breach
 Viewed: 79 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
  Are you running a DAST and/or IAST scan?

I'm sure she knows, just like everyone!

I wouldn't do any such acronym thing (first), I'd just a CTRL+F on all
user Input fields and check if they're sanitized correctly...
 Author: CPgolfaddict View Messages Posted By CPgolfaddict
 Posted: Dec 17, 2022 17:28
 Subject: Re: Article about a BrickLink data breach
 Viewed: 95 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
Upon closer read.... near the end. So this is good....

"The security researchers reported the discovered vulnerabilities to LEGO, and
the company took action to fix all issues."

I am still professionally curious about the scans....

In Administrative, CE_Tanja writes:
  Dear BrickLink members,

A report has recently surfaced of a possible data breach on our website, BrickLink.com.
We can assure you, our members, that we have seen no evidence of any breach of
our systems and have no reason to believe that the data you entrust us with has
been compromised.

A short while ago, we were approached by a third party who offered their services
to fix several potential security loopholes they had identified. This third party
is not one of our suppliers and we did not request them to provide any analysis
or diagnosis of our systems.

When we did not engage the services of this third party, they apparently released
this “news” that a security breach could have happened on our site. Whereas it
is true that there is always a small possibility that data could be compromised
on any site, we feel this report unfairly portrays our website as unsafe.

We have invested substantially in our security system and are confident in its
ability to keep your data safe. In addition, we strictly follow the LEGO Group
standards for GDPR compliance and other legal requirements regarding the data
of our users.

Thanks for you attention, and please feel free to contact the Help Desk with
any questions you might have.

The BrickLink Team
 Author: SylvainLS View Messages Posted By SylvainLS
 Posted: Dec 17, 2022 17:12
 Subject: Re: Article about a BrickLink data breach
 Viewed: 102 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, CPgolfaddict writes:
  Can you provide some assurance us by telling us the types of security scans that
you are running on BrickLink? You don't need to name brands/names of specific
tools. Just the sorts of things you are doing...

Are you running a DAST and/or IAST scan? (Dynamic and/or interactive scans)
This sort of application scan, (run on a test environment) probes the application
for breaches such as those mentioned in the article.

A SAST (static testing) may also help in this area.
known vulnerable patterns in the code itself.

SCA - Software Composition Analysis (e.g. looking for vulnerable Open Source
Libraries incorporated into the application). I'm used to calling this Open
Source SW scanning.

Secrets -- Scanning for api key/secret or an ID/PW inadvertently left in
the code itself.

Looking for a job?
 Author: CPgolfaddict View Messages Posted By CPgolfaddict
 Posted: Dec 17, 2022 16:58
 Subject: Re: Article about a BrickLink data breach
 Viewed: 102 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
Can you provide some assurance us by telling us the types of security scans that
you are running on BrickLink? You don't need to name brands/names of specific
tools. Just the sorts of things you are doing...

Are you running a DAST and/or IAST scan? (Dynamic and/or interactive scans)
This sort of application scan, (run on a test environment) probes the application
for breaches such as those mentioned in the article.

A SAST (static testing) may also help in this area.
known vulnerable patterns in the code itself.

SCA - Software Composition Analysis (e.g. looking for vulnerable Open Source
Libraries incorporated into the application). I'm used to calling this Open
Source SW scanning.

Secrets -- Scanning for api key/secret or an ID/PW inadvertently left in
the code itself.


In Administrative, CE_Tanja writes:
  Dear BrickLink members,

A report has recently surfaced of a possible data breach on our website, BrickLink.com.
We can assure you, our members, that we have seen no evidence of any breach of
our systems and have no reason to believe that the data you entrust us with has
been compromised.

A short while ago, we were approached by a third party who offered their services
to fix several potential security loopholes they had identified. This third party
is not one of our suppliers and we did not request them to provide any analysis
or diagnosis of our systems.

When we did not engage the services of this third party, they apparently released
this “news” that a security breach could have happened on our site. Whereas it
is true that there is always a small possibility that data could be compromised
on any site, we feel this report unfairly portrays our website as unsafe.

We have invested substantially in our security system and are confident in its
ability to keep your data safe. In addition, we strictly follow the LEGO Group
standards for GDPR compliance and other legal requirements regarding the data
of our users.

Thanks for you attention, and please feel free to contact the Help Desk with
any questions you might have.

The BrickLink Team
 Author: CE_Tanja View Messages Posted By CE_Tanja
 Posted: Dec 17, 2022 15:33
 Subject: Re: Article about a BrickLink data breach
 Viewed: 137 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, macebobo writes:
  In Administrative, CE_Tanja writes:
  Please rest assured that we are taking these things very seriously.

That was not my take away from your initial post. It felt to me like "No big
deal, these bozos are just trying to scam us into using their product/service."

Fair enough! But that is not the case at all! That is never the case

Happy Holidays!
 Author: macebobo View Messages Posted By macebobo
 Posted: Dec 17, 2022 14:47
 Subject: Re: Article about a BrickLink data breach
 Viewed: 111 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, CE_Tanja writes:
  Please rest assured that we are taking these things very seriously.

That was not my take away from your initial post. It felt to me like "No big
deal, these bozos are just trying to scam us into using their product/service."
 Author: macebobo View Messages Posted By macebobo
 Posted: Dec 17, 2022 14:39
 Subject: Re: Article about a BrickLink data breach
 Viewed: 105 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, peregrinator writes:
  In Administrative, macebobo writes:
  Link for those who did not see it yesterday: https://www.bleepingcomputer.com/news/security/lego-bricklink-bugs-let-hackers-hijack-accounts-breach-servers/

From the article, which then goes on to describe vulnerabilities totally unrelated
to the API:
   Security analysts have discovered two API security vulnerabilities in BrickLink.com

Not sure of your point, but it does not make the XSS and XXE vulnerabilities
any less concerning. I wrote it off to poor writing/journalism.
 Author: peregrinator View Messages Posted By peregrinator
 Posted: Dec 17, 2022 14:31
 Subject: Re: Article about a BrickLink data breach
 Viewed: 119 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, macebobo writes:
  Link for those who did not see it yesterday: https://www.bleepingcomputer.com/news/security/lego-bricklink-bugs-let-hackers-hijack-accounts-breach-servers/

From the article, which then goes on to describe vulnerabilities totally unrelated
to the API:
   Security analysts have discovered two API security vulnerabilities in BrickLink.com
 Author: CE_Tanja View Messages Posted By CE_Tanja
 Posted: Dec 17, 2022 14:16
 Subject: Re: Article about a BrickLink data breach
 Viewed: 149 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
Please rest assured that we are taking these things very seriously.

In Administrative, macebobo writes:
  In Administrative, CE_Tanja writes:
  Dear BrickLink members,

A report has recently surfaced of a possible data breach on our website, BrickLink.com.
We can assure you, our members, that we have seen no evidence of any breach of
our systems and have no reason to believe that the data you entrust us with has
been compromised.

Yet. It is a vulnerability as stated in the article.

  A short while ago, we were approached by a third party who offered their services
to fix several potential security loopholes they had identified. This third party
is not one of our suppliers and we did not request them to provide any analysis
or diagnosis of our systems.

When we did not engage the services of this third party, they apparently released
this “news” that a security breach could have happened on our site. Whereas it
is true that there is always a small possibility that data could be compromised
on any site, we feel this report unfairly portrays our website as unsafe.

Not unsafe, just vulnerable. Does this mean you are not taking it seriously and
are going to do nothing to remediate the identified attack vectors? (Two issues,
XSS and XXE attacks.)

  We have invested substantially in our security system and are confident in its
ability to keep your data safe. In addition, we strictly follow the LEGO Group
standards for GDPR compliance and other legal requirements regarding the data
of our users.

Blah, blah, blah. Nothing to see here, ignore the minifig behind the curtain.

  Thanks for you attention, and please feel free to contact the Help Desk with
any questions you might have.

The BrickLink Team

Link for those who did not see it yesterday: https://www.bleepingcomputer.com/news/security/lego-bricklink-bugs-let-hackers-hijack-accounts-breach-servers/
 Author: macebobo View Messages Posted By macebobo
 Posted: Dec 17, 2022 14:14
 Subject: Re: Article about a BrickLink data breach
 Viewed: 170 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, CE_Tanja writes:
  Dear BrickLink members,

A report has recently surfaced of a possible data breach on our website, BrickLink.com.
We can assure you, our members, that we have seen no evidence of any breach of
our systems and have no reason to believe that the data you entrust us with has
been compromised.

Yet. It is a vulnerability as stated in the article.

  A short while ago, we were approached by a third party who offered their services
to fix several potential security loopholes they had identified. This third party
is not one of our suppliers and we did not request them to provide any analysis
or diagnosis of our systems.

When we did not engage the services of this third party, they apparently released
this “news” that a security breach could have happened on our site. Whereas it
is true that there is always a small possibility that data could be compromised
on any site, we feel this report unfairly portrays our website as unsafe.

Not unsafe, just vulnerable. Does this mean you are not taking it seriously and
are going to do nothing to remediate the identified attack vectors? (Two issues,
XSS and XXE attacks.)

  We have invested substantially in our security system and are confident in its
ability to keep your data safe. In addition, we strictly follow the LEGO Group
standards for GDPR compliance and other legal requirements regarding the data
of our users.

Blah, blah, blah. Nothing to see here, ignore the minifig behind the curtain.

  Thanks for you attention, and please feel free to contact the Help Desk with
any questions you might have.

The BrickLink Team

Link for those who did not see it yesterday: https://www.bleepingcomputer.com/news/security/lego-bricklink-bugs-let-hackers-hijack-accounts-breach-servers/
 Author: CE_Tanja View Messages Posted By CE_Tanja
 Posted: Dec 17, 2022 13:56
 Subject: Article about a BrickLink data breach
 Viewed: 842 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
Dear BrickLink members,

A report has recently surfaced of a possible data breach on our website, BrickLink.com.
We can assure you, our members, that we have seen no evidence of any breach of
our systems and have no reason to believe that the data you entrust us with has
been compromised.

A short while ago, we were approached by a third party who offered their services
to fix several potential security loopholes they had identified. This third party
is not one of our suppliers and we did not request them to provide any analysis
or diagnosis of our systems.

When we did not engage the services of this third party, they apparently released
this “news” that a security breach could have happened on our site. Whereas it
is true that there is always a small possibility that data could be compromised
on any site, we feel this report unfairly portrays our website as unsafe.

We have invested substantially in our security system and are confident in its
ability to keep your data safe. In addition, we strictly follow the LEGO Group
standards for GDPR compliance and other legal requirements regarding the data
of our users.

Thanks for you attention, and please feel free to contact the Help Desk with
any questions you might have.

The BrickLink Team
 Author: wildchicken13 View Messages Posted By wildchicken13
 Posted: Dec 17, 2022 13:55
 Subject: Re: How sharp are your eyes?
 Viewed: 73 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, Admin_Russell writes:
  Hello everyone,

There is a thin yellow banner that pops up to remind you about the upcoming monthly
maintenance. Please notice that the date on the banner is exactly one week later
than usual:

[REMINDER] The site will be down during the monthly maintenance scheduled
at 12/28 from 01:00 AM to 02:00 AM EST.


Thank you.

Thanks for the heads up. I look forward to the site going down every month.

Would it be possible to make the banner dynamic, so that it displays the time
in the user's current local time? I am very fortunate to live in the Eastern
Time Zone which BrickLink uses, but we've users from all over the world here.
 Author: wildchicken13 View Messages Posted By wildchicken13
 Posted: Dec 17, 2022 13:51
 Subject: Re: How sharp are your eyes?
 Viewed: 55 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, Leftoverbricks writes:
  I have very bad eyesight for which I use various aids such as reading glasses
and I view websites in my browser at 120% or more. If the print is really small
I use a magnifying glass on top of that.

If the monthly maintenance differs from previous times, you would do better to
change the design of the banner, or even better: send all your customers
an email that this month is different from previous times.

I find the title of your post offensive to people with low vision and feel offended.

Surely you can do better ???

I didn't see that one coming!
 Author: manganschlamm View Messages Posted By manganschlamm
 Posted: Dec 17, 2022 12:28
 Subject: Re: How sharp are your eyes?
 Viewed: 57 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, Leftoverbricks writes:
  In Administrative, Admin_Russell writes:
  Hello everyone,

There is a thin yellow banner that pops up to remind you about the upcoming monthly
maintenance. Please notice that the date on the banner is exactly one week later
than usual:

[REMINDER] The site will be down during the monthly maintenance scheduled
at 12/28 from 01:00 AM to 02:00 AM EST.


Thank you.

I have very bad eyesight for which I use various aids such as reading glasses
and I view websites in my browser at 120% or more. If the print is really small
I use a magnifying glass on top of that.

If the monthly maintenance differs from previous times, you would do better to
change the design of the banner, or even better: send all your customers
an email that this month is different from previous times.

I find the title of your post offensive to people with low vision and feel offended.

Surely you can do better ???


I am sure soon someone will complain that the banner does not show the LGBT+
colors and feel offended by not being included.
 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Dec 17, 2022 11:58
 Subject: Re: How sharp are your eyes?
 Viewed: 49 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, jennnifer writes:
  In Administrative, Nubs_Select writes:
  
  
I find the title of your post offensive to people with low vision and feel offended.

Really… really… you can never win with some people

  Surely you can do better ???



Yes, I can think of much better things to complain about! But, hey, if we didn't
have our share of negative people, it wouldn't be the internet I guess.

That is true! The internets best quality!

  Have a happy day everyone!

Likewise!

  Jen
 Author: jennnifer View Messages Posted By jennnifer
 Posted: Dec 17, 2022 11:49
 Subject: Re: How sharp are your eyes?
 Viewed: 54 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, Nubs_Select writes:
  
  
I find the title of your post offensive to people with low vision and feel offended.

Really… really… you can never win with some people

  Surely you can do better ???



Yes, I can think of much better things to complain about! But, hey, if we didn't
have our share of negative people, it wouldn't be the internet I guess.

Have a happy day everyone!

Jen
 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Dec 17, 2022 11:32
 Subject: Re: How sharp are your eyes?
 Viewed: 46 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, goldknight writes:
  In Administrative, Leftoverbricks writes:
  In Administrative, Admin_Russell writes:
  Hello everyone,

There is a thin yellow banner that pops up to remind you about the upcoming monthly
maintenance. Please notice that the date on the banner is exactly one week later
than usual:

[REMINDER] The site will be down during the monthly maintenance scheduled
at 12/28 from 01:00 AM to 02:00 AM EST.


Thank you.

I have very bad eyesight for which I use various aids such as reading glasses
and I view websites in my browser at 120% or more. If the print is really small
I use a magnifying glass on top of that.

If the monthly maintenance differs from previous times, you would do better to
change the design of the banner, or even better: send all your customers
an email that this month is different from previous times.

I find the title of your post offensive to people with low vision and feel offended.

Surely you can do better ???

Good morning to you!😀

 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Dec 17, 2022 11:31
 Subject: Re: How sharp are your eyes?
 Viewed: 45 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, Leftoverbricks writes:
  In Administrative, Admin_Russell writes:
  Hello everyone,

There is a thin yellow banner that pops up to remind you about the upcoming monthly
maintenance. Please notice that the date on the banner is exactly one week later
than usual:

[REMINDER] The site will be down during the monthly maintenance scheduled
at 12/28 from 01:00 AM to 02:00 AM EST.


Thank you.

I have very bad eyesight for which I use various aids such as reading glasses
and I view websites in my browser at 120% or more. If the print is really small
I use a magnifying glass on top of that.

If the monthly maintenance differs from previous times, you would do better to
change the design of the banner, or even better: send all your customers
an email that this month is different from previous times.

I find the title of your post offensive to people with low vision and feel offended.

Really… really… you can never win with some people

  Surely you can do better ???

 Author: goldknight View Messages Posted By goldknight
 Posted: Dec 17, 2022 11:26
 Subject: Re: How sharp are your eyes?
 Viewed: 47 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, Leftoverbricks writes:
  In Administrative, Admin_Russell writes:
  Hello everyone,

There is a thin yellow banner that pops up to remind you about the upcoming monthly
maintenance. Please notice that the date on the banner is exactly one week later
than usual:

[REMINDER] The site will be down during the monthly maintenance scheduled
at 12/28 from 01:00 AM to 02:00 AM EST.


Thank you.

I have very bad eyesight for which I use various aids such as reading glasses
and I view websites in my browser at 120% or more. If the print is really small
I use a magnifying glass on top of that.

If the monthly maintenance differs from previous times, you would do better to
change the design of the banner, or even better: send all your customers
an email that this month is different from previous times.

I find the title of your post offensive to people with low vision and feel offended.

Surely you can do better ???

Good morning to you!😀
 Author: Leftoverbricks View Messages Posted By Leftoverbricks
 Posted: Dec 17, 2022 10:49
 Subject: Re: How sharp are your eyes?
 Viewed: 75 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, Admin_Russell writes:
  Hello everyone,

There is a thin yellow banner that pops up to remind you about the upcoming monthly
maintenance. Please notice that the date on the banner is exactly one week later
than usual:

[REMINDER] The site will be down during the monthly maintenance scheduled
at 12/28 from 01:00 AM to 02:00 AM EST.


Thank you.

I have very bad eyesight for which I use various aids such as reading glasses
and I view websites in my browser at 120% or more. If the print is really small
I use a magnifying glass on top of that.

If the monthly maintenance differs from previous times, you would do better to
change the design of the banner, or even better: send all your customers
an email that this month is different from previous times.

I find the title of your post offensive to people with low vision and feel offended.

Surely you can do better ???
 Author: TheCuteGiraffe View Messages Posted By TheCuteGiraffe
 Posted: Dec 17, 2022 05:02
 Subject: Re: How sharp are your eyes?
 Viewed: 48 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
If u miss BL that much you can use BL Beta, that’s not shut during maintenance.


The Cute Giraffe
 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Dec 17, 2022 03:31
 Subject: Re: How sharp are your eyes?
 Viewed: 54 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, Admin_Russell writes:
  Hello everyone,

There is a thin yellow banner that pops up to remind you about the upcoming monthly
maintenance. Please notice that the date on the banner is exactly one week later
than usual:

[REMINDER] The site will be down during the monthly maintenance scheduled
at 12/28 from 01:00 AM to 02:00 AM EST.


Thank you.

Thanks for the heads up. Whenever I see the banner appear I realize that in the
coming weeks the site will be down for an hour while I’m scrolling on my phone
at 1 in the morning and won’t be able to check bricklink
 Author: Admin_Russell View Messages Posted By Admin_Russell
 Posted: Dec 17, 2022 03:29
 Subject: How sharp are your eyes?
 Viewed: 545 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
Hello everyone,

There is a thin yellow banner that pops up to remind you about the upcoming monthly
maintenance. Please notice that the date on the banner is exactly one week later
than usual:

[REMINDER] The site will be down during the monthly maintenance scheduled
at 12/28 from 01:00 AM to 02:00 AM EST.


Thank you.
 
 Author: cycbuild View Messages Posted By cycbuild
 Posted: Dec 14, 2022 08:04
 Subject: Re: Reserve your LEGO® account nickname today!
 Viewed: 63 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
Just a heads up. If you reserved yours on Nov 15 and were waiting to adjust it
before changing your BL username, you can try again tomorrow.
 
 Author: TheCuteGiraffe View Messages Posted By TheCuteGiraffe
 Posted: Dec 13, 2022 23:15
 Subject: Re: Recent Forum spam
 Viewed: 63 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Dec 12, 2022 19:11
 Subject: Re: Recent Forum spam
 Viewed: 58 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, ImperialFleet writes:
  Bruuhhhhhhh

MBA


its even a real thing
 Author: ImperialFleet View Messages Posted By ImperialFleet
 Posted: Dec 12, 2022 18:33
 Subject: Re: Recent Forum spam
 Viewed: 40 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
Bruuhhhhhhh

MBA
 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Dec 12, 2022 14:49
 Subject: Re: Recent Forum spam
 Viewed: 59 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, 1001bricks writes:
  In Administrative, Nubs_Select writes:
  In Administrative, ImperialFleet writes:
  People thar spam are annoying, but without them funny replies like this wouldn't
be possible!



  MBAQANGA

Sorry I let predictive text auto complete your sign off

See? We don't need external spammers.

 Author: 1001bricks View Messages Posted By 1001bricks
 Posted: Dec 12, 2022 14:45
 Subject: Re: Recent Forum spam
 Viewed: 46 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, Nubs_Select writes:
  In Administrative, ImperialFleet writes:
  People thar spam are annoying, but without them funny replies like this wouldn't
be possible!



  MBAQANGA

Sorry I let predictive text auto complete your sign off

See? We don't need external spammers.
 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Dec 12, 2022 14:39
 Subject: Re: Recent Forum spam
 Viewed: 68 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, ImperialFleet writes:
  People thar spam are annoying, but without them funny replies like this wouldn't
be possible!



  MBAQANGA

Sorry I let predictive text auto complete your sign off
 Author: ImperialFleet View Messages Posted By ImperialFleet
 Posted: Dec 12, 2022 14:31
 Subject: Re: Recent Forum spam
 Viewed: 59 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
People thar spam are annoying, but without them funny replies like this wouldn't
be possible!

MBA
 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Dec 12, 2022 14:27
 Subject: Re: Recent Forum spam
 Viewed: 46 times
 Topic: Administrative
View Message
View
Cancel Message
Cancel
Reply to Message
Reply
In Administrative, UTLF writes:
  
  “PDEL from Brick Hill is a real giga chad”

ah yes, because the first thing you think of when you hear "gigachad" is a Roblox
server

Next Page: 5 More | 10 More | 25 More | 50 More | 100 More