Latest in Gear

Image credit:

Disqus reveals it suffered a security breach in 2012

Hackers stole email addresses, as well as hashed password data for some users.
Richard Lawler, @Rjcc
October 6, 2017
Share
Tweet
Share

Sponsored Links

fotomay via Getty Images

Another day, another security breach (and another, and another...). This time it's Disqus, which is revealing that in 2012 -- around the time when Engadget used Disqus for comments -- hackers made off with some of its data, covering a snapshot of usernames and associated email addresses dating back to 2007, as well as "sign-up dates, and last login dates in plain text for 17.5mm [sic] users." More distressing is news that it also coughed up passwords for a third of those accounts, which were in hashed (SHA1) form but it's possible the attackers could have decrypted them.

According to Disqus, it learned of the leak Thursday evening after Troy Hunt of Have I Been Pwned notified obtained a copy of the site's information and informed the company. Within about 24 hours, it has disclosed the breach, started to contact users and forced password resets for affected accounts.

Within the last day, Hunt has also added databases for breaches from Bit.ly and Kickstarter to his site, and he says he has three more to go. HIBP is a free service that collects the databases of account information stolen by hackers and will let you know if your information is among those affected -- signing up is probably a good idea.

If you have an account with one of the services that have been pwned, then besides needing to reset your password there, you could have a problem if a password is shared across accounts on other websites. If you've reused a password elsewhere, then it's time to change it everywhere, which is why a password manager (like LastPass or 1Password) to create and manage unique keys is a good idea, as well as enabling two-factor authentication wherever you can.

All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission.
Comment
Comments
Share
Tweet
Share

Popular on Engadget

Presenting the Best of CES 2021 winners!

Presenting the Best of CES 2021 winners!

View
Bloomberg: 'Cyberpunk 2077' full development didn't start until 2016

Bloomberg: 'Cyberpunk 2077' full development didn't start until 2016

View
Canon made a site that lets you 'take photos' from a real satellite

Canon made a site that lets you 'take photos' from a real satellite

View
Philips Hue module turns any light switch into a smart switch

Philips Hue module turns any light switch into a smart switch

View
The next iPhone might have an in-screen fingerprint scanner

The next iPhone might have an in-screen fingerprint scanner

View

From around the web

Page 1Page 1ear iconeye iconFill 23text filevr