Live data from Hacker News

Notice of Data Breach

content.myfitnesspal.com

111–120 of 160 posts

Re: Notice of Data Breach

#111
post #61
post #6

Earlier quoted context omitted.

The article is likely to be repeating what was in a press release or statement from the company. It's there to bound above the impact of the breach.

This is the statement from the company.

I'm reasonably certain that the link was changed from an article about the breach to the company's post.

I'm not completely certain, but that was my impression at the time I wrote the post.

Re: Notice of Data Breach

#112

That's unfortunate. At least we didn't get the stereotypical "your passwords are hashed, so nothing to worry about" one liner I've been reading from a lot of companies during disclosures. All they said here is that the passwords are hashed and with a reasonably secure method -- bcrypt (although without knowing work-factor and percentage of passwords, it is hard to know just how strongly). It has become pretty difficu…

I initially really liked the idea of a hardware pepper, however, if that ever goes defunct or you need to spread the load over multiple machines the password now is invalid and the user is stranded and forced to recover their account via email or some other means. I think there are definitely areas where a hardware pepper would be awesome though!

Re: Notice of Data Breach

#114
post #88

Earlier quoted context omitted.

I'm 34, and I don't care. I also tend to walk around naked, without much care if someone spots me through a window - though I try not to obviously flash the neighbors through the kitchen window, which is the only real direct easy sightline. I used to be really insecure about being nude - I requested, and got permission to, change somewhere besides the locker room in middle school - but I think I don't care anymore, a…

Same here - my new roommate is constantly closing the blinds at night because he doesn't want the old lady in the building across from us see us sit around and play video games, I guess. I remember refusing to shower after the gym because I didn't want people to see my wiener. I think it changed when my friend's bathroom's door lock was broken. His brother was about to go in and was the kind of guy that liked to anno…

So you became less embarrassed at his easy dismissal of something that you were afraid of?

Re: Notice of Data Breach

#115
The MyFitnessPal database has been compromised for years. I register with a unique email address for every website and app that I use so that I can tell when somebody's database gets compromised or they sell my data. I started getting an influx of spam to my MyFitnessPal email years ago. I told them about it at the time but they didn't care.

Re: Notice of Data Breach

#117
post #45

Somebody is about to come across 250 pictures of me in my boxers standing in front of a dirty mirror with my belly popping out. I only hope they don't judge me for the size of my belly not really changing over those 250 days...

They won't judge you, but your health insurance rate might go up for unspecific reasons.

See, most comments here are a bit on the side of So what? Who cares?, but fitness data is health data and health data is considered extra sensitive. And I guess rightly so, because of this: http://www.tearsheet.co/data/allstate-is-watching-you-how-th...

My prediction is that most health-related apps will be regulated in the near future. It's already happening with the GDPR to some extend, which classifies health data as sensitive requiring extra protection (and extra consent from users).

A breach like that (if fitness data was leaked) could result in heavy fines under GDPR (or something like the Medical Device Regulation, which is starting to extend to medical/health apps), if it becomes clear that the company didn't take security seriously enough.

Re: Notice of Data Breach

#118
post #88

Earlier quoted context omitted.

I'm 34, and I don't care. I also tend to walk around naked, without much care if someone spots me through a window - though I try not to obviously flash the neighbors through the kitchen window, which is the only real direct easy sightline. I used to be really insecure about being nude - I requested, and got permission to, change somewhere besides the locker room in middle school - but I think I don't care anymore, a…

Same here - my new roommate is constantly closing the blinds at night because he doesn't want the old lady in the building across from us see us sit around and play video games, I guess. I remember refusing to shower after the gym because I didn't want people to see my wiener. I think it changed when my friend's bathroom's door lock was broken. His brother was about to go in and was the kind of guy that liked to anno…

Back in Roman times you'd go to the communal bathroom with your friends, sitting side by side and having a chat while doing your business. They didn't even bother with cubicles back then.

Re: Notice of Data Breach

#119
post #64

That's unfortunate. At least we didn't get the stereotypical "your passwords are hashed, so nothing to worry about" one liner I've been reading from a lot of companies during disclosures. All they said here is that the passwords are hashed and with a reasonably secure method -- bcrypt (although without knowing work-factor and percentage of passwords, it is hard to know just how strongly). It has become pretty difficu…

”All they said here is that the passwords are hashed and with a reasonably secure method -- bcrypt” The “majority” of the passwords was hashed with bcrypt. https://content.myfitnesspal.com/security-information/FAQ.ht... : ”The MyFitnessPal account information that was not protected using bcrypt was protected with SHA-1, a 160-bit hashing function.” That majority could be as low as 50.0000001%. I also couldn’t find ho…

They probably do know, and practically speaking I would guess that those accounts using an older hash are those which nobody has logged into since they switched to bcrypt. Yeah, we don’t know for certain, but it’s a reasonable assumption.

Re: Notice of Data Breach

#120

Mods, there's a better article on Reuters: https://www.reuters.com/article/us-under-armour-databreach/u...

Better in what way? This is notable because it is the official word of the company, so we can discuss how forthcoming they are.
Post reply on HN