Business IT - Technology for your business

No. 1 Story

Cloud alliance sides with Optus on copyright

OzHub, the Macquarie Telecom-led cloud computing alliance, has come down firmly on the side of Optus over the copyright controversy surrounding Optus TV Now, warning that any moves to change the law "risk branding Australia a global luddite state."

read more

32 million passwords in the clear, in the wild

Business IT - Security

Anyone with an account on RockYou might like to RUN to every other site where they have used the same password and change it.

RockYou is an application hub publishing a number of gadgets for use on a variety of social networking sites.  Visiting their website, users are confronted with add-ons for Facebook, MySpace, Hi5 (the dating site, not the children's entertainers!), Bebo and many others.

According to reports, RockYou has around 32 million registered users.  And this is where the problems start.

According to the good folks at Imperva, it appears that there was a SQL injection flaw on the site.  This flaw allowed pretty-much unimpeded access to the back-end database.  It would appear that on December 4th someone took a copy of the entire user database.  We know this because they publicized pieces of it, with details obscured.  The link is on the TechCrunch site, but don't follow it – malware was pushed at my PC when I tried.

Unfortunately, it wasn't until at least December 14th that RockYou acknowledged the intrusion, although they claim that the intrusion was quickly detected and the site taken offline to close the loophole.

In a statement RockYou claimed that they are about to advise all users of the intrusion. 

Ten days after the intrusion, they still haven't advised the compromised accounts?

By the way – the reason everyone is up in arms about this?  The user database records contained (amongst other information) every user's email address and their RockYou password IN PLAIN TEXT!

So, if you were one of the majority of users who tend to use the same password on multiple sites, you now have a big problem.  Worse, the bad guys have a ten day head start on you.

So, what does this mean?



- sponsored feature -

The Death of Traditional BI: What’s Next?

How to Make Business Discovery Work for Your Business IP PABX BUYING GUIDE

Business Discovery takes its cues from consumer apps. Like Google, it encourages us- ers to hunt for and explore data without worrying about or even noticing the underly- ing technology. Their entire experience is working within an intuitive interface to get real-time, self-service results with only minimal training. ...more