Live data from Hacker News

Zappos.com customer database compromised

zappos.com

51–60 of 93 posts

Re: Zappos.com customer database compromised

#51
post #43

Earlier quoted context omitted.

Agree. So many companies don't act like grown-ups and just try to cover up the problem. Still, it's going to be pretty tough getting your average customer back who hears they've been "hacked" and are afraid to create a new password. Not to mention the average customer's password is probably the same password across facebook, gmail, etc.

Absolutely. The biggest risk is the shared password part. It is surprising people still do it. I am surprised that some of the big eCommerce companies still mail back the password in clear text. Just plain stupid.

Sharing passwords will end when I don't have to remember one for every random website ever.

Re: Zappos.com customer database compromised

#52
post #17

+1 for not storing clear text passwords. I like the tone of the blog & how forthright they have been with dealing with the issue.

> +1 for not storing clear text passwords. That shouldn't need a +1.

It shouldn't, but it's shocking how many companies don't encrypt passwords before storing them in the db.

Re: Zappos.com customer database compromised

#54
post #17

+1 for not storing clear text passwords. I like the tone of the blog & how forthright they have been with dealing with the issue.

> +1 for not storing clear text passwords. That shouldn't need a +1.

Considering that 90% of success is showing up, and the next 9% is avoiding obvious failure paths, Zappos is doing pretty well here.

Lots of room for improvement above and beyond these two points, sure, but at least they're not falling victim to the classic blunders.

Disallowing international sales means they'll probably also avoid getting involved in a land war in Asia.

Now if I can just find my iocane powder...

Re: Zappos.com customer database compromised

#55

Zappos developer here. I'll answer any questions that I legally can or help get customer problems passed onto people that can help.

The email did not mention order history. Do you know if our personal order history was among the items compromised?

Not sure. Sorry.

Re: Zappos.com customer database compromised

#56

Earlier quoted context omitted.

Do you know what hash was used, if the passwords were salted and if so, if the salt is secure?

I'm not on the team that handles passwords so can't comment. Sorry.

Hmmm, please ask the team that handles passwords and let us know.

Re: Zappos.com customer database compromised

#57

Zappos developer here. I'll answer any questions that I legally can or help get customer problems passed onto people that can help.

Good job on not storing or sending clear text passwords. However, as others have indicated, we would like to know more about the hashing method used.

As a side note, I was horrified to discover that Hertz sends passwords (as part of password recovery) in the clear. For those using Hertz, you should take the appropriate precautions.

Re: Zappos.com customer database compromised

#58

Earlier quoted context omitted.

FFS! It wasn't compromised, not remotely. The incident last year is what convinced me I could trust last pass.

Well they said that their database was compromised and they were not sure what was accessed. So I stopped using them after that incident. It was a while ago I don't remember the particulars, but I do remember they said they were not sure if someone stole everyones password so everyone should change their master password to be safe. So I deleted my account to be safer.

For that reason, I find the 1Password model more suited to my tastes. Using Dropbox to sync, it works just as nicely and I'm not beholden to a third party central database (LastPass).

Re: Zappos.com customer database compromised

#59
post #3

Page gives me : "We are so sorry – we are currently not accepting international traffic. If you have any questions please email us at help@zappos.com" Anyone could paste/screenshot/... what there is to see ?

You can check the URL http://viewtext.org/article?url=http://www.zappos.com/passwo... in case content changes/updates in that page.

Re: Zappos.com customer database compromised

#60

Earlier quoted context omitted.

FFS! It wasn't compromised, not remotely. The incident last year is what convinced me I could trust last pass.

Well they said that their database was compromised and they were not sure what was accessed. So I stopped using them after that incident. It was a while ago I don't remember the particulars, but I do remember they said they were not sure if someone stole everyones password so everyone should change their master password to be safe. So I deleted my account to be safer.

  Well they said that their database was compromised
No they didn't.

  I don't remember the particulars
Then why do you make such explicit claims about what happened? They spotted a traffic anomaly on their network and went into complete paranoid mode. It is completely unknown, even to them, whether someone unauthorized accessed their database or whether they just couldn't account for some traffic on their internal network.

I don't know anyone else that monitors the traffic on their network to detect unauthorized access and I know many companies that don't. That's already a huge plus and it makes me trust them with security in general all the more.

Post reply on HN