Zappos developer here. I'll answer any questions that I legally can or help get customer problems passed onto people that can help.
Zappos.com customer database compromised
31–40 of 93 posts
Re: Zappos.com customer database compromised
#32Good thing they didn't store passwords in clear-text!
Re: Zappos.com customer database compromised
#33Zappos developer here. I'll answer any questions that I legally can or help get customer problems passed onto people that can help.
As a developer who fears these kinds of attacks on my own sites, is there anything you are able/allowed to reveal regarding how the attack happened, how it was discovered, and/or how it could be prevented?
Re: Zappos.com customer database compromised
#34LastPass FTW! The attacker will reverse my password just to find a bunch of unusable bits :). What would be even cooler is an API on top of LastPass that sites like Zappos could hook into to force a behind-the-scenes change of passwords, similar to revoking a compromised certificate. Essentially, since there is some lead time after the breach is discovered and before the attacker manages to crack the long, random pas…
> What would be even cooler is an API on top of LastPass that sites like Zappos could hook into to force a behind-the-scenes change of passwords How would Lastpass protect against an attacker masquerading as the third party website? (Especially considering this feature would be used when a website finds itself compromised.)
Or, as I mentioned, let's do away with passwords. Anyone can have your public key so long as your private key stays private.
Re: Zappos.com customer database compromised
#35LastPass FTW! The attacker will reverse my password just to find a bunch of unusable bits :). What would be even cooler is an API on top of LastPass that sites like Zappos could hook into to force a behind-the-scenes change of passwords, similar to revoking a compromised certificate. Essentially, since there is some lead time after the breach is discovered and before the attacker manages to crack the long, random pas…
Re: Zappos.com customer database compromised
#36Zappos developer here. I'll answer any questions that I legally can or help get customer problems passed onto people that can help.
Re: Zappos.com customer database compromised
#37Earlier quoted context omitted.
Why was international traffic disabled?
Just a precaution while we asses and deal with this. Zappos doesn't ship internationally so we hope this isn't affecting many customers. But to those that are, we apologize. As soon as we can we'll re-enable traffic from outside the US.
Re: Zappos.com customer database compromised
#38It is probably worthwhile in these situations to provide basic implication info for laymen, i.e. implications of "your cryptographically scrambled password."
Re: Zappos.com customer database compromised
#39LastPass FTW! The attacker will reverse my password just to find a bunch of unusable bits :). What would be even cooler is an API on top of LastPass that sites like Zappos could hook into to force a behind-the-scenes change of passwords, similar to revoking a compromised certificate. Essentially, since there is some lead time after the breach is discovered and before the attacker manages to crack the long, random pas…
Re: Zappos.com customer database compromised
#40Zappos sister site 6pm.com was compromised, too.