Live data from Hacker News

Data Breach Reveals 100k IEEE.org Members' Plaintext Passwords

ieeelog.com

31–40 of 138 posts

Re: Data Breach Reveals 100k IEEE.org Members' Plaintext Passwords

#31

Earlier quoted context omitted.

> You seem unfamiliar with the specific case. It wasn't the user database that was compromised. Which isn't really relevant. A password leak is a password leak, whatever its source is. > It was plainly obvious to any user of IEEE that they were storing your password in clear text And nobody every took issue with that? > And the mail would have live hyperlinks to access your account, which generally means GET requests…

Which isn't really relevant. Then please don't bring it up, i.e., say things like "if the user database is compromised, you can safely assume all of the site is". And nobody every took issue with that? Maybe they did, maybe they didn't. IEEE members are probably slightly more informed than your random AOL user. There are plenty of mail managers out there that mail you your password automatically every month.

A password leak is one of several ways in which a user database can be considered compromised. Beside the fact that every leaked user had access to every other leaked user's database record, which is a huge breach in itself, how do you know that no administrative credentials were leaked?

The user database was compromised in a major way, even if nobody got root.

Re: Data Breach Reveals 100k IEEE.org Members' Plaintext Passwords

#32
post #24
post #15

Earlier quoted context omitted.

You realize that people use the same password on multiple sites? given that people signed up using corporate email addresses, this could be used to hack internal networks of companies.

Using a corporate password for any other site is a firable misconduct.

You'd better be prepared to fire half the corporate world. And then do it again the next month. Because people will never stop doing this.

Re: Data Breach Reveals 100k IEEE.org Members' Plaintext Passwords

#33
post #28

Earlier quoted context omitted.

And... how could they know exactly?

web browsers are doing this for malware / fraud sites. see other comments on parent for citations.

That's reactive, for passwords in cleartext it's not very useful: by the time you get the news, the damage has been done already.

At best it tells you to change you passwords before the site itself tells you.

Re: Data Breach Reveals 100k IEEE.org Members' Plaintext Passwords

#34

"For a few days I was uncertain what to do with the information and the data." what? how is telling the ieee not completely the right thing to do, as soon as possible? (this is the source - http://www.dragusin.ro/ ; seems like an academic rather than a hacker. still, that seems like an odd thing to be uncertain about).

People have been threatened with legal action for discovering vulnerabilities before.

Re: Data Breach Reveals 100k IEEE.org Members' Plaintext Passwords

#35

What concerns me is that I have to renew my IEEE membership very soon, and if they have the wrong logging enabled how can I be assured that they aren't logging me CC details? I've seen it happen in one of my client's production systems, but at least they never put the log files up on a public FTP site. I checked the ieee.org website and nothing about this has been mentioned yet. Not even a "We're investigating the al…

If they're taking credit card information, they have to be PCI compliant. An auditor should notice pretty quickly if they're logging CC transactions. Not to say it can't happen and you're absolutely right to be suspicious, but if they are there will be repercussions.

Re: Data Breach Reveals 100k IEEE.org Members' Plaintext Passwords

#36

"For a few days I was uncertain what to do with the information and the data." what? how is telling the ieee not completely the right thing to do, as soon as possible? (this is the source - http://www.dragusin.ro/ ; seems like an academic rather than a hacker. still, that seems like an odd thing to be uncertain about).

People have been threatened with legal action for discovering vulnerabilities before.

[deleted]

Re: Data Breach Reveals 100k IEEE.org Members' Plaintext Passwords

#37
The browser data graph is actually quite interesting. I'm guessing that the slight windows where Firefox edges out Chrome for the top spot corresponds to European users waking up a few hours before North American users.

And of course, we now have evidence that educated users practice superior computer security; compare "1234" (the most popular password among the general populace) to "123456" (the most popular password among IEEE members). That's at least 50% more secure!

Re: Data Breach Reveals 100k IEEE.org Members' Plaintext Passwords

#38

I understand that many organizations, even fairly large/respected organizations like the ieee work on a limited "IT" budget, but we've reached the point in our society where it's reasonable to expect these guys to do the bare minimum. Just like everyone working in a restaurant needs to know the basics of food handling in order to avoid getting people sick, everyone who's operating a website with logins has a responsi…

I think at this point, I think the software community at large is responsible for not solving this problem once and for all. It's clearly preferable to trust each OS/Browser vendor rather than trust each and every web site.

Re: Data Breach Reveals 100k IEEE.org Members' Plaintext Passwords

#39

Earlier quoted context omitted.

Because it's not that important. In most cases what someone could do with my account is to view articles I have paid for, either piecemeal or as a subscription. It's much more in their interest than my interest to keep that private. They've sent me my cleartext password several times before I finally wrote it down in a place I could keep it safe, and I was always thankful. Also, the default password is something very…

> Because it's not that important. yes, it very much is. > In most cases what someone could do with my account is to view articles I have paid for That's not the problem with leaking plaintext accounts. If the user database is compromised, you can safely assume all of the site is and the site's data is leaked as well (or would be if anyone gave a fuck). The problem of cleatext (or easy to reverse) password databases…

"Most users reuse the same password again and again and again. Having their password leaked"

Yes it is generally accepted that many users reuse the same password on different sites. But that is a separate issue and really has nothing to do with what has happened here or why proper security should obviously be followed. Not disagreeing with that.

But I disagree with the fact that since the user does the wrong thing many times, it is the responsibility of the site operator to assume that in the building of their product (in the way this issue is being discussed). If it is, where are all the warnings on any site saying "make sure not to give us a password you use anywhere else". (I've rarely seen any warning like that, have you?)

Of course this is all a matter of degree. There are many cases where you have to prevent users from their folly. True. My question is simply while there are many ways that sites try to enforce correct password behavior, I've yet to see (meaning if it exists I haven't really noticed it whereas I've notice other password thoughts) one that informs people to make sure the password they use is unique to their site AND the other typical restrictions (length, mixed case etc.)

Re: Data Breach Reveals 100k IEEE.org Members' Plaintext Passwords

#40

I understand that many organizations, even fairly large/respected organizations like the ieee work on a limited "IT" budget, but we've reached the point in our society where it's reasonable to expect these guys to do the bare minimum. Just like everyone working in a restaurant needs to know the basics of food handling in order to avoid getting people sick, everyone who's operating a website with logins has a responsi…

d) To not keep 100K users' passwords in a public FTP server :)
Post reply on HN