10 ms·
Weebly hacked, 43M credentials stolen
- guessmyname 10y agoAnd here I am, trying to apply for a Senior position there [1]. [1] https://news.ycombinator.com/item?id=12752642 https://news.ycombinator.com/item?id=12752642
- reustle 10y agoSounds like they need you :-)
- deleted 10y ago[deleted]
- cyberferret 10y agoWell, the breach was back in February this year, so I hope they have put better security in place since then. I've seen ads for Weebly all over the place, but never realised they had that many users. Good luck with your application... :)
- ryanburk 10y agoaccounts doesn't mean the same thing as current or active users. a company very likely doesn't delete accounts right away or at all, even if the service has been cancelled. for example, a few years ago microsoft's live ID system had well over a billion accounts. but MAU was only around 450M. and that is with culling / deleting accounts after a year if they were unused.
- joncalhoun 10y agoWhile I agree the two are different, I also think in weeks case accounts could translate into multiple users. I know for a fact that my wife and her sister both share a weebly account for their business and I believe they have to share a login to do this.
- jc4p 10y agoThat job listing is just so sad. Who starts a senior android role's requirements with "git workflows"?
- hueving 10y agoOrganizations that heavily rely on git? It might seem trivial to you, but the last thing I want in a CI/CD pipeline is senior engineers that don't understand the underlying technology. Believe me, I've interviewed lots of people for senior positions that just haven't had to properly learn revision control. It's not a given.
- jc4p 10y agoPerhaps I should've gone in more detail. I'm not upset about them wanting people who are proficient in git, I'm saddened that the job listing doesn't mention anything about what a Senior Android Developer does at Weebly. The only Android related things on the job listing are proficiency with the IDE (Android Studio) and generic "frameworks". I am an Android engineer, I clicked this job listing earlier today when it was on HN because I was interested in it. From the perspective of a listing that tries to get a good funnel of candidates coming in, it does nothing for me. Would you apply to that job listing? I spend a lot of my day to day helping companies optimize their job listings, especially when they have high view numbers but low application click through rates, so this is a pet peeve.
- sroussey 10y agoWhat are your suggestions?
- jc4p 10y agoI wrote a post about this a while back: http://kasrarahjerdi.com/2016/08/on-developer-hiring/ http://kasrarahjerdi.com/2016/08/on-developer-hiring/ Basically I like job listings that include _specific_ information about the role at the company. Maybe that means listing some of the hard challenges the other people on the team have worked on recently, maybe it just means listing the frameworks and libraries they're using, but anything to help me differentiate their Android role from someone else's Android role.
- mirekrusin 10y agoBut on the website it says they have 30m users only?
- papayawhip 10y agoResponsible disclosure and proper handling of passwords as well as not storing credit cards. Barring no breach at all, this is about as well as something like this can go.
- matt_wulfeck 10y agoBonus points for mentioning the hashing algo and for not confusing "hashed" with "encrypted".
- teej 10y agoThat incident response firm seems to be worth it.
- tptacek 10y agoWeebly is one of the more clueful startups. They didn't get this from the IR team. They've been doing stuff right for a long time.
- teej 10y agoI don't doubt that they're clueful. That's why I'm confident that they hired an excellent incident response team and wisely chose to have them review and edit any external communication. Anything less would be irresponsible.
- dsacco 10y agoWeebly's team made the conscious decision to use security protections like bcrypt hashing on passwords, and they've been doing that for a long time (years). They're well aware of security best practices, and that did not come out of work with an incident response team for discovery.
- nso 10y agoAgreed, minus the lack of salting and hashing of upadtresses in the db. Sace meta like country and city about the ip and then store the adress unrecoverable. Generally no big eeasons to have the actual ip stiored.
- mattjaynes 10y agoMore details and background: https://www.leakedsource.com/blog/weebly/ https://www.leakedsource.com/blog/weebly/
- vonklaus 10y agoLook, this was 100% Russia. 17 government departments have certified this was Russia. This has Russian fingerprints all over it. <sarcasm> Edit: man, this got unpopular. Curious if people dislike the sarcasm, or the sentiment of regular unfounded claims Russia is responsible-- at a gov't level, for major "hacking" transgressions.
- notliketherest 10y agoI appreciate the sneaky attempt at political dialog after the past few days of in your face flame wars.
- vonklaus 10y agoI am not trying to start a flame war, just curious why the 2 jokes about Russian hackers being the origin of breaches are being heavily downvoted. I would assume people think they aren't clever or funny, but hopefully not because they disagree that Russia seems to be the catch-all scapegoat right now.
- grzm 10y agoLikely because they don't add substantively to the topic conversation and are distracting given discussions going on in other threads.
- axitanull 10y agoSimple really, joke that is not adding anything to the discussion is not appreciated here.
- unimpressive 10y agoIt doesn't matter if people think they're clever or funny, a core tenet of HN is that you downvote cute jokes so that they don't eat all the real discussion like they do on Reddit.
- vonklaus 10y ago
- stevesun21 10y agoI wonder if the hacker really interested in decoding credential or they just want to collect the email addresses which is really valuable for email marketing.
- jazoom 10y agoYou mean "email spamming"? I'd be hesitant to call that "marketing".
- davidsong 10y agoSpam is as much a form of marketing as assault is a form of touching.
- scurvy 10y agoIt's not worth much at today's going rates (maybe a few hundred bucks). The hacker probably could have made more money through a bug bounty program.
- drusenko 10y agoObviously, this is a very disappointing situation for us -- we've always taken security very seriously since day 1, it's something that's been core to who we are from the beginning. That said, how you respond in this situation can be just as important, and so we are making sure to be incredibly proactive in addressing the situation & transparent in how we communicate the details with our customers. Our top and immediate concern has been our users and the safety of their accounts. A few days ago we became aware that an unauthorized party obtained email addresses/usernames, last login IP addresses and bcrypt hashed passwords for a large number of customers (anyone who signed up prior to March 1 of this year). At this point we do not have evidence of any customer website/account being improperly accessed. It's also worth noting that we do not store any full credit card numbers on Weebly servers, so any credit card information was not part of this incident. We immediately starting working on taking steps to notify our customers, and were able to get this out in a matter of a few days. We're initiating password resets as of this morning, and we've also made several improvements to the application including new password complexity requirements and a new dashboard that gives customers an overview of recent log-in history of their Weebly account to track account activity. We also increased our bcrypt work factor from 8 to 10, and all passwords will be automatically upgraded as of the next time a user logs in. We've hired an incident response firm who is working with our internal team to complete a full investigation. In the meantime, we're examining our stack top to bottom and taking many steps to enhance our network and application security. This is an area we take very seriously and we'll be putting in tremendous effort to ensure this doesn't happen again.
- kitanata 10y agoJust tried updating my password for my weebly account. It appears this functionality is broken. It keeps telling me that "Your current password must be correct". I logged in and out with the same password a couple times to confirm I'm not crazy.
- drusenko 10y agoCan you email me at david@weebly.com? We looked into this shortly after you posted this comment and can't replicate (also not receiving other complaints)... If you can email me we'll get to the bottom of it -- thanks for letting us know!
- lrvick 10y agoI have talked to a number of current and former Weebly employees trying to convince them to use things like hardware token based 2FA, hardened servers, hardened workstations, and strong end to end encrypted password management that can't be trivially decrypted from a private key stolen from memory. I had such things written off as being too paranoid when they are too easy -not- to set up. I was not at all shocked by this headline. I don't want to just single out Weebly here as I discuss these sorts of things with people at different companies all over the bay out of personal interest and anything harder than using something like lastpass to reach production systems is considered too much work. Honestly Google and Facebook are the only large companies I have seen deploy fairly decent security practices out of the dozens I have exposure to. I credit this to the fact the employ teams people who have the specific job of continually auditing and enforcing all available security tools on their systems and fostering a culture that security is everyone's job. You will pay for security either way. Either up front paying teams of capable people, or in lost customer trust after the fact. Security apathy in the valley is a cancer impacting companies of all sizes. Sure you can't make anything perfectly secure, but you can at least force your attacker to burn a 0day. Don't make it as easy as spoofing an email and getting an employee to click a malicious link. If you have any sort if privileged access to PII data of your customers and are not even doing basics like using hardware tokens to gate your server and db access you are one keykogger or XSS away from a serious breach. If you know how to set such things up and still don't do it, you are additionally a terrible person. At the very least the data required to readily plaintext the passwords is not public in this case which is a lot better off than companies using only simple hashing like md5. Some credit is due here for sure, but I can't help but strongly suspect the issues here and in now countless other orgs are a result of people having access to PII that don't really care about security or respect the privacy of the user data they are responsible for.
- scurvy 10y agoHow do you know if any employee passwords were stolen? How do you know it wasn't just a basic application exploit? How do you know Weebly doesn't do the things you mentioned? Fact is, you don't and that post was just an ad for your "services" in the form of a thinly veiled critique.
- drinchev 10y agoEvery time when this happens I ask myself only one question. What about all those hacked servers that we don't know that are hacked yet? There are ( and I'm pretty sure ) lots of hackers that do this on a daily basis, but don't try to do anything malicious on a large scale ( like dumping the whole db of customers, DDoS, etc. ). They probably target medium-large or small companies' servers, put a backdoor there and analyze. Either stealing some business secrets or leave it like that for one of the dark days when some political-corporate person will need their help. Having the whole human knowledge on the palm of my hand made also our own lives public-knowledge.
- erjjones 10y agoExactly! Also in this instance, Weebly, they get an anonymous "hey look, I have all of your data". So Weebly issues a statement to their customers to reset their passwords (which the hackers knew would be a byproduct) and unbeknownst to them the hackers are now skimming the new passwords off the network.
- allerhellsten 10y agoCredentials aren't stolen for sure. I can still log in.
- ksec 10y agoI really like Google's Recent Log in Activity and Location. So anyone logging into your account from a Different location, you are automatically notified. But one of the problem with this is that once hacked, it exposed your location as well. 2nd thing is 2FA. I hope 2FA becomes the standard for all login. Even SMS. ( I know SMS is not save in US, but I am not sure if similar can be said in EU or Japan )
- DeAndre222 10y agoIf you are looking for a professional Hacker that is specialized in changing school grades,getting password to Facebook, Instagram ,any email account, Mobile phone Hacking, removal of links from website. Retrieving hack and frozen bank account, His jobs are secured and without trace. contact him at dataoasis247@outlook.com or message us at +1 262 777 8270