I didn't get this notice so that means my information wasn't compromised? Wouldn't bet on it.
Zappos.com customer database compromised
41–50 of 93 posts
Re: Zappos.com customer database compromised
#42LastPass FTW! The attacker will reverse my password just to find a bunch of unusable bits :). What would be even cooler is an API on top of LastPass that sites like Zappos could hook into to force a behind-the-scenes change of passwords, similar to revoking a compromised certificate. Essentially, since there is some lead time after the breach is discovered and before the attacker manages to crack the long, random pas…
Except when LastPass was compromised last year...
Re: Zappos.com customer database compromised
#43+1 for not storing clear text passwords. I like the tone of the blog & how forthright they have been with dealing with the issue.
Agree. So many companies don't act like grown-ups and just try to cover up the problem. Still, it's going to be pretty tough getting your average customer back who hears they've been "hacked" and are afraid to create a new password. Not to mention the average customer's password is probably the same password across facebook, gmail, etc.
I am surprised that some of the big eCommerce companies still mail back the password in clear text. Just plain stupid.
Re: Zappos.com customer database compromised
#44Zappos developer here. I'll answer any questions that I legally can or help get customer problems passed onto people that can help.
Re: Zappos.com customer database compromised
#45+1 for not storing clear text passwords. I like the tone of the blog & how forthright they have been with dealing with the issue.
That shouldn't need a +1.
Re: Zappos.com customer database compromised
#46Zappos developer here. I'll answer any questions that I legally can or help get customer problems passed onto people that can help.
Can you provide any further information that would be of interest to HN readers? If not, why do you bother posting this?
Re: Zappos.com customer database compromised
#47Earlier quoted context omitted.
Except when LastPass was compromised last year...
FFS! It wasn't compromised, not remotely. The incident last year is what convinced me I could trust last pass.
So I stopped using them after that incident.
It was a while ago I don't remember the particulars, but I do remember they said they were not sure if someone stole everyones password so everyone should change their master password to be safe. So I deleted my account to be safer.
Re: Zappos.com customer database compromised
#48Re: Zappos.com customer database compromised
#49Zappos developer here. I'll answer any questions that I legally can or help get customer problems passed onto people that can help.
Do you know what hash was used, if the passwords were salted and if so, if the salt is secure?
Re: Zappos.com customer database compromised
#50Earlier quoted context omitted.
Just a precaution while we asses and deal with this. Zappos doesn't ship internationally so we hope this isn't affecting many customers. But to those that are, we apologize. As soon as we can we'll re-enable traffic from outside the US.
I for one would love Zappos to ship internationally, and your owners at Amazon already do. I know you can't comment, but please do what you can to push for selling to the other 6.7 billion of us.