AVE website completely offline

Status
Not open for further replies.

unloaded

Ultra Member
ECF Veteran
Verified Member
Jun 2, 2011
2,491
2,365
SW. Indiana
I just hope they've been making a huge stockpile of juice to meet the demand when they reopen. I'm down to about 100ml of Boba's and I'm starting to get nervous. The only time I've been without is when I sucked down the first sample bottle of it and had to wait on new bottle to arrive. That was almost two years ago. Since then I've always had some coming when I opened my last 100ml bottle. Until recently I've even been able to get it locally. Made it through a lot of droughts but I'm getting edgy this time. Don't want to find out what it's like to be without.
 

Jermania

Moved On
Jun 18, 2012
166
71
Valhalla
Online fraud is super confusing for a good reason, and that is to remain untraceable. In this case, the hackers were only out to sabotage, which is why very few of the transactions were successful. If a hacker really wanted to successfully funnel funds from our accounts, they would have done so quietly with our identities, not through such obvious fronts. This type of hacking is intended to terrorize more than anything.
 

fogMann

Senior Member
ECF Veteran
Verified Member
May 4, 2013
204
184
Chicago, IL, USA
I have never tried BB but hope to have the opportunity. I read posts about getting down to “my last 100ml”. Holy @%#^. Wish he was my neighbor.
I really hope this can live up to the hype. I’m considering ordering all the stuff to brew my own clone posted on the DIY threads. I’ll guess it would be lacking but I think the brewers working on that are getting close to a facsimile. That may be quicker since I expect AVE will have a horrible backlog if/when they re-open. I also hope they don’t shut off orders daily as I’ve read they do. One guy posted that he wakes up at 8am checking the site, hoping beyond hope that he’ll squeeze into the open for business window. Yikes, I have a day job.
Don’t reply to this with a “yeah, go away, we’ll take your share” comment. I’ll wiggle my way through the waiting line. It may not live up to all the hype since I now expect something between a morphine drip and an orgasm, but I expect it’ll be a great vape. But, I’ve been cutting my teeth on some really nice juices. Of course, more have been ho-hum and a few of them -- I’d swear some high school kid cooked the recipe up in his kitchen one afternoon.
 

Michael James

Super Member
ECF Veteran
Verified Member
Jan 28, 2012
322
119
Montgomery, AL
I have never tried BB but hope to have the opportunity. I read posts about getting down to “my last 100ml”. Holy @%#^. Wish he was my neighbor.
I really hope this can live up to the hype. I’m considering ordering all the stuff to brew my own clone posted on the DIY threads. I’ll guess it would be lacking but I think the brewers working on that are getting close to a facsimile. That may be quicker since I expect AVE will have a horrible backlog if/when they re-open. I also hope they don’t shut off orders daily as I’ve read they do. One guy posted that he wakes up at 8am checking the site, hoping beyond hope that he’ll squeeze into the open for business window. Yikes, I have a day job.
Don’t reply to this with a “yeah, go away, we’ll take your share” comment. I’ll wiggle my way through the waiting line. It may not live up to all the hype since I now expect something between a morphine drip and an orgasm, but I expect it’ll be a great vape. But, I’ve been cutting my teeth on some really nice juices. Of course, more have been ho-hum and a few of them -- I’d swear some high school kid cooked the recipe up in his kitchen one afternoon.

You'll either love it or hate it. I had a reg vape before it. After vaping it for a while now I will say I can't vape PG blends anymore, it just tastes like ..... My old one before BB I had to give to my wife and reorder in 100% vg. BB is my go to for sure, but I won't die if they don't come back. But it's definitely on a level by itself.
 
Last edited:

Jermania

Moved On
Jun 18, 2012
166
71
Valhalla
Bobas cannot ever be duplicated due to the fact it uses tobacco extract. Notice you cannot get bobas in zero nic. Determining which tobacco is a challenge enough, but perhaps its a combo, who knows? This juice sparked so much creativity while attempting to duplicate, it has become redundant. We have discovered enough awesome recipes because of it, to no longer be dependent upon it, and that alone is worthy of a legacy. It now boils down to if you are willing to become a mix master yourself. I for one hate doing it, and would much rather buy it from the master himself. I got other .... to do.
 

BentWookie

Super Member
ECF Veteran
Verified Member
Feb 14, 2013
418
343
SF Bay Area CA USA
They didn't either... Otherwise they wouldn't have had card data on a PCI compliant server in the first place.




Not likely, more like the Processor revoked their cert until they come into compliance.

PCI compliance had nothing to do with the problems seen with the fraud. PCI compliance dictates that if he is to store credit card info in his database that his database should be encrypted. It also states that you must encrypt any transmission of data containing personal and financial information.

As the credit card info never directly touched any of the AVE servers and went directly to the processors and all transactions were done via port 925 he was in full compliance.
 

MonsterTKE

Senior Member
ECF Veteran
Verified Member
May 4, 2012
112
73
Georgia
As the credit card info never directly touched any of the AVE servers and went directly to the processors and all transactions were done via port 925 he was in full compliance.

My handbook lists a lot more than that for compliance, assuming they weren't just using the authorize.net api. If that's the case, why is everyone ...... at ave for the breach? Maybe they should have communicated with their customers better, considering I had to cancel a card due to unauthorized activity, I had no contact from them. I had to learn about it here and /r/ecf.

And whats this about port 925? Authorize.net is on 80 and 443 according to their specs, and google literally turns nothing up for "port 925 credit card processing"?
 

BentWookie

Super Member
ECF Veteran
Verified Member
Feb 14, 2013
418
343
SF Bay Area CA USA
My handbook lists a lot more than that for compliance, assuming they weren't just using the authorize.net api. If that's the case, why is everyone ...... at ave for the breach? Maybe they should have communicated with their customers better, considering I had to cancel a card due to unauthorized activity, I had no contact from them. I had to learn about it here and /r/ecf.

And whats this about port 925? Authorize.net is on 80 and 443 according to their specs, and google literally turns nothing up for "port 925 credit card processing"?


Sorry about that. I was still thinking Secure POP which uses port 925 for communication as I am currently dealing with multiple PCI projects in regards to secure email infrastructures. Yes port 443 was the transaction port that AVE was using. People are upset because the average Joe does not understand the workflow of how payment is made and handled in the background. Most people don't even understand that AVE's servers are not even physically accessible by them.

AVE will NOT receive notifications that their customer's credit cards have been compromised since it is against financial regulations to inform vendors of such matters. Instead the credit card processors will notify the issuing bank of any potential breach and it is the issuing bank's duty to notify their customers. At least this is what I understand from the 10 largest banks that I work with here in the USA. This makes it impossible for AVE to notify specific customers that their credit cards have been compromised. The only thing they can do is issue a generic notice that some customers have complained and that you should review your credit card statements for any fraudulent activity. Something ALL people should do anyway with each and every statement that they receive. I also need to add that AVE was not alone in this attack. During the February-April time frame several online retailers were attacked and several credit cards were compromised. This attack was widespread throughout several different types of business and not specific to the vaping community.
 
Last edited:

Veezy

Senior Member
ECF Veteran
Verified Member
Mar 4, 2013
222
126
California
Thank you for this. I didn't feel like getting into another e-brawl


PCI compliance had nothing to do with the problems seen with the fraud. PCI compliance dictates that if he is to store credit card info in his database that his database should be encrypted. It also states that you must encrypt any transmission of data containing personal and financial information.

As the credit card info never directly touched any of the AVE servers and went directly to the processors and all transactions were done via port 925 he was in full compliance.
 
Last edited:

Michael James

Super Member
ECF Veteran
Verified Member
Jan 28, 2012
322
119
Montgomery, AL
Yeah I do web and graphic design as a side hobby and from experience setting up and configuring blogs, shopping carts and the like they're definitely look to be setting it back up. If they moved hosting companies they might have the SQL (database) server on another physical server so you can't use localhost as you could if it was the same server. Also they could just be using the new site with a different SQL host and haven't changed the config file in their cart to point to it yet.

So with the site in it's current condition I see it as a good sign.
Card in hand finger on F5 key.

Actually I kind of take it back to a neutral stance, they still have the same images on the site, and it wouldn't take them 5 seconds to make a coming soon page. But then again they aren't exactly keeping anyone informed so who knows.
 

transamspirit

Senior Member
ECF Veteran
Jan 25, 2013
135
44
41
mobile al
It's possible that your other vendors aren't two person operations with insane demand.
And how much money has avejuice made and not prepared for this????? Nothing against them but its not good business to have a hokey website while making huge profits. Well deserved huge profits. I freaking love av bobas and hype. Amazing juice. ... but a hokey site... is silly
 
Status
Not open for further replies.

Users who are viewing this thread