4 ms·
> The stolen data contained names, email addresses, scrambled password (believed to be hashed with the MD5 algorithm and salted), and other profile information
by hacker_9 7y ago
> The stolen data contained names, email addresses, scrambled password (believed to be hashed with the MD5 algorithm and salted), and other profile information — such as shoe size and trading currency. The data also included the user’s device type, such as Android or iPhone, and the software version.
The serious tone of this article made me double check if this was April 1st when I read this paragraph. The stolen data is shoe sizes? MD5 hashing for passwords isn't ideal, especially combined with email addresses - that could lead to some email accounts being accessed if people use the same password for everything. The article seems to not really give much attention to this though, not clear if the author even realises this is the main problem.
- TeMPOraL 7y ago> The stolen data is shoe sizes? StockX is a platform for trading shoes, among other things.
- perl4ever 7y agoI never heard of them before, so I checked Wikipedia and read this: "The platform works by buyers undercutting each other in a fashion similar to the stock market, eventually causing limited items to lose all value. " Can someone elucidate how this is like the stock market, because I don't get it.
- SkyPuncher 7y agoWikipedia gives a terrible description. It's basically eBay, but focused specifically on limited release/high value fashion - sneakers, bags, streetwear, eatches, etc. Since the market rate for these items changes over time, the gimick (hence the name) is to track them like stocks. Stockx basically facilitates the sale and exchange of items, taking a cut of the sale and verifying the integrity of the items.
- anon4242 7y agoWell, every data helps if you're trying some targeted hacking. If the username is LebronJames and the shoe size is 9, it's not the right Lebron...
- adrr 7y agoWe need to start charging companies with criminal negligence if they are not using secure password hashing algorithms. People reuse passwords and this leak puts other companies at risk.
- sieabahlpark 7y agoYou can't sue a company for your own bad security practices.
- whatshisface 7y agoThat would be a civil case prosecuted by the other companies, not a criminal case.
- kokowawa393 7y agoIt should be criminal.
- alasdair_ 7y agoPeople that re-use passwords should be considered negligent. There is no reason to do so for anything but the most trivial logins.
- gruez 7y agoGood luck proving that a "reasonable person" shouldn't have done it. Most people on HN probably do, but I wouldn't be surprised if everyone coming out of a 3 month coding bootcamp only knew to hash passwords and nothing else. The other comments in this thread seems to suggest that the company is filled with bootcamp programmers.
- shakna 7y agoAs a government body actually publishes advice on this, NIST [0], it may well be possible to argue for what is reasonable in a court of law. [0] https://csrc.nist.gov/projects/hash-functions/nist-policy-on-hash-functions https://csrc.nist.gov/projects/hash-functions/nist-policy-on...
- youeseh 7y agoAuthor might be a young intern writer.
- youeseh 7y agoMy bad. He isn't. I suppose this was a 'strictly news' piece. Separate analysis coming soon.