Live data from Hacker News

Weebly hacked, 43M credentials stolen

techcrunch.com

11–20 of 99 posts

Re: Weebly hacked, 43M credentials stolen

#12

And here I am, trying to apply for a Senior position there [1]. [1] https://news.ycombinator.com/item?id=12752642

Well, the breach was back in February this year, so I hope they have put better security in place since then. I've seen ads for Weebly all over the place, but never realised they had that many users. Good luck with your application... :)

accounts doesn't mean the same thing as current or active users. a company very likely doesn't delete accounts right away or at all, even if the service has been cancelled. for example, a few years ago microsoft's live ID system had well over a billion accounts. but MAU was only around 450M. and that is with culling / deleting accounts after a year if they were unused.

Re: Weebly hacked, 43M credentials stolen

#13
post #10

And here I am, trying to apply for a Senior position there [1]. [1] https://news.ycombinator.com/item?id=12752642

That job listing is just so sad. Who starts a senior android role's requirements with "git workflows"?

Organizations that heavily rely on git?

It might seem trivial to you, but the last thing I want in a CI/CD pipeline is senior engineers that don't understand the underlying technology.

Believe me, I've interviewed lots of people for senior positions that just haven't had to properly learn revision control. It's not a given.

Re: Weebly hacked, 43M credentials stolen

#14
Obviously, this is a very disappointing situation for us -- we've always taken security very seriously since day 1, it's something that's been core to who we are from the beginning.

That said, how you respond in this situation can be just as important, and so we are making sure to be incredibly proactive in addressing the situation & transparent in how we communicate the details with our customers. Our top and immediate concern has been our users and the safety of their accounts.

A few days ago we became aware that an unauthorized party obtained email addresses/usernames, last login IP addresses and bcrypt hashed passwords for a large number of customers (anyone who signed up prior to March 1 of this year).

At this point we do not have evidence of any customer website/account being improperly accessed. It's also worth noting that we do not store any full credit card numbers on Weebly servers, so any credit card information was not part of this incident.

We immediately starting working on taking steps to notify our customers, and were able to get this out in a matter of a few days. We're initiating password resets as of this morning, and we've also made several improvements to the application including new password complexity requirements and a new dashboard that gives customers an overview of recent log-in history of their Weebly account to track account activity. We also increased our bcrypt work factor from 8 to 10, and all passwords will be automatically upgraded as of the next time a user logs in.

We've hired an incident response firm who is working with our internal team to complete a full investigation. In the meantime, we're examining our stack top to bottom and taking many steps to enhance our network and application security. This is an area we take very seriously and we'll be putting in tremendous effort to ensure this doesn't happen again.

Re: Weebly hacked, 43M credentials stolen

#17
post #9

Look, this was 100% Russia. 17 government departments have certified this was Russia. This has Russian fingerprints all over it. Edit: man, this got unpopular. Curious if people dislike the sarcasm, or the sentiment of regular unfounded claims Russia is responsible-- at a gov't level, for major "hacking" transgressions.

I appreciate the sneaky attempt at political dialog after the past few days of in your face flame wars.

Re: Weebly hacked, 43M credentials stolen

#18

Obviously, this is a very disappointing situation for us -- we've always taken security very seriously since day 1, it's something that's been core to who we are from the beginning. That said, how you respond in this situation can be just as important, and so we are making sure to be incredibly proactive in addressing the situation & transparent in how we communicate the details with our customers. Our top and immedi…

Can't blame you for being hacked, but how can security be "core to who we are" if it took 6 months to discover a breach?

Re: Weebly hacked, 43M credentials stolen

#19
post #13
post #10

Earlier quoted context omitted.

That job listing is just so sad. Who starts a senior android role's requirements with "git workflows"?

Organizations that heavily rely on git? It might seem trivial to you, but the last thing I want in a CI/CD pipeline is senior engineers that don't understand the underlying technology. Believe me, I've interviewed lots of people for senior positions that just haven't had to properly learn revision control. It's not a given.

Perhaps I should've gone in more detail. I'm not upset about them wanting people who are proficient in git, I'm saddened that the job listing doesn't mention anything about what a Senior Android Developer does at Weebly.

The only Android related things on the job listing are proficiency with the IDE (Android Studio) and generic "frameworks".

I am an Android engineer, I clicked this job listing earlier today when it was on HN because I was interested in it. From the perspective of a listing that tries to get a good funnel of candidates coming in, it does nothing for me.

Would you apply to that job listing? I spend a lot of my day to day helping companies optimize their job listings, especially when they have high view numbers but low application click through rates, so this is a pet peeve.

Re: Weebly hacked, 43M credentials stolen

#20

Responsible disclosure and proper handling of passwords as well as not storing credit cards. Barring no breach at all, this is about as well as something like this can go.

Bonus points for mentioning the hashing algo and for not confusing "hashed" with "encrypted".
Post reply on HN