They take great pains to point out they are not sure that the entire database was transferred (although it could have been) and that they don't know that anyone has used the data (although they could have) - all they're saying is that they were storing her personal data on a server that somebody had obtained unauthorized access to.
Well, great. This keeps happening to Universities - there are books telling you how to mine SSNs from universities - yet over 5 years later E's data sits in cleartext because they needed to "archive" their poor security choices.
Helpfully, they suggest watching our credit reports and account activity to see if anything "unusual" occurs. Forever.
Thanks, guys.
I don't believe that her data is likely to be put to evil ends that would affect us - but isn't it nice to know that that possibility will always exist?
-----
On a related note - I received an email from Gawker telling me that my account had been compromised. I honestly didn't remember ever having an account with them, but it's possible that I posted a comment there years back.
I'm set to ignore it when I get a second email from LinkedIn - telling me I should reset my account because of the Gawker intrusion.
So I reset LinkedIn and start on Gawker for good measure. Gawker's website is just godawful UI and (bonus) their email server is having problems, so when you try you get a "Reset Failed" message that appears for 2 seconds.
Well, thanks guys. I'm so glad that I tried, now I will try again.
And again.
And then wait 5 minutes and try again.
And then go away for an hour and then try again.
And so on - until the damn thing finally sends me a reset link.
You figure you have a security breach that requires resets, you might try to see if your reset process is actually working before you push the send button on the "we're so owned" message.
Fail.
Coding Horror has the goods on Gawker's data faceplant, and wow have they screwed the pooch.
The hack came complete with release notes from the hackers which goes out of its way to shame them.
They post the usernames and passwords of Gawker staff. Then they use the password of Gawker's Nick Denton to see how many other accounts they can get to.
Subtext for users: Don't use one password for multiple sites.
They post this bit of fun:
They then post ftp logins for several other companies to drive home the point.You'd think by now after being compromised Nick would change all his passwords.He doesn't, instead his fellow circle jerkers convince him that it was his own fault,That the account wasn't hacked but instead Nicks own fault by clicking a "link" lol.
Nice.
The release notes detail the depth of the attack - and is illustrative for lots of reasons.
Forbe's has more detail.
What Could Gawker Have Done Differently?
Everything. Their founder noticed strange activity a month ago, and reported it, yet the investigation into it came to the wrong conclusions. It seems clear they do not have a good information security person on staff or that they can call. When they closed out the Nick Denton account on campfire, they could have realized that someone logging in as him to an internal system might mean that someone outside the company has access to internal systems or that the extent of the breach may be larger..
Subtext to businesses: don't be like these guys.
No comments:
Post a Comment