Live data from Hacker News

Zappos.com customer database compromised

zappos.com

11–20 of 93 posts

Re: Zappos.com customer database compromised

#15

Zappos developer here. I'll answer any questions that I legally can or help get customer problems passed onto people that can help.

Hi. I'm customer outside of US and I received the email, went to site to reset my password and "We are so sorry – we are currently not accepting international traffic" - WTF? (sorry, but there is your logic?)

Re: Zappos.com customer database compromised

#16
post #14

Zappos developer here. I'll answer any questions that I legally can or help get customer problems passed onto people that can help.

Was the password hash generated using bcrypt?

Plaintext passwords never touch our database. Expiring everyone's passwords was a security precaution given the fact that our non financial customer data was compromised in the first place. I can't comment on what lib or algorithm we use to encrypt our passwords since I don't work on that team.

Re: Zappos.com customer database compromised

#18
post #15

Zappos developer here. I'll answer any questions that I legally can or help get customer problems passed onto people that can help.

Hi. I'm customer outside of US and I received the email, went to site to reset my password and "We are so sorry – we are currently not accepting international traffic" - WTF? (sorry, but there is your logic?)

International traffic will be re-enabled in the near future.

Re: Zappos.com customer database compromised

#19

Zappos developer here. I'll answer any questions that I legally can or help get customer problems passed onto people that can help.

Good job on the fast response! This is the first time I've heard about a security breach from a company before seeing the dump on pastebin

Re: Zappos.com customer database compromised

#20
post #7

I've been having issues with Zappos for a couple days. I called up support yesterday and they said they were "upgrading the website and had bugs they were trying to get fixed." Not sure if this is related or just a coincidence.

Probably coincidence. Companies that expect a lot of Christmas traffic minimize changes from Thanksgiving to Christmas, and web retail gets more traffic during business hours in America, so I expect that this weekend and last weekend saw a lot of code deployments, and so things are more likely to be broken specifically right now than pretty much any other time of the year.
Post reply on HN