UserVoice Security Incident Notification
community.uservoice.com
UserVoice Security Incident Notification
1–10 of 14 posts
Re: UserVoice Security Incident Notification
#2Further information: https://status.uservoice.com/incidents/fb7ml8b3nphf
Re: UserVoice Security Incident Notification
#3Apparently I'm part of the "0.001%" that was affected in the breach.
Re: UserVoice Security Incident Notification
#4Just got an email from Uservoice about this. Apparently I'm part of the "0.001%" that was affected in the breach.
Re: UserVoice Security Incident Notification
#5Re: UserVoice Security Incident Notification
#6Earlier quoted context omitted.
Me too. Maybe 0.001% is not accurate.
seconded. I got one too. It seems unlikely we'd converge here if it was only a tiny fraction of users...
Re: UserVoice Security Incident Notification
#7There's a bit more info in this one about exactly what was compromised though. While I can understand the abundance of caution in resetting passwords despite only hashes and salts being lost, it is odd that they would "[presume] the attackers may be able to decrypt the passwords," assuming they're using strong encryption.
Re: UserVoice Security Incident Notification
#8Another thread on the incident report here: https://news.ycombinator.com/item?id=11664713 https://status.uservoice.com/incidents/fb7ml8b3nphf There's a bit more info in this one about exactly what was compromised though. While I can understand the abundance of caution in resetting passwords despite only hashes and salts being lost, it is odd that they would "[presume] the attackers may be able to decrypt the password…
Here's a good blog post how and why this is problematic: https://www.troyhunt.com/our-password-hashing-has-no-clothes...
Re: UserVoice Security Incident Notification
#9Another thread on the incident report here: https://news.ycombinator.com/item?id=11664713 https://status.uservoice.com/incidents/fb7ml8b3nphf There's a bit more info in this one about exactly what was compromised though. While I can understand the abundance of caution in resetting passwords despite only hashes and salts being lost, it is odd that they would "[presume] the attackers may be able to decrypt the password…
I wouldn't call resetting passwords an "abundance of caution" in this case. It's very likely that the attackers are able to retrieve passwords when they have the SHA1 hash and the salt (not exactly by decrypting though). Here's a good blog post how and why this is problematic: https://www.troyhunt.com/our-password-hashing-has-no-clothes...
Re: UserVoice Security Incident Notification
#10Just got an email from Uservoice about this. Apparently I'm part of the "0.001%" that was affected in the breach.