4 ms·
They don't really say it has been hacked, just that being a target of an advanced password attack. It might mean attackers are using password lists from previo
by rmdoss 10y ago
They don't really say it has been hacked, just that being a target of an advanced password attack.
It might mean attackers are using password lists from previous leaks (linkedin), so they decided to force a pass reset to everyone. Or maybe they got hacked. Who knows, not very clear.
- hellomrpeter 10y agoTrue, but wouldn't this apply to any web-service in existence?
- yborg 10y agoAs has been proven many times before, "very sophisticated", "advanced", "highly complex" etc. actually generally means "our staff was humiliatingly negligent" in some regard. i.e. they were spearphished and the attacker pulled a password database from their internal network. It seems very odd that they resorted to resetting all passwords instead of just affected or potentially affected accounts as Github did recently.
- throwaway_g2p 10y agoWell since its a botnet that is trying to login with lots of different passwords and lots of different accounts its fairly obvious what the attack vector is. That's also why its safer to force a password reset than to just continue to reset passwords after they get compromised.