Slashdot Mirror


Formspring Hacked - 420,000 Password Hashes Leaked

wiredmikey writes with news of yet another business suffering a data breach. From the article: "Formspring, the Social Q&A portal ..., admitted to being breached on Tuesday. The compromise led to the loss of 420,000 passwords, forcing the site to reset all member passwords. Mirroring the recent LinkedIn breach, Formspring said that it was alerted to a forum post that contained 420,000 password hashes. Engineers shutdown the service and confirmed the passwords were indeed theirs. In less than a day, an investigation revealed that the attacker(s) had 'broken into one of our development servers and was able to use that access to extract account information from a production database' .... There have been no reported incidents of individual account compromise, but there were reports of Phishing by some users on Twitter attempting to capitalize on the incident."

3 of 68 comments (clear)

  1. 420,000? by Anonymous Coward · · Score: 5, Funny

    420,000? Is that like 100,000 people smokin' the reefer?

    1. Re:420,000? by Fnord666 · · Score: 3, Funny

      More like 420,000 people use(d) something I've never heard of?

      Exactly. One of the articles even concludes with

      Interestingly, while it gained popularity early on, most users who were reporting that they had received a password reset notice had forgotten they even registered with the service.

      --
      'The tyrant will always find pretext for his tyranny.' - Aesop's Fables
  2. I think I figured it out. by InvisibleClergy · · Score: 5, Funny

    I know it's a Q&A site, but ForumSpring Engineers really shouldn't have answered the question, "How do I hack the ForumSpring servers?"