Live data from Hacker News

Tuts+ Premium Account Security Compromised

notes.envato.com

1–10 of 70 posts

Re: Tuts+ Premium Account Security Compromised

#4
This is ridiculous. In the email I received from Envato it says the following:

"-- What To Do

(1) Update passwords on ANY service you use that uses the same password as you had on Tuts+ Premium.

(2) In particular you should consider your own email account, PayPal, Moneybookers, and other payment services. These are the most sensitive targets, and if you had the same password, you should consider this an urgent priority. If you can’t remember what your Tuts+ Premium password was, we encourage you to change passwords on all services you use.

(3) If you use the same password on any other Envato service such as the Envato Marketplaces, you should change your password there too."

You have to be kidding me? Do I really need to start using unique passwords on every site that I use? This just blows me away that one site messes up and then I have to spend hours of my time figuring out which passwords to change, update, etc. This just frustrates me so much. I'm also very surprised they put this in the blog post:

"As a company that teaches and preaches best practices, it’s deeply disappointing to me to not only have been the victim of a security attack, but to be running software that doesn’t follow those same best practices. This is a situation we will be working to address."

...Based on what has happened to LinkedIn and others, aren't they easily setting themselves up for a lawsuit by blatantly saying they did not follow best practices?

Ugh. I'm just very sick of this crap happening. /rant

Re: Tuts+ Premium Account Security Compromised

#6

This is ridiculous. In the email I received from Envato it says the following: "-- What To Do (1) Update passwords on ANY service you use that uses the same password as you had on Tuts+ Premium. (2) In particular you should consider your own email account, PayPal, Moneybookers, and other payment services. These are the most sensitive targets, and if you had the same password, you should consider this an urgent priori…

>You have to be kidding me? Do I really need to start using unique passwords on every site that I use?

Errr, ...yes!

Re: Tuts+ Premium Account Security Compromised

#7

This is ridiculous. In the email I received from Envato it says the following: "-- What To Do (1) Update passwords on ANY service you use that uses the same password as you had on Tuts+ Premium. (2) In particular you should consider your own email account, PayPal, Moneybookers, and other payment services. These are the most sensitive targets, and if you had the same password, you should consider this an urgent priori…

>You have to be kidding me? Do I really need to start using unique passwords on every site that I use? Errr, ...yes!

I already do to an extent but come on, you can't tell me you use a completely unique password for EACH of the HUNDREDS of sites that use passwords? That just seems ridiculous, or maybe it's just me...

Re: Tuts+ Premium Account Security Compromised

#8

I'll never visit an envato site again, let alone pay for any of their services. I can understand everyone gets hacked, but cleartext! wtf.

From the article:

Tuts+ Premium is the only Envato service that operates with cleartext passwords, and it was a known internal issue for us, with a plan currently in progress to upgrade away from the current plugin.

Re: Tuts+ Premium Account Security Compromised

#9
Still storing clear text passwords in 2012, how the hell do these people have businesses? I mean, I learned about this stuff at age 12 while learning PHP on my own, how hard can it be?

Getting hacked happens, even to the best but come on, how many times will we have to read blog posts like this one before people wake up? How hard can it be to hash and salt your passwords?

Glad I wasn't one of their customers (and never will be) but it's frustrating how we can't trust anyone with anything these days.

Re: Tuts+ Premium Account Security Compromised

#10

Earlier quoted context omitted.

>You have to be kidding me? Do I really need to start using unique passwords on every site that I use? Errr, ...yes!

I already do to an extent but come on, you can't tell me you use a completely unique password for EACH of the HUNDREDS of sites that use passwords? That just seems ridiculous, or maybe it's just me...

1Password (https://agilebits.com/onepassword) is your friend
Post reply on HN