Live data from Hacker News

Weebly hacked, 43M credentials stolen

techcrunch.com

51–60 of 99 posts

Re: Weebly hacked, 43M credentials stolen

#51
post #48
post #42

Earlier quoted context omitted.

Security is hard. It is very possible to take it seriously, do many things right (perhaps everything right, insofar as it's in your power), and still have your company end up in a headline like this. You can parameterize your queries until you're blue in the face, but that won't help you if the right employee is phished (for example). This is an inherently imperfect and chaotic world, and it's unrealistic to assume t…

I'm kind of tired of the "Security is hard, every one gets hacked eventually and we are just victims" mentality. This is not true. Why don't we see peoples banking information plastered over the web every month? That if something would be a high value target. No, it's always these Web 2.0 services this happens to. Now, you could argue that a small SAAS service can not possibly afford security as rigorous as a bank, b…

I invite you to research this topic more thoroughly.

First, while there is a recent uptick in breaches, newsworthy ones do not happen every month. There does appear to be something of a clustering effect, which I think is attributable to a number of different causes. [1]

Second, banks, even very large ones like Citigroup and Chase, have been compromised in recent memory. [2] Even the IRS suffered one of the largest breaches ever, just last year. Peripherally "financial" institutions that aren't banks have also suffered breaches, such as every single credit card processor and NASDAQ.

You have a right to be upset about the increasing probability of your passwords being compromised by third parties. As a consumer, you can mitigate the damage of such breaches by 1. using a password manager, 2. using a different password for each and every account you have and 3. generating extremely secure passwords for each account. You can also use services like HaveIBeenPwned [3] to stay ahead of the damage.

However, your indictment here is unreasonable. Like basically everyone else in this thread, you don't have much information to go on yet. Weebly properly hashed and stored their passwords. As far as breaches go, this one is pretty tame. They are reacting responsibly and quickly considering the breach happened this year - normally we'd find out about this in three years. We do not yet know the root cause of the attack, and the criticism you're levying against Weebly is equally applicable to the industries you believe are more safe (they aren't). While many "web 2.0" companies may be rather lax in security, Weebly did not do anything obviously wrong or negligent here.

________________________

1. As data breaches become more of a hot topic, they will be more likely to be reported widely because it guarantees eyeballs. Similarly, it increases scrutiny, which aids in discoverability, and leads to more copycat hackers attempting these breaches for fame or fortune.

2. https://en.m.wikipedia.org/wiki/List_of_data_breaches

3. https://haveibeenpwned.com

Re: Weebly hacked, 43M credentials stolen

#52
post #48
post #42

Earlier quoted context omitted.

Security is hard. It is very possible to take it seriously, do many things right (perhaps everything right, insofar as it's in your power), and still have your company end up in a headline like this. You can parameterize your queries until you're blue in the face, but that won't help you if the right employee is phished (for example). This is an inherently imperfect and chaotic world, and it's unrealistic to assume t…

I'm kind of tired of the "Security is hard, every one gets hacked eventually and we are just victims" mentality. This is not true. Why don't we see peoples banking information plastered over the web every month? That if something would be a high value target. No, it's always these Web 2.0 services this happens to. Now, you could argue that a small SAAS service can not possibly afford security as rigorous as a bank, b…

Why don't we see peoples banking information plastered over the web every month?

Banks get hacked. They just don't tell people about it. The difference is that banks aren't as transparent, not that they're more secure.

Re: Weebly hacked, 43M credentials stolen

#53
post #38
post #31

Earlier quoted context omitted.

That incident response firm seems to be worth it.

Weebly is one of the more clueful startups. They didn't get this from the IR team. They've been doing stuff right for a long time.

I don't doubt that they're clueful. That's why I'm confident that they hired an excellent incident response team and wisely chose to have them review and edit any external communication. Anything less would be irresponsible.

Re: Weebly hacked, 43M credentials stolen

#54
post #37

Earlier quoted context omitted.

Can't blame you for being hacked, but how can security be "core to who we are" if it took 6 months to discover a breach?

You're describing basically every breach ever.

You wish. I'd wager the majority never gets discovered.

Re: Weebly hacked, 43M credentials stolen

#55
I have talked to a number of current and former Weebly employees trying to convince them to use things like hardware token based 2FA, hardened servers, hardened workstations, and strong end to end encrypted password management that can't be trivially decrypted from a private key stolen from memory. I had such things written off as being too paranoid when they are too easy -not- to set up.

I was not at all shocked by this headline.

I don't want to just single out Weebly here as I discuss these sorts of things with people at different companies all over the bay out of personal interest and anything harder than using something like lastpass to reach production systems is considered too much work. Honestly Google and Facebook are the only large companies I have seen deploy fairly decent security practices out of the dozens I have exposure to. I credit this to the fact the employ teams people who have the specific job of continually auditing and enforcing all available security tools on their systems and fostering a culture that security is everyone's job.

You will pay for security either way. Either up front paying teams of capable people, or in lost customer trust after the fact.

Security apathy in the valley is a cancer impacting companies of all sizes. Sure you can't make anything perfectly secure, but you can at least force your attacker to burn a 0day. Don't make it as easy as spoofing an email and getting an employee to click a malicious link.

If you have any sort if privileged access to PII data of your customers and are not even doing basics like using hardware tokens to gate your server and db access you are one keykogger or XSS away from a serious breach. If you know how to set such things up and still don't do it, you are additionally a terrible person.

At the very least the data required to readily plaintext the passwords is not public in this case which is a lot better off than companies using only simple hashing like md5. Some credit is due here for sure, but I can't help but strongly suspect the issues here and in now countless other orgs are a result of people having access to PII that don't really care about security or respect the privacy of the user data they are responsible for.

Re: Weebly hacked, 43M credentials stolen

#56

Obviously, this is a very disappointing situation for us -- we've always taken security very seriously since day 1, it's something that's been core to who we are from the beginning. That said, how you respond in this situation can be just as important, and so we are making sure to be incredibly proactive in addressing the situation & transparent in how we communicate the details with our customers. Our top and immedi…

Why does it take a few days to send an email saying "we got hacked, please change your passwords promptly".

I accept there are costs to jumping the gun and passing out incomplete information, but if I screw up I tell the affected parties that day. Not after a few days of planning how to manage the message.

Re: Weebly hacked, 43M credentials stolen

#57
post #56

Obviously, this is a very disappointing situation for us -- we've always taken security very seriously since day 1, it's something that's been core to who we are from the beginning. That said, how you respond in this situation can be just as important, and so we are making sure to be incredibly proactive in addressing the situation & transparent in how we communicate the details with our customers. Our top and immedi…

Why does it take a few days to send an email saying "we got hacked, please change your passwords promptly". I accept there are costs to jumping the gun and passing out incomplete information, but if I screw up I tell the affected parties that day. Not after a few days of planning how to manage the message.

For one, it's pretty challenging to send out 43M similarly-looking emails within 24h without tripping a whole bunch of anti-spam filters - even when you're using tailored services (that distribute over IPs with good rep, etc) like Amazon SES.

Re: Weebly hacked, 43M credentials stolen

#58
post #56

Earlier quoted context omitted.

Why does it take a few days to send an email saying "we got hacked, please change your passwords promptly". I accept there are costs to jumping the gun and passing out incomplete information, but if I screw up I tell the affected parties that day. Not after a few days of planning how to manage the message.

For one, it's pretty challenging to send out 43M similarly-looking emails within 24h without tripping a whole bunch of anti-spam filters - even when you're using tailored services (that distribute over IPs with good rep, etc) like Amazon SES.

No its not. they are called transactional emails and dont get blocked. Usually, you have a dedicated IP for that which guarantees fast delivery.

Re: Weebly hacked, 43M credentials stolen

#59

Earlier quoted context omitted.

For one, it's pretty challenging to send out 43M similarly-looking emails within 24h without tripping a whole bunch of anti-spam filters - even when you're using tailored services (that distribute over IPs with good rep, etc) like Amazon SES.

No its not. they are called transactional emails and dont get blocked. Usually, you have a dedicated IP for that which guarantees fast delivery.

This is silly – the entire process of "Oh, we got hacked. What did they access? Who's been compromised? Better write an email. Better find a channel to send that email, and wait for it to be sent" could very, very obviously take a couple of days. You are unfairly trivialising that.

Re: Weebly hacked, 43M credentials stolen

#60
post #40

Obviously, this is a very disappointing situation for us -- we've always taken security very seriously since day 1, it's something that's been core to who we are from the beginning. That said, how you respond in this situation can be just as important, and so we are making sure to be incredibly proactive in addressing the situation & transparent in how we communicate the details with our customers. Our top and immedi…

"we've always taken security very seriously since day 1" No you have not because then this would not have happened. The only one who should be able to query passwords from the database should be the DBA. Everyone else should only be able to validate against it. So either it's an inside job by your DBA, or you thought your users security was less important then avoiding the friction such high security standards would…

Shit happens. It's possible to take security seriously, but for something to be overlooked.
Post reply on HN