Monster.com Data Stolen, Won't Email Users
chiguy writes "There's been another break-in at Monster.com. It's surprising that there are still unencrypted passwords stored in database despite the previous hack, as is the decision to not email users — presumably so that no one will make a fuss. From PC World: 'Monster.com user IDs and passwords were stolen, along with names, e-mail addresses, birth dates, gender, ethnicity, and in some cases, users' states of residence. The information does not include Social Security numbers, which Monster.com said it doesn't collect, or resumes. Monster.com posted the warning about the breach on Friday morning and does not plan to send e-mails to users about the issue, said Nikki Richardson, a Monster.com spokeswoman. The SANS Internet Storm Center also posted a note about the break-in on Friday.'"
They did the mash. They did the monster mash.
If only there was some kind of service where you could advertise for a network security guy...
I am a nigerian prince who wishes to hire you. I will send you a check for $60,000 to cover your employment of $55,000.
All I ask is that you purchase $5000 in laptops to send back to the parent company here.You can even keep one as your work computer.
As soon as we get the laptops we will send you another check for $100,000 to hire two employees. We only ask the extra $10,000 be sent back to the parent company.
--
So who is hotter? Ali or Ali's Sister?
... I just got a job offer from the Russian Mob!
the person that stole the data emailed the users instead:
Monster.com let me steal your personal information, not once but twice, knew about it, and didn't feel like letting you know, so I thought I would instead.
Click this link to send an email to monster.com to let them know what you think about their security and their policy for handling of breaches.
- The Haxors
BONUS! If you click on the javascript form (can't link directly to it) on their main page up top right that says Help and Security, there's two interesting bullet points lower right:
- Protect yourself against online fraud
- Contact us
Those two really shouldn't be so close together on the same page?
I work for the Department of Redundancy Department.
You left out corporate HR and PR spokespersons. Black women only please. Lesbian, if available, for the company looking for a chic, liberal image.
When incompetence becomes a crime.
and that won't happen because no politician will incriminate themselves.
An SQL query goes to a bar, walks up to a table and asks, "Mind if I join you?"
Then the joke's on them because if they take away my first born, my phone bill's going way down...