6 ms·
Obviously, this is a very disappointing situation for us -- we've always taken security very seriously since day 1, it's something that's been core to who we ar
by drusenko 10y ago
Obviously, this is a very disappointing situation for us -- we've always taken security very seriously since day 1, it's something that's been core to who we are from the beginning.
That said, how you respond in this situation can be just as important, and so we are making sure to be incredibly proactive in addressing the situation & transparent in how we communicate the details with our customers. Our top and immediate concern has been our users and the safety of their accounts.
A few days ago we became aware that an unauthorized party obtained email addresses/usernames, last login IP addresses and bcrypt hashed passwords for a large number of customers (anyone who signed up prior to March 1 of this year).
At this point we do not have evidence of any customer website/account being improperly accessed. It's also worth noting that we do not store any full credit card numbers on Weebly servers, so any credit card information was not part of this incident.
We immediately starting working on taking steps to notify our customers, and were able to get this out in a matter of a few days. We're initiating password resets as of this morning, and we've also made several improvements to the application including new password complexity requirements and a new dashboard that gives customers an overview of recent log-in history of their Weebly account to track account activity. We also increased our bcrypt work factor from 8 to 10, and all passwords will be automatically upgraded as of the next time a user logs in.
We've hired an incident response firm who is working with our internal team to complete a full investigation. In the meantime, we're examining our stack top to bottom and taking many steps to enhance our network and application security. This is an area we take very seriously and we'll be putting in tremendous effort to ensure this doesn't happen again.
- kitanata 10y agoJust tried updating my password for my weebly account. It appears this functionality is broken. It keeps telling me that "Your current password must be correct". I logged in and out with the same password a couple times to confirm I'm not crazy.
- drusenko 10y agoCan you email me at david@weebly.com? We looked into this shortly after you posted this comment and can't replicate (also not receiving other complaints)... If you can email me we'll get to the bottom of it -- thanks for letting us know!
- markdown 10y agoCan't blame you for being hacked, but how can security be "core to who we are" if it took 6 months to discover a breach?
- bigtones 10y agoThey did not discover the breach, it was reported to them.
- mordocai 10y agoDiscovering a breach is arguably the hardest part.
- tptacek 10y agoYou're describing basically every breach ever.
- dsacco 10y agoIn a perfect world companies would recognize and react to security breaches almost as soon as they happen. But if you have ever managed the logging pipeline or incident response practice for a company, you understand that this is deeply unrealistic. There is virtually no company which discovers that it has been breached within a short period of time - the nature of a security breach is such that it doesn't generally become apparent until some time later. This pattern continually plays itself out with just about every large breach you can think of. In that respect, considering Weebly actually hashed their passwords with bcrypt and is reacting to the breach in the same year, they're fairly far ahead of the curve on this one.
- 10y ago
- dpweb 10y agoThis title is incorrect. Credentials not stolen, usernames and hashed passwords stolen. That is not the same as having everyone's password. The title implies someone can easily log in to your account.
- user5994461 10y ago> That is not the same as having everyone's password It is for everyone who used "weebly" or any of the top 100 most common passwords. That could mean no less than 82% of users are at risk.
- jorisvansoest 10y agomore than 63% of all statistics are made up [1] [1] me
- novaleaf 10y agoThis is also not true, as if they used bcrypt (a key derivation function) the hash is salted, so even users using common passwords are protected against rainbow (lookup table) attacks. as for brute force, yes attackers now know usernames, so can try brute forcing the live sites, or brute forcing each user hash.
- MasterScrat 10y agoI believe he meant the will try the top 100 most common passwords on each account on the website directly, resulting on "82% of users at risk", assuming 82% of users use one of these 100 passwords. Strong brute-force protection (eg block account for exponential times) could mitigate this attack vector.
- user5994461 10y agoWhy are you guys talking about live site and rainbow table??? The attackers have the salts and the hashes, they can brute force the hashes offline with [ocl]hashcat as they wish. Top 100 passwords * 43M accounts is only ~4B hashes to compute. We don't know what bcrypt parameters they used but we're probably talking a few hours here, maybe only a few minutes.
- Puts 10y ago"we've always taken security very seriously since day 1" No you have not because then this would not have happened. The only one who should be able to query passwords from the database should be the DBA. Everyone else should only be able to validate against it. So either it's an inside job by your DBA, or you thought your users security was less important then avoiding the friction such high security standards would have introduced in your workflow.
- dsacco 10y agoSecurity is hard. It is very possible to take it seriously, do many things right (perhaps everything right, insofar as it's in your power), and still have your company end up in a headline like this. You can parameterize your queries until you're blue in the face, but that won't help you if the right employee is phished (for example). This is an inherently imperfect and chaotic world, and it's unrealistic to assume that you're insulated from these scenarios just because you locked down database access correctly. Personally, I believe David when he says Weebly takes security very seriously.
- Puts 10y agoI'm kind of tired of the "Security is hard, every one gets hacked eventually and we are just victims" mentality. This is not true. Why don't we see peoples banking information plastered over the web every month? That if something would be a high value target. No, it's always these Web 2.0 services this happens to. Now, you could argue that a small SAAS service can not possibly afford security as rigorous as a bank, but guess what, if you are going to handle peoples information, and don't have the assets to protect it, then maybe your business is not viable enough?
- dsacco 10y agoI invite you to research this topic more thoroughly. First, while there is a recent uptick in breaches, newsworthy ones do not happen every month. There does appear to be something of a clustering effect, which I think is attributable to a number of different causes. [1] Second, banks, even very large ones like Citigroup and Chase, have been compromised in recent memory. [2] Even the IRS suffered one of the largest breaches ever, just last year. Peripherally "financial" institutions that aren't banks have also suffered breaches, such as every single credit card processor and NASDAQ. You have a right to be upset about the increasing probability of your passwords being compromised by third parties. As a consumer, you can mitigate the damage of such breaches by 1. using a password manager, 2. using a different password for each and every account you have and 3. generating extremely secure passwords for each account. You can also use services like HaveIBeenPwned [3] to stay ahead of the damage. However, your indictment here is unreasonable. Like basically everyone else in this thread, you don't have much information to go on yet. Weebly properly hashed and stored their passwords. As far as breaches go, this one is pretty tame. They are reacting responsibly and quickly considering the breach happened this year - normally we'd find out about this in three years. We do not yet know the root cause of the attack, and the criticism you're levying against Weebly is equally applicable to the industries you believe are more safe (they aren't). While many "web 2.0" companies may be rather lax in security, Weebly did not do anything obviously wrong or negligent here. ________________________ 1. As data breaches become more of a hot topic, they will be more likely to be reported widely because it guarantees eyeballs. Similarly, it increases scrutiny, which aids in discoverability, and leads to more copycat hackers attempting these breaches for fame or fortune. 2. https://en.m.wikipedia.org/wiki/List_of_data_breaches https://en.m.wikipedia.org/wiki/List_of_data_breaches 3. https://haveibeenpwned.com https://haveibeenpwned.com
- Ntrails 10y agoWhy does it take a few days to send an email saying "we got hacked, please change your passwords promptly". I accept there are costs to jumping the gun and passing out incomplete information, but if I screw up I tell the affected parties that day. Not after a few days of planning how to manage the message.
- EmielMols 10y agoFor one, it's pretty challenging to send out 43M similarly-looking emails within 24h without tripping a whole bunch of anti-spam filters - even when you're using tailored services (that distribute over IPs with good rep, etc) like Amazon SES.
- Dolores12 10y agoNo its not. they are called transactional emails and dont get blocked. Usually, you have a dedicated IP for that which guarantees fast delivery.
- matthewmacleod 10y agoThis is silly – the entire process of "Oh, we got hacked. What did they access? Who's been compromised? Better write an email. Better find a channel to send that email, and wait for it to be sent" could very, very obviously take a couple of days. You are unfairly trivialising that.
- Dolores12 10y agoMy point was transactional emails does not hit any spam filters. And since email services tracks how many of emails were opened, i am pretty sure 'we have been hacked' will be opened quite often and will never be in spam folder.
- quicksilver03 10y agoFrom the point of view of a spam filter, there isn't really any difference between a "transactional" (what a horrible name, but not your fault that the industry has adopted it) email and any other email. "Transactional" emails simply have some distinctive elements, such as the first and last name of the customer, which make them less likely to be filtered out.