Live data from Hacker News

Zappos.com customer database compromised

zappos.com

21–30 of 93 posts

Re: Zappos.com customer database compromised

#21

Zappos developer here. I'll answer any questions that I legally can or help get customer problems passed onto people that can help.

Good job on the fast response! This is the first time I've heard about a security breach from a company before seeing the dump on pastebin

and to jump on social media to answer questions. the future of professionalism.

Re: Zappos.com customer database compromised

#22
post #17

+1 for not storing clear text passwords. I like the tone of the blog & how forthright they have been with dealing with the issue.

Agree. So many companies don't act like grown-ups and just try to cover up the problem.

Still, it's going to be pretty tough getting your average customer back who hears they've been "hacked" and are afraid to create a new password. Not to mention the average customer's password is probably the same password across facebook, gmail, etc.

Re: Zappos.com customer database compromised

#23
post #17

+1 for not storing clear text passwords. I like the tone of the blog & how forthright they have been with dealing with the issue.

Zappos is always a class act. I have about 3X the shoes I otherwise would have as a result of their customer service.

Re: Zappos.com customer database compromised

#24
post #15

Earlier quoted context omitted.

Hi. I'm customer outside of US and I received the email, went to site to reset my password and "We are so sorry – we are currently not accepting international traffic" - WTF? (sorry, but there is your logic?)

International traffic will be re-enabled in the near future.

Why was international traffic disabled?

Re: Zappos.com customer database compromised

#25
LastPass FTW! The attacker will reverse my password just to find a bunch of unusable bits :). What would be even cooler is an API on top of LastPass that sites like Zappos could hook into to force a behind-the-scenes change of passwords, similar to revoking a compromised certificate. Essentially, since there is some lead time after the breach is discovered and before the attacker manages to crack the long, random passwords, their efforts would be futile by the time they are done since all LastPass passwords would have already been changed.

Or we could just stop using passwords everywhere and not have this problem again. Anybody? Anybody?

Disclosure: I have no affiliation with LastPass beyond being a satisfied user.

Re: Zappos.com customer database compromised

#26

Earlier quoted context omitted.

International traffic will be re-enabled in the near future.

Why was international traffic disabled?

Just a precaution while we asses and deal with this. Zappos doesn't ship internationally so we hope this isn't affecting many customers. But to those that are, we apologize. As soon as we can we'll re-enable traffic from outside the US.

Re: Zappos.com customer database compromised

#29

Earlier quoted context omitted.

Why was international traffic disabled?

Just a precaution while we asses and deal with this. Zappos doesn't ship internationally so we hope this isn't affecting many customers. But to those that are, we apologize. As soon as we can we'll re-enable traffic from outside the US.

also.... "assess" not "asses"

Re: Zappos.com customer database compromised

#30

LastPass FTW! The attacker will reverse my password just to find a bunch of unusable bits :). What would be even cooler is an API on top of LastPass that sites like Zappos could hook into to force a behind-the-scenes change of passwords, similar to revoking a compromised certificate. Essentially, since there is some lead time after the breach is discovered and before the attacker manages to crack the long, random pas…

> What would be even cooler is an API on top of LastPass that sites like Zappos could hook into to force a behind-the-scenes change of passwords

How would Lastpass protect against an attacker masquerading as the third party website? (Especially considering this feature would be used when a website finds itself compromised.)

Post reply on HN