Disqus Confirms Over 17.5 Million Email Addresses Were Stolen In 2012 Hack of Its Comments Tool (zdnet.com)
Disqus, a company that builds and provides a web-based comment plugin for news websites, said Friday that hackers stole more than 17.5 million email addresses in a data breach in July 2012. "About a third of those accounts contained passwords, salted and hashed using the weak SHA-1 algorithm, which has largely been deprecated in recent years in favor of stronger password scramblers," reports ZDNet. From the report: Some of the exposed user information dates back to 2007. Many of the accounts don't have passwords because they signed up to the commenting tool using a third-party service, like Facebook or Google. The theft was only discovered this week after the database was sent to Troy Hunt, who runs data breach notification service Have I Been Pwned, who then informed Disqus of the breach. The company said in a blog post, posted less than a day after Hunt's private disclosure, that although there was no evidence of unauthorized logins, affected users will be emailed about the breach. Users whose passwords were exposed will have their passwords force-reset. The company warned users who have used their Disqus password on other sites to change the password on those accounts.
I'm really not sure how much I consider an email "breach" all that big a deal. Most people use semi-disposable email anyway, and how is your email address much more secret than your street address? I suppose they could use them in a big data-mining cross-reference deal, but at this point, I'm kind of "so what".
If you want news from today, you have to come back tomorrow.
It's Disqus, not disgus.
It's not "Disgus" with a G, it's "Disqus" with a Q. It's a play on "discuss".
Freudian slip?
Yet another one gets hit.
What was the hole this time I wonder.
I wonder how many more upcoming breach announcements we'll have, all hoping to get away with minimal casualties because they aren't as bad as the disasters at Equifax and Yahoo.
What a great idea. Supply valid email addresses to an unknown third-party. That little BB rattling around your skull is very lonely, isn't it?
but this one is mine.
"About a third of those accounts contained passwords, salted and hashed using the weak SHA-1 algorithm, which has largely been deprecated in recent years in favor of stronger password scramblers,"
Sigh. If you're going to pick a quote, pick one that states a meaningful fact. SHA-1's flaw is that it allows a pre-image attack, where an attacker can craft a duplicate message that yields the same hash value as a different message, which is very useful for forging signatures on certificates. But that flaw is utterly useless for more efficiently brute force attacking a password that was hashed with SHA-1.
All the information I gleaned from this quote is that the author doesn't understand what he's talking about, and his writing isn't worth reading. Oh, and that my password on Disqus is still safe.
John
I really don't trust these sites to do a good job... but only allowing google and twitter oauth providers is pathetic
He is right though. If you can get yourself to trust HaveIBeenPwned.com (and it's a pretty well-known security site), then you get free reports of all major password leaks from all other sites, even itself if that ever happens. If you can't trust it, then you you implicitly trust *all* the other sites you sign up for to not get hacked, or to reliably notify you when they do. Now which is easier: to trust one site, or to trust all of them minus the first one?
Years ago, I used Yahoo!'s OAuth provider to sign up on lots of sites. That sure kept my accounts secure! :-/
John
Yep. I use the notifications from that site to remind me when it's time to change all my important passwords.
Many of those account owners could literally be dead.
The problem with oauth and the like is that they are a bit like keeping all your eggs in one basket. If the auth provider is breached, it is theoretically possible for credentials to be forged. Unlikely, but possible. It's generally better to compartmentalize, so a breach at one place won't make you vulnerable anywhere else.
On the other hand, people really don't like doing passwords in a secure way. It is, admittedly, a real hassle. If you aren't going to do passwords securely, then you're much better off using an auth provider.
Since this is a good post I'll promote it to a whopping zero score.
Check out "Have I Been Pwned" website. You can enter all your email addresses and get notifications if a particular email address got exposed in a data breach. I've gotten several email in recent days informing me of data breaches at Kickstarter and Pinterest.
https://haveibeenpwned.com/
This way we can all benefit from the only good post you made all year without having to mod you up where you'll spam your amazon affiliate links all over.
The USA government simply cannot be trusted.
Every single email that I checked shows to have been compromised. Sigh.....
***please pay attention to the Moon update***
C.D. Reimer is a renowned Slashdot collaborator, as he puts it himself; "Because of the quality of my posts and my article submissions, I'm a highly rated commentator and moderator."
But does anybody ever wondered what "C.D." stands for? Well, it stands for Creimy Dumpty of course!
Creimy Dumpty sat on the wall,
Creimy Dumpty had a great fall.
All the king's horses
And all the king's men
Couldn't put Creimy Dumpty
Together again.
Creimy's siblings video and theme song, very realistic, especially the pants, just like Creimy's:
https://www.youtube.com/watch?...
With "Vice President Pence Vowing US Astronauts Will Return To the Moon", we are sure they will need miracle workers up there, here is what it would look like. Note that Creimy takes care of bringing a lot of food to the moon as depicted below:
https://www.youtube.com/watch?...
Creimy's real pictures:
Before the sex change:
https://ibb.co/cc7Ddw
After the sex change:
https://ibb.co/gVad65
Creimy's "enterprise-level" chair, he talks about it all the time on slashdot:
http://www.keynamics.com/image...
Creimy's head, while his supervisor was talking to him, not with him, since it is impossible to do with Creimy:
https://school.discoveryeducat...
Creimy acting in educational resource document, he actually confirmed himself on Slashdot that he was handled by Special Education for the Santa Clara County Office of Education! He is really a king Dumpty!:
http://www.sccoe.org/depts/stu...
Exactly! We, at Special Education for the Santa Clara County Office of Education, couldn't agree more with you!
For the valuable /. users that might already have read the following, please note that there is an important update.
IMPORTANT UPDATE:
Special Education for the Santa Clara County Office of Education has invested money to buy Chris a new chair:
http://www.keynamics.com/image...
Information about Christopher Dale Reimer and autistic people:
Autistic people have obsessions about things normal people don't care. For example, one of our autistic patient went haywire when he realized that there was a penny missing in his pocket change.
To calm him down, one of our educator pretended to have found it on the floor and gave a penny to him.
The autistic patient condition went even worse because he realized it wasn't the same penny!
Chris has an obsession with budgeting every penny. He doesn't understand that most people do not budget to the penny and have a flexible amount they allow for miscellaneous items.
I am Nancy Guerrero and I am Director of Special Education for the Santa Clara County Office of Education. We use Chris' (a.k.a. creimer,cdreimer) picture in our document because he is the hardest case we have ever had to handle:
http://www.sccoe.org/depts/stu...
Our artists were inspired by the low carb diet that Christopher follows scrupulously for the small lunch box and by the picture linked below for the rest. I am sure that you will notice the similarities such as the bump on the side of his chest and more:
https://ibb.co/gVad65
Please be easy on Christopher although, I am aware that some of our staff handling Chris post joke comments here and obvoiusly, the Santa Clara County Office of Education disapprove that behavior vehemently:
https://school.discoveryeducat...
But it isn't Chris' fault if he is the way he is. We do the best we can do with him and he is partially integrated into society. We try to cure his abnormal need for attention but he is kind of stubborn and won't listen to anybody.
Thank You dear users,
-Nancy Guerrero
Christopher, my love,
I am deeply sorry. I didn't feel well lately but I am better now since I had my meds adjusted. I am sorry that I called you all sorts of names on /. and I feel truly ashamed of myself.
The python click script you wrote for me my sweet love for my pheromone revenue stream web site suddenly stopped to work.
Could you come visit me in my studio so we could look at it?
Signed:
Your sweetee who will love you for ever.
You are just as delusional as creimer. If you give him the slightest chance, he will just jump into the opening and get back at his old tricks. That's all he knows and that's all he is interested about.
--
The chief representative AC.
Let's make Slashdot great again!
That's what you get for following creimer's advice. Now, expect to be spammed with amazon affiliate links as well by email to those addresses as well.
Creimer is highly toxic.
After their members spent half a decade posting unwittingly with their de-anonymized accounts.
Brilliant!
Welcome to creimer's empty heads club, you are now automatically subscribed as a member!
So many bitter people replying to this comment. Did creimer pwned them all?
CAP: chortle
No I totally agree. Anything he does here is just an attempt to up his karma so that more people click the link in his sig and poison their amazon cookies.
But even if by some chance he gets 5 upvotes and get to 0 karma it'll be 2 posts before he's booted back down.
Tick tock, fat boy!
http://www.tmz.com/2017/10/06/...
Who the fuck is creimer? Sounds like a fat, lonely, sour-smelling loser.
AssFux (lol) tell us about your NDA lie and your dns fuckups apk tore you up on please hahahaha https://slashdot.org/comments.pl?sid=11188265&cid=55322595/
Well it says your usual email hasn't been pwned so you're OK on that side.
You are absolutely correct for SHA-1 hashes of random data, of significant length. Passwords, however, are neither random nor long. I'll describe the attack for you and you can try it out yourself. The fact that an ordinary consumer PC can compute SHA-1 password hashes at the rate 10 billion per second is why SHA-1 is no longer appropriate for passwords. Here's how the attack is done:
Download two large lists of passwords, any "combined list" from your favorite haxor site will do. It doesn't matter what sites the passwords are from. If you run a comparison, you'll find that given two lists of a million passwords, about half of the passwords will be on both lists - with different accounts. That is, there is about a 50/50 chance that your password is in the list because somebody else used the same password. You probably know it's not too hard to find lists totaling many millions of passwords (we don't need fresh ones). If we put together a list of 10 million passwords, most of the Disqus passwords will be on our list, because SOMEBODY used the same password (not necessarily the same person).
So we take the first, most common password on our list of previously seen passwords and try it against each of the 17 million hashes from Disqus. Because SHA-1 is so fast, our $100 GPU can check all 17 million hashes in one millisecond. In one second, we can try the top thousand most common passwords. In 24 hours, we can test out 10 MILLION passwords that somebody, somewhere, has used before, and thereby crack perhaps 8 million of the Disqus passwords - which gives us the email addresses to match those passwords.
For passwords, therefore, you need a hash that can't be easily computed at the rate of billions per second with commodity hardware. Bcrypt and scrypt are appropriate choices. To avoid certain problems with particularly long or particularly short passwords, you first take a SHA-2 hash of the password, then scrypt it.*
* In the general case of random data, hashing a hash doesn't add security. Passwords, however are not the general case.
no but in the summary they already mention the website and the fact that it's the guy who runs haveibeenpwned that told disqus about the breach. Then creimer steps in and mention the site in his insightful comment.
That's like telling a joke to two retards then hearing one of them telling the joke to the other.
lucm, indeed.
It's also annoying if you close your Google account and those sites are tied to it.
lucm, indeed.
Guess what service I'm glad I never bothered to sign up for.
There is no XUL, only WebExtensions...
Yeah, typical creimer M.O. Be as annoying as possible, then play the victim when people get tired of his noisome horseshit.
Have you stopped raping your neighbor's goats yet?
Disqus is a scam.
A while ago we had a news discussion where we found the following rules for cencorship:
"Putin is an Idiot" is censored.
"Trump is an Idiot" is censored.
"Obama is an Idiot" is NOT censored.
"Merkel is an Idiot" is NOT censored.
So now we got curious, we edited the already posted texts by exchanging the names randomly... at first the "new" anti-Putin comments where up for a couple of minutes puplicly and then got cencored. The "new" Anti-Obama-comments on the other hand where still blocked for a couple of minutes and then became public. So we edited the texts back and voila, a couple of minutes later the censorship strikes again. We continued this on several accounts for a couple of hours then suddenly EVERY edited comment became invisible for a couple of hours(!) until being manually switched public as long as it did not insult putin or trump. Being Greasemonkeys we made sure the texts got edited for another couple of days over and over again, also using new accounts but no way to criticize Putin.
Forum didn't matter, topic didn't matter, it just was not possible to critcise authoritarian politics. After we made this public several news papers stopped using disqus.
Therefor I say: Disqus is a Scam!
"Life is short and in most cases it ends with death." Sir Sinclair
Has anyone verified that this site isn't going to send spam with a dump email?
Just wondering since my normal source for dump emails has an NSFW name and I'm reading this at work.
Potayto potaughto
What neighbor? They're *MY* goats, Chris!
...and now 5 years later they notice it? Why are companies like that still allowed to stay in business?
It wouldn't be a big deal... if for not the fact that NOW they are telling us about something that happened FIVE YEARS AGO.
Sure, and you *chose* to get your karma nuked to -1, right, tubby? And I'm supposed to believe someone like you has friends, and they fit in your 475sq.ft. storage closet?
Oh, right, you "had" you ten year old (no hyphens, dummy) account deleted, but magically feel the need to register 4 new accounts?
You're such a smear of rectal jelly.
It may be actually kinda lame to waste time on you. It's worse to delude yourself into thinking that you're not universally disliked so that you can keep posting on a dying forum and make 13 extra dollars a day posting links to amazon.
Creimer must be moving up in the world. Six months ago he was making a half-cent per day on Slashdot.
CAP: please
. . . to the latest count of over 3 billion, 240 million invasive hacks since 2012, we how are updated to OVER 3 billion 258 million!
According to the graph he posted it was the best month he had. He's making a lot less now, no doubt because his "trolls" have made everyone aware of his hustle.He should block this site and get into behavioral therapy
" and laugh my ass off "
Oh, is that what happened to it?
Couldn't happen to a better company. The way they show posts must be one of the most fucked up ways of doing it.
How can they email the affected people when they said that their email addresses were stolen?
disqus is shit, any web site using it is not worth my time.
NFI what you're asking.