Completely unacceptable

| 1 Comment
If you have a Monster.com, then delete it. They just suffered a major break-in that has cost them all of the information about their user accounts, including their passwords. The people who stole this information were able to get clear text passwords which is completely unacceptable. I not only canceled my account with them, but left them the following note explaining why:

There is no good reason why our passwords were able to be stolen. Even as a fresh college graduate a few years ago, I understood the basics of securing this information through common hashing algorithms and other basic infosec measures. The fact that such simple, common sense measures were not taken by your engineering staff leaves me without one iota of confidence in Monster or its services.
They should have passed the passwords through a strong hashing algorithm and stored the value from that in the database instead of the regular password. This is a common way of securing such information. When the user logs in, you pass the value they submit as their password into the hashing algorithm and see if it matches what is in the database.

1 Comment

I did not hear about this at all. I hope they sent a notice to everyone who had an account. Did you get a response back?

Leave a comment

March 2010

Sun Mon Tue Wed Thu Fri Sat
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30 31      

Recent Entries

A window into the totalitarian mind of the left on freedom of religion
From Digg: Me: I'm not going to hold my breath waiting for the same liberal democrats who shriek about the…
Google's lossy compiler
Google's closure compiler service gets a little too frisky under ADVANCED_OPTIMIZATIONS. Original code: With advanced optimizations enabled, it was able…
The three purposes of the federal income tax law
Businesses will spend about 3.4 billion man-hours and individuals about 1.7 billion hours figuring out their taxes this year.…

Subscribe

Advertisements

OpenID accepted here Learn more about OpenID