8 ms·
Zappos.com customer database compromised
- aforty 15y agoI didn't get this notice so that means my information wasn't compromised? Wouldn't bet on it.
- jesseendahl 15y agoI didn't receive the email yet either. Hmm... just changed my password just in case.
- dylanbathurst 15y agoYeah, I think they're sending the email out in separate blasts. This is one email they don't want ISPs blocking IPs on because it looks like spam.
- syneater 15y agoAs a rule, anytime something like this happens, you should change your password (and any other place you use the same password or a variation of it). That being said, we are bursting the emails (as I believe Dylan commented already). Spam filters being what they are, it's possible it may be in there, so I would suggest you change your password.
- Wilya 15y agoPage gives me : "We are so sorry – we are currently not accepting international traffic. If you have any questions please email us at help@zappos.com" Anyone could paste/screenshot/... what there is to see ?
- clamstar 15y agoSubject: Information on the Zappos.com site - please create a new password First, the bad news: We are writing to let you know that there may have been illegal and unauthorized access to some of your customer account information on Zappos.com, including one or more of the following: your name, e-mailaddress, billing and shipping addresses, phone number, the last four digits of your credit card number (the standard information you find on receipts), and/or your cryptographically scrambled password (but not your actual password). THE BETTER NEWS: The database that stores your critical credit card and other payment data was NOT affected or accessed. SECURITY PRECAUTIONS: For your protection and to prevent unauthorized access, we have expired and reset your password so you can create a new password. Please follow the instructions below to create a new password. We also recommend that you change your password on any other web site where you use the same or a similar password. As always, please remember that Zappos.com will never ask you for personal or account information in an e-mail. Please exercise caution if you receive any emails or phone calls that ask for personal information or direct you to a web site where you are asked to provide personal information. PLEASE CREATE A NEW PASSWORD: We have expired and reset your password so you can create a new password. Please create a new password by visiting Zappos.com and clicking on the "Create a New Password" link in the upper right corner of the web site and follow the steps from there. We sincerely apologize for any inconvenience this may cause. If you have any additional questions about this process, please email us at passwordchange@zappos.com
- kalyanganjam 15y agoYou can check the URL http://viewtext.org/article?url=http://www.zappos.com/passwordchange http://viewtext.org/article?url=http://www.zappos.com/passwo... in case content changes/updates in that page.
- Loic 15y agoAdding the one really interesting, that, the way they communicate in house: http://viewtext.org/article?url=http://blogs.zappos.com/securityemail http://viewtext.org/article?url=http://blogs.zappos.com/secu...
- alexlitov 15y agoI didn't get an email, but upon logging in - my password was reset and an email sent with further instructions.
- leak 15y agoI've been having issues with Zappos for a couple days. I called up support yesterday and they said they were "upgrading the website and had bugs they were trying to get fixed." Not sure if this is related or just a coincidence.
- pkteison 15y agoProbably coincidence. Companies that expect a lot of Christmas traffic minimize changes from Thanksgiving to Christmas, and web retail gets more traffic during business hours in America, so I expect that this weekend and last weekend saw a lot of code deployments, and so things are more likely to be broken specifically right now than pretty much any other time of the year.
- hummer 15y agoGood thing they didn't store passwords in clear-text!
- getsat 15y agoThat doesn't mean they're not using a bad (i.e., fast) hashing algorithm.
- wahnfrieden 15y agoOr that they're not using reversible encryption.
- nikcub 15y agoa lot of poor hash/encryption implementations are close enough to plaintext.
- desigooner 15y agoFWIW, I just got a similar email from 6pm.com (It's a Zappos Affiliate) ..
- imjoel 15y agoZappos sister site 6pm.com was compromised, too.
- syneater 15y agoCorrection, it was not a separate compromise, they share the same database (since they share the same stock, etc.)
- davepeck 15y agoSo: "cryptographically scrambled" -- do we believe they use a good hash, and salt? Or... not?
- jjacobson 15y agoZappos developer here. I'll answer any questions that I legally can or help get customer problems passed onto people that can help.
- paulv 15y agoHow was the compromise discovered?
- jjacobson 15y agono clue
- palish 15y agoWas the password hash generated using bcrypt?
- jjacobson 15y agoPlaintext passwords never touch our database. Expiring everyone's passwords was a security precaution given the fact that our non financial customer data was compromised in the first place. I can't comment on what lib or algorithm we use to encrypt our passwords since I don't work on that team.
- ikor 15y agoHi. I'm customer outside of US and I received the email, went to site to reset my password and "We are so sorry – we are currently not accepting international traffic" - WTF? (sorry, but there is your logic?)
- jjacobson 15y agoInternational traffic will be re-enabled in the near future.
- MichaelApproved 15y ago
- skrish 15y ago+1 for not storing clear text passwords. I like the tone of the blog & how forthright they have been with dealing with the issue.
- arnoldwh 15y agoAgree. So many companies don't act like grown-ups and just try to cover up the problem. Still, it's going to be pretty tough getting your average customer back who hears they've been "hacked" and are afraid to create a new password. Not to mention the average customer's password is probably the same password across facebook, gmail, etc.
- skrish 15y agoAbsolutely. The biggest risk is the shared password part. It is surprising people still do it. I am surprised that some of the big eCommerce companies still mail back the password in clear text. Just plain stupid.
- tomjen3 15y agoSharing passwords will end when I don't have to remember one for every random website ever.
- MartinCron 15y agoZappos is always a class act. I have about 3X the shoes I otherwise would have as a result of their customer service.
- conradev 15y ago> +1 for not storing clear text passwords. That shouldn't need a +1.
- csallen 15y agoIt shouldn't, but it's shocking how many companies don't encrypt passwords before storing them in the db.
- IgorPartola 15y agoLastPass FTW! The attacker will reverse my password just to find a bunch of unusable bits :). What would be even cooler is an API on top of LastPass that sites like Zappos could hook into to force a behind-the-scenes change of passwords, similar to revoking a compromised certificate. Essentially, since there is some lead time after the breach is discovered and before the attacker manages to crack the long, random passwords, their efforts would be futile by the time they are done since all LastPass passwords would have already been changed. Or we could just stop using passwords everywhere and not have this problem again. Anybody? Anybody? Disclosure: I have no affiliation with LastPass beyond being a satisfied user.
- Donald 15y ago> What would be even cooler is an API on top of LastPass that sites like Zappos could hook into to force a behind-the-scenes change of passwords How would Lastpass protect against an attacker masquerading as the third party website? (Especially considering this feature would be used when a website finds itself compromised.)
- IgorPartola 15y agoMaybe an API is an overkill in this case. Instead, a simple web service with a twist: Zappos has a private key and LastPass has the corresponding public key. Now, if Zappos.com is compromised and the breached is discovered and fixed, their CEO/CTO/head security guy grabs the private key and authenticates to LastPass, telling them that he is in fact who he says he is, and finally triggers the massive automatic password reset. Obviously, this will not work if the private key is compromised, but then again, our whole web security paradigm is "trust that the website owner knows what s/he is doing", so this is already a step up. Or, as I mentioned, let's do away with passwords. Anyone can have your public key so long as your private key stays private.
- tedivm 15y agoWell, lastpass doesn't store the passwords on its servers in a way that they could just change. From my understanding the database is only decrypted on the client machines when the master password is entered. Still, the idea of a service for handling this makes sense. Rather than one based on a single vendor, a simple API for querying compromised domains would handle it. Then the lastpass extension can call that api for a list of the user's domains and see if anything needs to be changed. Being more general (just giving out information about recently compromised sites) also seems more useful, in that people would do a lot of different things with it.
- vnchr 15y agoMy thanks to Zappos for that email. It was enough for me to give my wife necessary suggestions to secure her associated accounts without alarming her. It is probably worthwhile in these situations to provide basic implication info for laymen, i.e. implications of "your cryptographically scrambled password."