Live data from Hacker News

Tuts+ Premium Account Security Compromised

notes.envato.com

11–20 of 70 posts

Re: Tuts+ Premium Account Security Compromised

#11

I'll never visit an envato site again, let alone pay for any of their services. I can understand everyone gets hacked, but cleartext! wtf.

From the article: Tuts+ Premium is the only Envato service that operates with cleartext passwords, and it was a known internal issue for us, with a plan currently in progress to upgrade away from the current plugin.

Still, this not being priority number one for them (before even making this service public!) means I will never do business with them. It says a lot about how they value their customers.

Re: Tuts+ Premium Account Security Compromised

#12

I'll never visit an envato site again, let alone pay for any of their services. I can understand everyone gets hacked, but cleartext! wtf.

From the article: Tuts+ Premium is the only Envato service that operates with cleartext passwords, and it was a known internal issue for us, with a plan currently in progress to upgrade away from the current plugin.

"plan currently in progress" - A bit late, don't you think?

Re: Tuts+ Premium Account Security Compromised

#13

I'll never visit an envato site again, let alone pay for any of their services. I can understand everyone gets hacked, but cleartext! wtf.

From the article: Tuts+ Premium is the only Envato service that operates with cleartext passwords, and it was a known internal issue for us, with a plan currently in progress to upgrade away from the current plugin.

The sad thing is, it's completely trivial and non-disruptive to switch to from a cleartext database to a hashed+salted one.

Re: Tuts+ Premium Account Security Compromised

#14

Earlier quoted context omitted.

>You have to be kidding me? Do I really need to start using unique passwords on every site that I use? Errr, ...yes!

I already do to an extent but come on, you can't tell me you use a completely unique password for EACH of the HUNDREDS of sites that use passwords? That just seems ridiculous, or maybe it's just me...

There are quite a few ways to automate that. Lastpass, Keepass, KeepassX, 1Password, ...

Re: Tuts+ Premium Account Security Compromised

#15

Earlier quoted context omitted.

>You have to be kidding me? Do I really need to start using unique passwords on every site that I use? Errr, ...yes!

I already do to an extent but come on, you can't tell me you use a completely unique password for EACH of the HUNDREDS of sites that use passwords? That just seems ridiculous, or maybe it's just me...

Salt the password with characters from the url. Maybe your password is P4ssw0rd, so your HN password is Py4csosw0rd. I've been using this scheme for years, works great!

Re: Tuts+ Premium Account Security Compromised

#16

Earlier quoted context omitted.

>You have to be kidding me? Do I really need to start using unique passwords on every site that I use? Errr, ...yes!

I already do to an extent but come on, you can't tell me you use a completely unique password for EACH of the HUNDREDS of sites that use passwords? That just seems ridiculous, or maybe it's just me...

Get LastPass (it's free and totally safe since it's client-side encrypted), but if you don't want that you can just use SuperGenPass.

http://lastpass.com/ http://supergenpass.com/

Re: Tuts+ Premium Account Security Compromised

#20
We should start a new award for web sites with crap password security. Let's name it after Robert Morris (Senior) who essentially inventing password hashing.

A Morris Award would be a bit like a Darwin Award for people who've failed to learn anything about password security and in doing so have been exposed.

Recent Morris Award winners: LinkedIn, last.fm, eHarmony, Tuts+, ...

Post reply on HN