Be Excellent To Each Other

And, you know, party on. Dude.

All times are UTC [ DST ]




Reply to topic  [ 7 posts ] 
Author Message
 Post subject: Spotify have lost all your passwords.
PostPosted: Wed Mar 04, 2009 18:13 
User avatar
I forgot about this - how vain

Joined: 30th Mar, 2008
Posts: 5979
http://www.spotify.com/blog/

Quote:
Last week we were alerted to a group that managed to compromise our protocols. After investigating we concluded that this group had gained access to information that could allow testing of a very large number of passwords, possibly finding the right one. The information was exposed due to a bug that we discovered and fixed on December 19th, 2008. Until last week we were unaware that anyone had had access to our protocols to exploit it.

Along with passwords, registration information such as your email address, birth date, gender, postal code and billing receipt details were potentially exposed. Credit card numbers are not stored by us and were not at risk. All payment data is handled by a secure 3rd party provider.

If you have an account that was created on or before December 19th, 2008, we strongly suggest that you change your password and strongly encourage you to change your passwords for any other services where you use the same password.

When choosing your password we provide you with an indicator of the password strength to help you choose a good one. To change your password please visit your profile page on our website.

https://www.spotify.com/en/account/profile/

For the technically minded amongst you, the information that may have been exposed when our protocols were compromised is the password hashes. As stated, we never store passwords, and they have never been sent over the Internet unencrypted, but the combination of the bug and the group’s reverse-engineering of our encrypted streaming protocol may have given outsiders access to individual hashes.

The hashes are salted, making attacks using rainbow tables unfeasible. Short or otherwise bad passwords could still be vulnerable to offline targeted brute-force or dictionary attacks on individual users, but you could not run attacks in parallel. Also, there has been no known breach of our internal systems. A complete user database has not been leaked, but until December 19th, 2008 it was possible to access the password hashes of individual users had you reverse-engineered the Spotify protocol and knew the username.

We are really sorry about this and hope you accept our apologies. We’re doubling our efforts to keep the systems secure in order to prevent anything like this from happening again.

_________________
Curiosity wrote:
The Rev Owen wrote:
Is there a way to summon lave?

Faith schools, scientologists and 2-D platform games.


Top
 Profile  
 
 Post subject: Re: Spotify have lost all your passwords.
PostPosted: Wed Mar 04, 2009 18:21 
User avatar
UltraMod

Joined: 27th Mar, 2008
Posts: 55717
Location: California
Oh dear.

_________________
I am currently under construction.
Thank you for your patience.


Image


Top
 Profile  
 
 Post subject: Re: Spotify have lost all your passwords.
PostPosted: Wed Mar 04, 2009 18:39 
SupaMod
User avatar
Est. 1978

Joined: 27th Mar, 2008
Posts: 69689
Location: Your Mum
I think we had accounts well after 19th December.

_________________
Grim... wrote:
I wish Craster had left some girls for the rest of us.


Top
 Profile  
 
 Post subject: Re: Spotify have lost all your passwords.
PostPosted: Wed Mar 04, 2009 18:41 
User avatar
UltraMod

Joined: 27th Mar, 2008
Posts: 55717
Location: California
Good point. I thought it was fairly recently, but it's 2.5 months ago.

_________________
I am currently under construction.
Thank you for your patience.


Image


Top
 Profile  
 
 Post subject: Re: Spotify have lost all your passwords.
PostPosted: Wed Mar 04, 2009 18:43 
User avatar
I forgot about this - how vain

Joined: 30th Mar, 2008
Posts: 5979
Ah phew. I wasn't sure when the big craze here was but I thought I should post just to be sure.

EDIT: FEW? FEW? JESUSFUCK.

_________________
Curiosity wrote:
The Rev Owen wrote:
Is there a way to summon lave?

Faith schools, scientologists and 2-D platform games.


Top
 Profile  
 
 Post subject: Re: Spotify have lost all your passwords.
PostPosted: Wed Mar 04, 2009 18:44 
User avatar
UltraMod

Joined: 27th Mar, 2008
Posts: 55717
Location: California
This thread says we started signing up on 4th Jan.

_________________
I am currently under construction.
Thank you for your patience.


Image


Top
 Profile  
 
 Post subject: Re: Spotify have lost all your passwords.
PostPosted: Wed Mar 04, 2009 19:02 
User avatar
Chinny chin chin

Joined: 30th Mar, 2008
Posts: 15695
myp wrote:
This thread says we started signing up on 4th Jan.


Good work Batman. Pity Ebuyer and Fasthosts still have my passwords ready for anyone to steal. But glad Spotify didn't make it a hat trick!


Top
 Profile  
 
Display posts from previous:  Sort by  
Reply to topic  [ 7 posts ] 

All times are UTC [ DST ]


Who is online

Users browsing this forum: Majestic-12 [Bot] and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search within this thread:
You are using the 'Ted' forum. Bill doesn't really exist any more. Bogus!
Want to help out with the hosting / advertising costs? That's very nice of you.
Are you on a mobile phone? Try http://beex.co.uk/m/
RIP, Owen. RIP, MrC. RIP, Dimmers.

Powered by a very Grim... version of phpBB © 2000, 2002, 2005, 2007 phpBB Group.