Live data from Hacker News

Weebly hacked, 43M credentials stolen

techcrunch.com

61–70 of 99 posts

Re: Weebly hacked, 43M credentials stolen

#61
post #48
post #42

Earlier quoted context omitted.

Security is hard. It is very possible to take it seriously, do many things right (perhaps everything right, insofar as it's in your power), and still have your company end up in a headline like this. You can parameterize your queries until you're blue in the face, but that won't help you if the right employee is phished (for example). This is an inherently imperfect and chaotic world, and it's unrealistic to assume t…

I'm kind of tired of the "Security is hard, every one gets hacked eventually and we are just victims" mentality. This is not true. Why don't we see peoples banking information plastered over the web every month? That if something would be a high value target. No, it's always these Web 2.0 services this happens to. Now, you could argue that a small SAAS service can not possibly afford security as rigorous as a bank, b…

That's ridiculous; older businesses and government services are compromised all the time!

And let's not forget that there is a spectrum of value associated with information. On the one hand, I'd rather my bank details and payments weren't publicly released. On the other… IP address, bcrypted password and email address? Minimal relative value.

Re: Weebly hacked, 43M credentials stolen

#62
post #9

Look, this was 100% Russia. 17 government departments have certified this was Russia. This has Russian fingerprints all over it. Edit: man, this got unpopular. Curious if people dislike the sarcasm, or the sentiment of regular unfounded claims Russia is responsible-- at a gov't level, for major "hacking" transgressions.

I think it's maybe just that this isn't Reddit.

Re: Weebly hacked, 43M credentials stolen

#63
post #48
post #42

Earlier quoted context omitted.

Security is hard. It is very possible to take it seriously, do many things right (perhaps everything right, insofar as it's in your power), and still have your company end up in a headline like this. You can parameterize your queries until you're blue in the face, but that won't help you if the right employee is phished (for example). This is an inherently imperfect and chaotic world, and it's unrealistic to assume t…

I'm kind of tired of the "Security is hard, every one gets hacked eventually and we are just victims" mentality. This is not true. Why don't we see peoples banking information plastered over the web every month? That if something would be a high value target. No, it's always these Web 2.0 services this happens to. Now, you could argue that a small SAAS service can not possibly afford security as rigorous as a bank, b…

Swift hack.

Re: Weebly hacked, 43M credentials stolen

#64
post #52
post #48

Earlier quoted context omitted.

I'm kind of tired of the "Security is hard, every one gets hacked eventually and we are just victims" mentality. This is not true. Why don't we see peoples banking information plastered over the web every month? That if something would be a high value target. No, it's always these Web 2.0 services this happens to. Now, you could argue that a small SAAS service can not possibly afford security as rigorous as a bank, b…

Why don't we see peoples banking information plastered over the web every month? Banks get hacked. They just don't tell people about it. The difference is that banks aren't as transparent, not that they're more secure.

So true. They also have government agencies on their side. If you hack a bank, you're messing with money which suddenly involves a whole raft of governmental agencies.

Re: Weebly hacked, 43M credentials stolen

#65

Earlier quoted context omitted.

No its not. they are called transactional emails and dont get blocked. Usually, you have a dedicated IP for that which guarantees fast delivery.

This is silly – the entire process of "Oh, we got hacked. What did they access? Who's been compromised? Better write an email. Better find a channel to send that email, and wait for it to be sent" could very, very obviously take a couple of days. You are unfairly trivialising that.

My point was transactional emails does not hit any spam filters. And since email services tracks how many of emails were opened, i am pretty sure 'we have been hacked' will be opened quite often and will never be in spam folder.

Re: Weebly hacked, 43M credentials stolen

#66

Earlier quoted context omitted.

For one, it's pretty challenging to send out 43M similarly-looking emails within 24h without tripping a whole bunch of anti-spam filters - even when you're using tailored services (that distribute over IPs with good rep, etc) like Amazon SES.

No its not. they are called transactional emails and dont get blocked. Usually, you have a dedicated IP for that which guarantees fast delivery.

As I understand, transactional email is often triggered by a user itself (new account creation, forgot password, etc). By definition, those are sent spread out over time.

This is - at least from a spam filter's perspective - a huge email broadcast, more akin to a news letter mailing or a spam run.

And semantics aside, a lot of those 43M users will consider the email to be unsolicited (didn't remember they signed up, don't care about computer security, etc). They will happily report such an email as spam, adding to the training set.

Re: Weebly hacked, 43M credentials stolen

#67

Earlier quoted context omitted.

This is silly – the entire process of "Oh, we got hacked. What did they access? Who's been compromised? Better write an email. Better find a channel to send that email, and wait for it to be sent" could very, very obviously take a couple of days. You are unfairly trivialising that.

My point was transactional emails does not hit any spam filters. And since email services tracks how many of emails were opened, i am pretty sure 'we have been hacked' will be opened quite often and will never be in spam folder.

From the point of view of a spam filter, there isn't really any difference between a "transactional" (what a horrible name, but not your fault that the industry has adopted it) email and any other email.

"Transactional" emails simply have some distinctive elements, such as the first and last name of the customer, which make them less likely to be filtered out.

Re: Weebly hacked, 43M credentials stolen

#68

Earlier quoted context omitted.

My point was transactional emails does not hit any spam filters. And since email services tracks how many of emails were opened, i am pretty sure 'we have been hacked' will be opened quite often and will never be in spam folder.

From the point of view of a spam filter, there isn't really any difference between a "transactional" (what a horrible name, but not your fault that the industry has adopted it) email and any other email. "Transactional" emails simply have some distinctive elements, such as the first and last name of the customer, which make them less likely to be filtered out.

First & last name in email alone doesn't guarantee to hit inbox. Huge free email services use social 'signals' as open rates, 'this is spam', 'this is not spam' as well as IP reputation i mentioned earlier to determinate if email hit inbox.

So, there is obviously a difference in those metrics between simple notification 'your account have been hacked. change password' and 'hey, we haven't seen you for ages'. As email system notice high user involvement it will never ever block such emails. Actually, i think it will increase IP reputation.

Re: Weebly hacked, 43M credentials stolen

#69
post #35

Obviously, this is a very disappointing situation for us -- we've always taken security very seriously since day 1, it's something that's been core to who we are from the beginning. That said, how you respond in this situation can be just as important, and so we are making sure to be incredibly proactive in addressing the situation & transparent in how we communicate the details with our customers. Our top and immedi…

This title is incorrect. Credentials not stolen, usernames and hashed passwords stolen. That is not the same as having everyone's password. The title implies someone can easily log in to your account.

> That is not the same as having everyone's password

It is for everyone who used "weebly" or any of the top 100 most common passwords.

That could mean no less than 82% of users are at risk.

Re: Weebly hacked, 43M credentials stolen

#70

Obviously, this is a very disappointing situation for us -- we've always taken security very seriously since day 1, it's something that's been core to who we are from the beginning. That said, how you respond in this situation can be just as important, and so we are making sure to be incredibly proactive in addressing the situation & transparent in how we communicate the details with our customers. Our top and immedi…

Can't blame you for being hacked, but how can security be "core to who we are" if it took 6 months to discover a breach?

FYI: The median time to discover a breach is "infinite".

6 months is much better than the median :D

Post reply on HN