Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


Klipspringer

2385 posts

Uber Geek
Inactive user


#116389 27-Apr-2013 19:06
Send private message

Seems like these security breaches are happening more and more.

This one from Living Social just arrived in my inbox.

IMPORTANT INFORMATION

LivingSocial recently experienced a security breach on our computer systems that resulted in unauthorised access to some customer data from our servers. We are actively working with the authorities to investigate this issue.

The information accessed includes names, email addresses, the date of birth of some users, and encrypted passwords; technically ‘hashed’ and ‘salted’ passwords. We never store passwords in plain text.

The database that stores customer credit card information was not affected or accessed.

Although your LivingSocial password would be difficult to decode, we want to take every precaution to ensure that your account is secure, so we are expiring your old password and requesting that you create a new one.




Create new topic
SaltyNZ
5440 posts

Uber Geek

Trusted
Lifetime subscriber

  #806464 27-Apr-2013 19:31
Send private message

Unfortunately I could not see a 'delete my account' option. Does anyone know where it is?




iPad Pro 11" + iPhone XS + 2degrees 4tw!

 

These comments are my own and do not represent the opinions of 2degrees.


 
 
 
 


gzt

gzt
11635 posts

Uber Geek

Lifetime subscriber

  #806515 27-Apr-2013 21:34
Send private message

Yeah, really annoying. Changed my password this morning after the news. Later in the afternoon received the message about the system password reset. Hmm.

freitasm
BDFL - Memuneh
68478 posts

Uber Geek

Administrator
Trusted
Geekzone
Lifetime subscriber

  #806530 27-Apr-2013 22:01
Send private message

I actually never created an account, but might have entered a competition. They took this opportunity to spam my spare email address. Basically they sent an email to everyone in their database. I then checked my eWallet file and I don't have a password. Went to the site clicked "Forgot password" and entered my spare email address.

The results say "Even though you receive our newsletter you don't have an account. Create one now" (no, never received a newsletter).

Basically they not only had a security problem, they took the opportunity to send emails to everyone, regardless of having an account or not. Pretty poor.




 

 

These links are referral codes

 

Geekzone broadband switch | Eletricity comparison and switch | Hatch investment (NZ$ 10 bonus if NZ$100 deposited within 30 days) | Sharesies | Mighty Ape | Backblaze | Amazon | My technology disclosure


jarledb
Webhead
2540 posts

Uber Geek

Moderator
Trusted
Lifetime subscriber

  #806574 28-Apr-2013 04:35
Send private message

A good time to remind people not to use the same password on several different services.

One good way to deal with lots of passwords, is to auto create them (good long passwords of 14+ letters/numbers) and use a service like Lastpassword or 1Password (my favorite) to deal with entering passwords on the different services.

That way your email and other services aren't in jeopardy if one of the services you use get hacked.

LinkedIn, PS Networks etc. are good examples that its not only small services/sites that gets hacked and bleed usernames and passwords.

Klipspringer

2385 posts

Uber Geek
Inactive user


  #807083 29-Apr-2013 09:15
Send private message

jarledb: A good time to remind people not to use the same password on several different services.

One good way to deal with lots of passwords, is to auto create them (good long passwords of 14+ letters/numbers) and use a service like Lastpassword or 1Password (my favorite) to deal with entering passwords on the different services.

That way your email and other services aren't in jeopardy if one of the services you use get hacked.

LinkedIn, PS Networks etc. are good examples that its not only small services/sites that gets hacked and bleed usernames and passwords.


Thanks for the tip. Going to try this out.

gzt

gzt
11635 posts

Uber Geek

Lifetime subscriber

  #807095 29-Apr-2013 09:28
Send private message

Date of birth is another issue to consider.

How many services have a genuine need for your exact date of birth?

Not LivingSocial that's for sure.

 
 
 
 


freitasm
BDFL - Memuneh
68478 posts

Uber Geek

Administrator
Trusted
Geekzone
Lifetime subscriber

  #807096 29-Apr-2013 09:30
Send private message

Klipspringer:
jarledb: One good way to deal with lots of passwords, is to auto create them (good long passwords of 14+ letters/numbers) and use a service like Lastpassword or 1Password (my favorite) to deal with entering passwords on the different services.


Thanks for the tip. Going to try this out.



LastPass (which I think jarledb is talking as "lastpassword") uses Google Authenticator for two factor security if you want to go even further. There are Google Authenticator apps in all mobile platforms.

I also use Google Authenticator on Google Account, Microsoft Windows account, Dropbox, Lastpass. I use SMS authentication on Facebook and a couple of other services.






 

 

These links are referral codes

 

Geekzone broadband switch | Eletricity comparison and switch | Hatch investment (NZ$ 10 bonus if NZ$100 deposited within 30 days) | Sharesies | Mighty Ape | Backblaze | Amazon | My technology disclosure


Oriphix
516 posts

Ultimate Geek


  #807097 29-Apr-2013 09:34

I personally use Keepass. Its free and you can get a portable version for iPhone (I think you can get it for android as well) so take your passwords with you as well.

Behodar
7128 posts

Uber Geek

Trusted
Lifetime subscriber

  #807110 29-Apr-2013 09:53
Send private message

gzt: Date of birth is another issue to consider.

How many services have a genuine need for your exact date of birth?

Not LivingSocial that's for sure.

Agreed. I'm not familiar with LivingSocial but I don't like sites that "require" data that they don't actually need. For example, I haven't registered with Pizza Hut because they won't let me create an account without providing my physical address (I only ever do pickups). It's not that I don't trust Pizza Hut, but rather that I don't trust potential hackers!

Create new topic




News »

Amazon introduces new Echo devices
Posted 25-Sep-2020 11:56


Mad Catz introduces new S.T.R.I.K.E. 13 Mechanical Gaming Keyboard
Posted 25-Sep-2020 11:34


Vodafone NZ upgrades international submarine network
Posted 25-Sep-2020 09:09


Jabra announces wireless noise-cancelling airbuds, upgrade existing model
Posted 24-Sep-2020 14:43


Nokia 3.4 to be available in New Zealand
Posted 24-Sep-2020 14:34


HP announces new HP ENVY laptops aimed at content creators
Posted 24-Sep-2020 14:02


Logitech introduce MX Anywhere 3
Posted 21-Sep-2020 21:17


Countdown unveils contactless shopping with new Scan&Go tech
Posted 21-Sep-2020 09:48


HP unveils new innovations for businesses adapting to rapidly evolving workstyles and workforces
Posted 17-Sep-2020 15:36


GoPro launches new HERO9 Black camera
Posted 17-Sep-2020 09:45


Telecommunications industry launches new 5G Facts website
Posted 17-Sep-2020 07:56


New Zealand ranks 3rd in world in GSMA index
Posted 15-Sep-2020 10:13


Trend Micro Security Suite adds web monitoring to prevent identity theft
Posted 14-Sep-2020 15:37


NVIDIA to acquire Arm for US$ 40 billion
Posted 14-Sep-2020 12:27


Epson launches its next gen A3+ colour EcoTank multi-function printer
Posted 10-Sep-2020 16:08



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.


Support Geekzone »

Our community of supporters help make Geekzone possible. Click the button below to join them.

Support Geezone on PressPatron



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.