Live data from Hacker News

Tuts+ Premium Account Security Compromised

notes.envato.com

61–70 of 70 posts

Re: Tuts+ Premium Account Security Compromised

#61

Earlier quoted context omitted.

>You have to be kidding me? Do I really need to start using unique passwords on every site that I use? Errr, ...yes!

I already do to an extent but come on, you can't tell me you use a completely unique password for EACH of the HUNDREDS of sites that use passwords? That just seems ridiculous, or maybe it's just me...

I do just that.

Between work and personal, roughly 130 password/account pairs.

I may be missing a few. I also don't believe in gratuitously creating accounts simply to make use of some site (information has value, including and often particularly, identifying information). I'll make use of BugMeNot and/or create throwaway accounts using Mailinator for one-offs.

Re: Tuts+ Premium Account Security Compromised

#63

Earlier quoted context omitted.

The sad thing is, it's completely trivial and non-disruptive to switch to from a cleartext database to a hashed+salted one.

Not if you depend on a software that requires plaintext passwords (as they obviously do). Whether it's a wise choice using such a software is open to discussion though.

Sometimes business/marketing managers and IT security managers disagree. Looks as though the business guys trumped the security guys on this one. That happens a lot in the real world.

Re: Tuts+ Premium Account Security Compromised

#64

I'll never visit an envato site again, let alone pay for any of their services. I can understand everyone gets hacked, but cleartext! wtf.

From the article: Tuts+ Premium is the only Envato service that operates with cleartext passwords, and it was a known internal issue for us, with a plan currently in progress to upgrade away from the current plugin.

It's not like it's hard for a site which offers programming tutorials to just change the password storage method.

Re: Tuts+ Premium Account Security Compromised

#65
post #63

Earlier quoted context omitted.

Not if you depend on a software that requires plaintext passwords (as they obviously do). Whether it's a wise choice using such a software is open to discussion though.

Sometimes business/marketing managers and IT security managers disagree. Looks as though the business guys trumped the security guys on this one. That happens a lot in the real world.

Since there's no such thing as absolute security, all security effort is a balance between an assumed threat and the havoc it could create and costs. So it's always business vs. security. I'm a bit on the fence here and I guess I'd have taken another route but well, if the product was not viable without the plugin... Who knows.

Given that: My remark was directed at the blank statement that it's always easy to switch. It obviously is not in that case, the change was on the agenda [1], so it's a bit tough that this happened in the meantime.

[1] At least according to the official statement. I don't have any reason to believe otherwise.

Re: Tuts+ Premium Account Security Compromised

#67

My email to Envato: I seriously can't understand how Envato found it responsible to even implement something that saves plaintext passwords. You must of known when inplementing it. If this "3rd party" plugin was so important, then implement the plugin later on when it is secure - you don't fuck around with private details. If it was important for the initial release, you shouldn't of launched until this was sorted. Y…

I think its wrong that you are espousing password security, when you have not taken the required steps to secure your own accounts across "a ton of forums"?

Security in the real world is hard. I worked as a penetration tester, so I have some authority to say so.

For most startups getting users is a priority and everyone is prone to taking shortcuts (clearly including YOU - sharing passwords across forums); incidents like this are common place in the business world and the fact that Envato had the balls to own up is kudos to them.

Re: Tuts+ Premium Account Security Compromised

#68

My email to Envato: I seriously can't understand how Envato found it responsible to even implement something that saves plaintext passwords. You must of known when inplementing it. If this "3rd party" plugin was so important, then implement the plugin later on when it is secure - you don't fuck around with private details. If it was important for the initial release, you shouldn't of launched until this was sorted. Y…

[deleted]

Re: Tuts+ Premium Account Security Compromised

#69
post #59

My email to Envato: I seriously can't understand how Envato found it responsible to even implement something that saves plaintext passwords. You must of known when inplementing it. If this "3rd party" plugin was so important, then implement the plugin later on when it is secure - you don't fuck around with private details. If it was important for the initial release, you shouldn't of launched until this was sorted. Y…

Why would you have to change your password on "a ton of forums" if you yourself have been using password best practices? Envato was responsible in their disclosure- you think those "tons" of forums are all going to do the same? For all you know your password has been in the wild for years. You should use this as an opportunity to get a password manager (Lastpass, for instance) and use unique passwords for each site.

I agree that it's my fault not having a unique password for Envato, I do have unique passwords for most important things, but to have unique weird passwords for everything is too much for me, especially since I'm switching computers all the time, it'd be quite a hassle each time. Especially since I log into a lot of less important sites with this password. If it was a salted and encrypted, I wouldn't bother changing them. But seriously, plaintext. It's the biggest cockup I can imagine. Some may argue, but you can also keep passwords on your phone or online, you're correct, but what if my pass phrase gets hacked to all my unique passwords? How do I know that these services are waterproof? It's not the most secure way of storing passwords either to be honest, but they don't have any other way. It has to be decryptable. In the end, nothing is waterproof.

Re: Tuts+ Premium Account Security Compromised

#70
post #59

Earlier quoted context omitted.

Why would you have to change your password on "a ton of forums" if you yourself have been using password best practices? Envato was responsible in their disclosure- you think those "tons" of forums are all going to do the same? For all you know your password has been in the wild for years. You should use this as an opportunity to get a password manager (Lastpass, for instance) and use unique passwords for each site.

I agree that it's my fault not having a unique password for Envato, I do have unique passwords for most important things, but to have unique weird passwords for everything is too much for me, especially since I'm switching computers all the time, it'd be quite a hassle each time. Especially since I log into a lot of less important sites with this password. If it was a salted and encrypted, I wouldn't bother changing…

Sure, nothing is water proof. However, some solutions are better than others- and as a lastpass user I know I don't have to change my password on "a ton of forums".
Post reply on HN