Kickstarter Security Breach Exposes Customer Data
New submitter jbov writes "Kickstarter members received an e-mail at about 16:40 EST notifying them of a security breach. According to the e-mail, information including user names, encrypted passwords, mailing addresses, and phone numbers may have been revealed. Kickstarter members were urged to change their passwords. 'Older passwords were uniquely salted and digested with SHA-1 multiple times. More recent passwords are hashed with bcrypt.' Kickstarter claims that credit card information was not accessed during the breach. According to Kickstarter, law enforcement officials contacted the company on Wednesday night and alerted them that 'hackers had sought and gained unauthorized access to some of our customers' data.' Upon learning of the breach, Kickstarter closed the security breach and began strengthening security measures."
Thank you for being a friend
Traveled down the road and back again
Your heart is true, you're a pal and a cosmonaut.
And if you threw a party
Invited everyone you knew
You would see the biggest gift would be from me
And the card attached would say, thank you for being a friend.
I guess Kickstarter failed to use APK's hosts file.
for several years no. The Republicans hate the post-corporate world in which we now live. Expect them to continue with more ridiculous attacks on Kickstarter and their investors.
they did the right thing and contacted all the people who use KS and advised them to change their login. Unlike Adobe who still haven't contacted me....... With influence comes responsibility - KS has taken responsibility, Adobe never did.
Kickstarter stores information about Amazon accounts and the like, too. This could be pretty serious.
AND, they should be held legally responsible. Really, as a society we have to start doing that.
Hmm. I have a Kickstarter account, but I haven't gotten a notification email, so far.
The 'beasts' share the same scent - how to piss off an alien/human hybrid
the hybrids carrying filthy spawn (like in the days of Noah) are easy to SNIFF out, literally, they all smell the same when you're in the proper state of mind.
some of them have eyes which appear to be bugging out of their face.
even if you can't detect the scent of the hybrids, or 'beasts', inhale deeply whenever the hybrids are close, don't express any emotion, just keep inhaling deeply and make your facial expression be that of deep contemplation.
when you do this, they know that you know what their true reality is - it's like the movie THEY LIVE where Nada sees the truth through the glasses and confronts them.
don't confront, just inhale deeply. maybe shake your head and laugh, mumble about stupid aliens but nothing deep.
Welcome to the decade where big corps realize they can't skimp on security anymore because it costs the banks more time and money to issue cards, and that raises rates for everyone else.
What does this mean for Star Citizen funders? lol
Seven puppies were harmed during the making of this post.
Why are we not using public private key infrastructure for online logins yet????? It's 2014, most people have been online for nearly twenty years and human beings are still using passwords that have to (generally speaking) be memorized which leads to poor password choices and repetition. This problem should have been solved YEARS ago.
When Beta first reared its head on this hallowed domain.
Thank you, I’ve just been searching for info approximately this subject for a while and yours is the greatest I’ve came upon till now. But, what in regards to the conclusion? Are you positive concerning the supply?|What i don’t realize is in reality how you’re no longer actually a lot more neatly-preferred than you might be right now. You’re so intelligent. and if you have free time
http://mahjongdimensions.info/ administrators
Encrypted passwords, how? Do they mean salted and hashed, if so, then the summary should say so.
...I thought the lyrics was "you're a pal and a confidant"
From what I've been able to understand from communication with Kickstarter and from their mail, the passwords weren't individually salted.
Storing encrypted passwords without salt should get whoever's responsible for their security FIRED. That's truly a rookie mistake. Why? Because it's vulnerable to dictionary attacks.
Kickstarter was nice enough to require you to use email as your login!
and your email address
and your phone number
and your mailing address.
Thank you for being a part of Kickstarter.
Still waiting for the email ...
Here in the land of Kraut and Wurst we had soemthing called "TAN List" in the past. Simply a sheet of paper with one-time-passwords. We used that to confirm banking transactions.
Very easy to make this scheme very secure. Why do we need electronic gadgets with half-baked security mechanisms ?