13 ms·
Tuts+ Premium Account Security Compromised
- krambs 14y agoCleartext!
- bluetidepro 14y agoThis is ridiculous. In the email I received from Envato it says the following: "-- What To Do (1) Update passwords on ANY service you use that uses the same password as you had on Tuts+ Premium. (2) In particular you should consider your own email account, PayPal, Moneybookers, and other payment services. These are the most sensitive targets, and if you had the same password, you should consider this an urgent priority. If you can’t remember what your Tuts+ Premium password was, we encourage you to change passwords on all services you use. (3) If you use the same password on any other Envato service such as the Envato Marketplaces, you should change your password there too." You have to be kidding me? Do I really need to start using unique passwords on every site that I use? This just blows me away that one site messes up and then I have to spend hours of my time figuring out which passwords to change, update, etc. This just frustrates me so much. I'm also very surprised they put this in the blog post: "As a company that teaches and preaches best practices, it’s deeply disappointing to me to not only have been the victim of a security attack, but to be running software that doesn’t follow those same best practices. This is a situation we will be working to address." ...Based on what has happened to LinkedIn and others, aren't they easily setting themselves up for a lawsuit by blatantly saying they did not follow best practices? Ugh. I'm just very sick of this crap happening. /rant
- anons2011 14y ago>You have to be kidding me? Do I really need to start using unique passwords on every site that I use? Errr, ...yes!
- bluetidepro 14y agoI already do to an extent but come on, you can't tell me you use a completely unique password for EACH of the HUNDREDS of sites that use passwords? That just seems ridiculous, or maybe it's just me...
- lparry 14y ago1Password (https://agilebits.com/onepassword https://agilebits.com/onepassword) is your friend
- Wilya 14y agoThere are quite a few ways to automate that. Lastpass, Keepass, KeepassX, 1Password, ...
- pault 14y agoSalt the password with characters from the url. Maybe your password is P4ssw0rd, so your HN password is Py4csosw0rd. I've been using this scheme for years, works great!
- kristofferR 14y agoGet LastPass (it's free and totally safe since it's client-side encrypted), but if you don't want that you can just use SuperGenPass. http://lastpass.com/ http://lastpass.com/ http://supergenpass.com/ http://supergenpass.com/
- DannoHung 14y agoPay for Lastpass. They're fucking awesome. Wish they'd add a system for private/public key storage though.
- dredmorbius 14y ago
- blissofbeing 14y agoI'll never visit an envato site again, let alone pay for any of their services. I can understand everyone gets hacked, but cleartext! wtf.
- charliesome 14y agoFrom the article: Tuts+ Premium is the only Envato service that operates with cleartext passwords, and it was a known internal issue for us, with a plan currently in progress to upgrade away from the current plugin.
- pwny 14y agoStill, this not being priority number one for them (before even making this service public!) means I will never do business with them. It says a lot about how they value their customers.
- bluetidepro 14y ago"plan currently in progress" - A bit late, don't you think?
- whichdan 14y agoThe sad thing is, it's completely trivial and non-disruptive to switch to from a cleartext database to a hashed+salted one.
- Xylakant 14y agoNot if you depend on a software that requires plaintext passwords (as they obviously do). Whether it's a wise choice using such a software is open to discussion though.
- 16s 14y agoSometimes business/marketing managers and IT security managers disagree. Looks as though the business guys trumped the security guys on this one. That happens a lot in the real world.
- pwny 14y agoStill storing clear text passwords in 2012, how the hell do these people have businesses? I mean, I learned about this stuff at age 12 while learning PHP on my own, how hard can it be? Getting hacked happens, even to the best but come on, how many times will we have to read blog posts like this one before people wake up? How hard can it be to hash and salt your passwords? Glad I wasn't one of their customers (and never will be) but it's frustrating how we can't trust anyone with anything these days.
- stef25 14y agoAnd it's a company that teaches web development ...
- mnicole 14y agoSerious question; all of these tutorial sites.. are any of them a reliable source for web dev or are they just another Smashing Magazine where people get paid to write about things they don't understand?
- stef25 14y agoHonestly I don't think their tutorials are half bad and I enjoy reading Smashing Magazine. Mainly for fluffy stuff. For security & scaling stuff go elsewhere.
- mnicole 14y agoI guess half-bad is subjective. I don't feel like a site that allows such a vast array of decent information vs. downright terrible/wrong is worth my time trying to decipher between the two. I know what I read on A List Apart is quality material from quality writers and people who have spent years and years in the field. Tommy the 17 year old graphic designer that only has mom-and-pop Wordpresses under his belt shouldn't be getting paid to tell thousands of people what's hot right now.
- ineedtosleep 14y ago
- highpixels 14y agoAs a regular author for Tuts+ I am absolutely FUMING with them.
- Dexec 14y agohttp://net.tutsplus.com/tutorials/php/understanding-hash-functions-and-keeping-passwords-safe/ http://net.tutsplus.com/tutorials/php/understanding-hash-fun...
- pwny 14y agoOh the sweet, sweet irony.
- yashchandra 14y agoI wish I could upvote this one forever. lol
- jgrahamc 14y agoWe should start a new award for web sites with crap password security. Let's name it after Robert Morris (Senior) who essentially inventing password hashing. A Morris Award would be a bit like a Darwin Award for people who've failed to learn anything about password security and in doing so have been exposed. Recent Morris Award winners: LinkedIn, last.fm, eHarmony, Tuts+, ...
- pwny 14y agoI feel weekend project potential here!
- creativityhurts 14y agoMore potential "winners" are here http://plaintextoffenders.com/ http://plaintextoffenders.com/
- nulluk 14y agoI have talked about & mentioned something similar before but bundeling the whole thing into a browser extension. Every site you hit gets checked against a local list thats periodically updated. It throws up an information bar with bad security practices associated with the site you are browsing, everything from mailing plaintext password to the idiotic things like above. If it becomes trusted enough it might move some developers/organisations to actually take action, if not it will at least warn individuals of the obvious problems before they signup and not afterwards like at the moment. Edit: Last sentence didn't make sense.
- yock 14y agoAnother criteria, perhaps... My wife loves to use Big Oven to find recipe ideas. I thought I'd also start using it so we could share those ideas more easily. When they rejected my password for having "invalid special characters" however...
- flyswatter 14y agoI think for impact there should be one grand winner each year. Otherwise there will soon be too many to count I'm afraid. Maybe also an award for most silly password policy?
- statictype 14y agoI like how they blamed it on a "3rd party plugin".
- deleted 14y ago[deleted]
- vitomd 14y ago"Our current Tuts+ Premium app makes use of a third party plugin that unfortunately stores passwords in cleartext (i.e. unencrypted)" That make me sad. If you use a plugin, you use it because it's a better and a proven solution , not because you are lazy. Sad day..
- polysaturate 14y agoIf you're going to store passwords in clear text... You're gonna have a bad time.
- stef25 14y agoAccording to some comments the plugin in question is "amember" but there are several (old) posts on their forums say they don't use plaintext. I'd be surprised if it was, but then again ... http://www.amember.com/forum/threads/db-password-encryption-w-vbulletin.14466/ http://www.amember.com/forum/threads/db-password-encryption-... http://www.amember.com/forum/threads/password-on-resend-sign-up-info-is-encrypted.14218/ http://www.amember.com/forum/threads/password-on-resend-sign...
- Xylakant 14y agoPosts are from spring this year, so it's not "old". The first post also references an upgrade from version 3 to version 4, so I guess they still use version 3 and didn't get around to updating to v4 yet, and now they pay the price.
- dutchbrit 14y agoCleartext? Are you kidding me? I actually have an account there, sorry Envato but you just lost a customer.
- yashchandra 14y agoIt is high time a site's registration form/process has a confirmation box confirming that they do not store passwords unencrypted before the user clicks "sign me up". This is getting ridiculous. I unfortunately used another site recently that sent me my password back in clear text over email.
- beezee 14y agoWhat is really absurd is they've gone offline and given people no way to confirm their password. Their suggestion: "If you can’t remember what your Tuts+ Premium password was, we encourage you to change passwords on all services you use" All I need is to try a handful of "important" passwords, make sure that none of them work for this compromised service, and I can go on with my day. But they figure, hey, if you can't remember our password, go change them all, not our problem. Real brilliant way to handle it.
- matdes 14y agoI alerted them to the fact that their passwords were in plaintext a YEAR AGO. I got a response email on June 29, 2011 saying: "Thanks for reporting the issue of plain text passwords to us. It's how passwords are handled with the membership software we use for Tuts+ Premium, which isn't extremely well coded and something we want to rebuild from scratch. In the mean-time our dev team will be hacking the software to bring password security up to the best practices we advocate on our Tuts+ sites, like Nettuts+." Not only was this issue brought up to them, they stated very clearly that they were working to bring their password security up to best practices. In a YEAR, they couldn't hack on a password hash or rebuild their plugin from scratch? If anyone knows if there is a lawsuit pending that could use my email as evidence, please let me know.
- dutchbrit 14y agoMy email to Envato: I seriously can't understand how Envato found it responsible to even implement something that saves plaintext passwords. You must of known when inplementing it. If this "3rd party" plugin was so important, then implement the plugin later on when it is secure - you don't fuck around with private details. If it was important for the initial release, you shouldn't of launched until this was sorted. You have hereby lost a customer. I now have to reset my password on a ton of forums and probably also themeforest. I will give you some other feedback. Maybe I'm blind but to login on Nettuts, don't make users have to scroll and look for a dinky login text. On ThemeForest, seriously remove the fucking Captcha from the login form. Sorry for my French but seriously, on a contact or registration form, I could understand why. If you are afraid of brute force, there are other great ways to do so. Fail, Sam Granger Ps. You should read your own tutorials on security, they aren't too bad.
- tedivm 14y agoWhy would you have to change your password on "a ton of forums" if you yourself have been using password best practices? Envato was responsible in their disclosure- you think those "tons" of forums are all going to do the same? For all you know your password has been in the wild for years. You should use this as an opportunity to get a password manager (Lastpass, for instance) and use unique passwords for each site.
- dutchbrit 14y agoI agree that it's my fault not having a unique password for Envato, I do have unique passwords for most important things, but to have unique weird passwords for everything is too much for me, especially since I'm switching computers all the time, it'd be quite a hassle each time. Especially since I log into a lot of less important sites with this password. If it was a salted and encrypted, I wouldn't bother changing them. But seriously, plaintext. It's the biggest cockup I can imagine. Some may argue, but you can also keep passwords on your phone or online, you're correct, but what if my pass phrase gets hacked to all my unique passwords? How do I know that these services are waterproof? It's not the most secure way of storing passwords either to be honest, but they don't have any other way. It has to be decryptable. In the end, nothing is waterproof.
- mschalle 14y agoPlain text? Are you KIDDING me?!
- 727374 14y agoWhat really irks me are the weak excuses in that blog entry. I don't care that it was a 3rd party plugin or that you wanted to encrypt the passwords. You screwed up and endangered your users.