Patreon Hacked, Personal Data Accessed
AmiMoJo writes: In a blog post Jake Conte, CEO and co-founder of Patreon, writes: "There was unauthorized access to registered names, email addresses, posts, and some shipping addresses. Additionally, some billing addresses that were added prior to 2014 were also accessed. We do not store full credit card numbers on our servers and no credit card numbers were compromised. Although accessed, all passwords, social security numbers and tax form information remain safely encrypted with a 2048-bit RSA key."
Erm,
Passwords should never be encrypted. Anyone who signed up should assume their passwords are fucked, especially since the private key for decrypting them (assuming this guy even knows what he's talking about) is almost certainly in the app.
People with artwork happening through Patreon are almost certainly having it ripped and distributed.
I know of hundreds of Patreon people having their stuff ripped and distributed right now.
Still waiting on Serviscope_minor to wake up to fucking reality and realize that Jessica Price isn't going to fuck him.
*sigh*
Everybody change your passwords...again. Everybody renew your credit cards...again. Everybody sign up for LifeLock....again. Everybody check your credit scores...again.
Patreon is full of talentless beggars who harass people for money similar to Jimbo "A Personal Appeal" Wales. I hope all Patreon users get their penises chopped off.
Anybody names Sam Yam deserves to be hacked
I've never heard of this outfit...What the fuck is it that they do? Doesn't seem that hard to give a description of the business.
If they let someone into their servers by accident, shouldn't we / they also be curious if the private key has been stolen, even if not stored on those servers?
Their about page says absolutely nothing about them, what they do or anything. How do they have anyone using what ever service they may be providing? Does anyone do any fucking research into the "businesses" they decide to do business with?
If a company can't put more than 2 fucking sentences about them on their about page, do they really even know who they are?
You don't 'protect' static data with RSA.
While we're covering the potential errors of Patreon, how about making the logout link/button easier to find? I'm tired of closing the entire browser to clear my connection to them.
GenZ hipsters looking for free money get ripped off? Cue the fake outrage. Here's a life lesson, kiddies - go get a job.
Until we find out that they never salted them, nor used pepper. Then we are cooked beyond believe with no seasonings.
Companies are rarely "hacked" in the traditional sense. Nine times out of ten it is an inside job or a disgruntled employee that leaks crucial details to facilitate a breach. In any case, the evidence of either is indistinguishable.
Related Links
1307 Greece Rejects EU Terms
1097 Two Gunman Killed Outside "Draw the Prophet" Event In Texas
894 Pope Francis: There Are Limits To Freedom of Expression
776 Worker Fired For Disabling GPS App That Tracked Her 24 Hours a Day
760 $56,000 Speeding Ticket Issued Under Finland's System of Fines Based On Income
Someone forgot to add the 'salt' to these.
If they send me my actual password (and I've had that happen)
TracFone and its associated sites do this