Live data from Hacker News

StockX was hacked, exposing millions of customers’ data

techcrunch.com

41–50 of 108 posts

Re: StockX was hacked, exposing millions of customers’ data

#41
post #22

Earlier quoted context omitted.

Look up benchmarks for cracking MD5 hashes. You can crack an MD5 hash of an average length password (and StockX only requires an 8 character password), even with a salt , within seconds with a single consumer grade GPU. A hacker group with any serious setup for hash cracking has almost certainly already cracked most, if not all, of these hashes.

Unless you presume that you know the salt your comment is utter nonsense. The fact that the article says “believed to be” strongly suggests that things are not as simple as they’re “believed to be”, because if the passwords were easy to crack that’d be trivial to prove.

If the passwords have leaked it's safe to assume the salts have, typically they're stored side by side.

Re: StockX was hacked, exposing millions of customers’ data

#42
post #9

Earlier quoted context omitted.

Sounds alarming, but not true. If you don’t know the salt, you are not cracking an MD5 password on basic hardware . You are probably not cracking the password in any reasonable time, period. And when you have a unique salt per user, that’s basically game over.

In 2012: https://www.zdnet.com/article/25-gpus-devour-password-hashes... That's 7.2 billion hashes per second per single Radeon GPU for md5. For 8 character password with numbers and letters that's 8.5 hours max and 4.25h on average.. The numbers only got better since then, I expect it's at least halved for this year's hardware. (edit: 1080ti does 32GHps, so yeah... make that 1h on average https://www.servethehome.co…

Those time periods also assume that you're just blindly cracking every possible 8-character combination, but you don't have to do that. Running your cracker against a password list like rockyou will probably get you 90%+ of passwords cracked in less than one second per hash with that same hardware.

Re: StockX was hacked, exposing millions of customers’ data

#43
post #35

Earlier quoted context omitted.

Well the reporting of the breaches is more strange than the fact they happened. A platform like StockX should be a continual breach, because the information will let you make advantageous trades and time series against the customers. Its pretty dumb to even announce a past tense on this as if it was a single event.

a time series of... shoes?

Yes of shoes, who buys who is trying to buy, position sizes, limit orders placed by user

Re: StockX was hacked, exposing millions of customers’ data

#44
I got an email 3 days ago asking me to reset my password due to "system updates" and initially assumed it was just a phishing email. Since gmail is pretty aggressive about filtering those I looked into it more and realized it was genuine which made me even more confused because I couldn't imagine what sort of "system updates" they could've done that would require a password reset for all users. I kind of assumed they were covering up a breach so I wasn't at all surprised to see this headline. How scummy.

Re: StockX was hacked, exposing millions of customers’ data

#45
post #20

I very nearly worked there in their engineering department, but once I got through the initial HR interview into the technical stuff, there were so many red flags that I got outta there as soon as I could. A few higher level people who were all let go with me ended up going there, and having met up with them a few times, I've heard some absolute horror stories about everything ranging from dev workload, to security,…

I had a similar experience, but I made the mistake of taking the job. I spent several months in denial about how smart people who act so... not smart. At one point, I asked the CTO for guidance on how to work with the team architect whose feelings I kept hurting. For example, I wrote a constructor for a class, and the architect asked me what "def initialize" was for, and got upset when I asked if they knew how OOP in…

I used to work closely with Quicken Loans and other FoCs and can attest that this behavior is commonplace. There is this strange culture within the Family of Companies where non-tech leaders think that tenured Quicken engineers and tech people are these sort of super-geniuses. Many years back I was a part of a company in the Quicken led start-up space. We were often "encouraged" to meet with Quicken or FatHead senior engineers for advice. One time I reluctantly agreed and met with "the best programmer in Michigan" who's first piece of advice was:

"Delete your app and start over. Ruby on Rails is trash. Real programmers use C#. With C# you can create libraries that you can reuse across all your apps."

Re: StockX was hacked, exposing millions of customers’ data

#46
I expect a lot of downvotes for this post from people who have not had experience working with people in fashion.

Investors should be weary of people from the fashion industry. I say this as someone who has both a computer science degree and a fashion design degree, and 90% of my friends were in the fashion industry at some point. Coming from tech, you'll find people here are much flakier and just unreliable. In the NYC fashion scene in particular, people have huge egos and they don't always act out of pragmatism or logic. The tendency to keep up appearances manifests itself in many ways. Look at Barney's, it appears great on the outside, but recently considered bankruptcy before receiving a capital injection.

Recently, I went into one of the top streetwear brands in the world, a staff member tried to start a fist fight with me after a piece of paper fell out of a hat, and I refused to pick it up and told them to screw off after the guy tried to disrespect me in front of my girlfriend. I've never been to a retail store where a staff member told a customer "meet me outside p___y", but that is the nature of streetwear culture in NYC. In case you aren't aware, these streetwear stores in NYC have BOUNCERS. Let that soak in. They're just accustomed to bullying customers because people are so desperate to buy clothing that they are willing to put up with the nonsense. They particularly like to single out mainland Chinese who don't realize (or maybe don't care) when these staff are disrespecting them, and, since I'm Asian, the guy who picked the fight thought I would not stand up for myself. If you want more examples of ridiculousness of streetwear, search "ym bape compilation" on YouTube. This dude loves the clothing brand called "Bape" and goes around and assaults everyone he sees wearing the brand Supreme.

There's economic demand and money to be made here, but just know the demographic you're dealing with. The customers and investees are of the same thread. I'm looking to start a fashion tech company myself, and aren't intimidated by potential competitors considering how disjoint these two worlds are, both network-wise and culturally. The typical engineer won't see the value of all this vain-ness, and people in fashion business aren't always the most reasonable people. A UX designer I work with recently told me a story of how they were redesigning a website for a top fashion brand, and the brand requested they make the shopping experience as UN-usable as possible and difficult for people to actually make a purchase (but it works I guess). At any rate Investors, find a leader who can bridge that gap while still being able to attract engineering talent.

Don't get me wrong, you can fund leaders in the FashionTech who are completely unreasonable, and even incompetent, but the company will still do well since product-market fit and demand will outstrip all other factors, until something like this happens. One of my professors owns a set of retail stores in NYC that was acquired by one of the largest clothing manufacturers in the US, but they did not know a single thing about accounting, business operations, engineering, and non-artistic things. Super unreliable, super unprofessional professor but they had a really good intuition for branding.

Luxury brands, corporations (Adidas, Nike), and the LVMH conglomerate are a slightly different story

Re: StockX was hacked, exposing millions of customers’ data

#47
post #20

I very nearly worked there in their engineering department, but once I got through the initial HR interview into the technical stuff, there were so many red flags that I got outta there as soon as I could. A few higher level people who were all let go with me ended up going there, and having met up with them a few times, I've heard some absolute horror stories about everything ranging from dev workload, to security,…

I had a similar experience, but I made the mistake of taking the job. I spent several months in denial about how smart people who act so... not smart. At one point, I asked the CTO for guidance on how to work with the team architect whose feelings I kept hurting. For example, I wrote a constructor for a class, and the architect asked me what "def initialize" was for, and got upset when I asked if they knew how OOP in…

Sounds like you dodged a bullet.

Did you end up working at another Fashion-Tech company? I'm curious how much of this is characteristic of Fashion-Tech industry in general.

Re: StockX was hacked, exposing millions of customers’ data

#48
post #23

Earlier quoted context omitted.

Show me the benchmarks.

https://gist.github.com/epixoip/a83d38f412b4737e99bbef804a27... Looking at phpass (one of the md5 algorithms), a high-end GPU can do 7M hashes per sec.

nowhere in these benchmarks anyone said the MD5 were salted. am i reading it wrong?

Re: StockX was hacked, exposing millions of customers’ data

#49
post #45

Earlier quoted context omitted.

I had a similar experience, but I made the mistake of taking the job. I spent several months in denial about how smart people who act so... not smart. At one point, I asked the CTO for guidance on how to work with the team architect whose feelings I kept hurting. For example, I wrote a constructor for a class, and the architect asked me what "def initialize" was for, and got upset when I asked if they knew how OOP in…

I used to work closely with Quicken Loans and other FoCs and can attest that this behavior is commonplace. There is this strange culture within the Family of Companies where non-tech leaders think that tenured Quicken engineers and tech people are these sort of super-geniuses. Many years back I was a part of a company in the Quicken led start-up space. We were often "encouraged" to meet with Quicken or FatHead senior…

Wow that is so sad/hilarious.

Re: StockX was hacked, exposing millions of customers’ data

#50
post #8

Earlier quoted context omitted.

We need to start charging companies with criminal negligence if they are not using secure password hashing algorithms. People reuse passwords and this leak puts other companies at risk.

That would be a civil case prosecuted by the other companies, not a criminal case.

It should be criminal.
Post reply on HN