StolenPasswords

Latest

  • Dropbox two-step login verification available in experimental build, coming to all accounts soon

    by 
    Sean Buckley
    Sean Buckley
    08.27.2012

    Following up on its promise to tighten account security following a recent breach, Dropbox is now offering two-step login authentication to users who install the service's latest experimental desktop build. The team says the functionality will roll out to all users in the coming days, but listed full instructions to forum users who just can't wait. Those who op-in only need to download a new version of the Dropbox desktop software and activate the feature in their account settings. Once set up, Dropbox will require all unrecognized machines to provide a code, culled from an authenticator app or received via text message. The firm also provides an emergency back-up code that'll disable the feature should you lose your phone. Feeling insecure? Check out the source link below to get started. Update: Dropbox just made it official, detailing set up instructions once more on the Dropbox blog.

  • Blizzard suffers security breach, encrypted passwords and authenticator data compromised

    by 
    Sean Buckley
    Sean Buckley
    08.09.2012

    According to a recent Blizzard security update, now might be a good time cook up a new password. Blizzard's security team found that its internal network has been illegally accessed, and answers to personal security questions, authenticator data and cryptographically scrambled Battle.net passwords have found their way into the perpetrator's hands. The team is confident, however, that the compromised data isn't enough to give the attacker access to user accounts, and says that there is no evidence to suggest financial data (credit cards, billing addresses and customer names) were accessed. Blizzard President Mike Morhaine recommends that users update their passwords all the same, and we couldn't agree more. Check out his official statement at the source link below and get that Diablo III account locked down.

  • Dropbox confirms user info was stolen, adds new security measures

    by 
    Steve Dent
    Steve Dent
    08.01.2012

    Dropbox has admitted that spam reported by its users over the last few weeks was the direct result of a security breach. Both login names and passwords were stolen from an unstated number of users, including a Dropbox employee. That account contained a list of clients' email addresses, which is what the company believes led to the spam in the first place. In response, it has contacted those affected to protect their accounts and outlined several new security features. These include a two-factor authentication option coming in several weeks and a new automated feature that will check for suspicious activity. A new landing page will also show you any logins to your account, while Dropbox reheated that always-helpful advise to avoid reusing passwords on multiple websites -- noting that a breach on one site can cause an entire cascade of grief.

  • Microsoft Store hacked in India, passwords stored in plain text

    by 
    Sean Buckley
    Sean Buckley
    02.12.2012

    Frequenters of India's online Microsoft Store were briefly greeted with the suspicious visage of a Guy Fawkes mask this morning, following a hack that compromised the site's user database. According to WPSauce, Microsoft Store India's landing page was briefly taken over by a hacker group called Evil Shadow Team, who, in addition to putting a new face on Windows products, revealed that user passwords were saved in plain text. The group's motivations are unknown, though the hacked page warned that an "unsafe system will be baptized." The store is now offline, suggesting that Microsoft may have regained control. Read on for a look at the compromised password database.[Thanks to everyone who sent this in]