Latest in Gear

Image credit: fotomay via Getty Images

Disqus reveals it suffered a security breach in 2012

Hackers stole email addresses, as well as hashed password data for some users.
685 Shares
Share
Tweet
Share

Sponsored Links

fotomay via Getty Images

Another day, another security breach (and another, and another...). This time it's Disqus, which is revealing that in 2012 -- around the time when Engadget used Disqus for comments -- hackers made off with some of its data, covering a snapshot of usernames and associated email addresses dating back to 2007, as well as "sign-up dates, and last login dates in plain text for 17.5mm [sic] users." More distressing is news that it also coughed up passwords for a third of those accounts, which were in hashed (SHA1) form but it's possible the attackers could have decrypted them.

According to Disqus, it learned of the leak Thursday evening after Troy Hunt of Have I Been Pwned notified obtained a copy of the site's information and informed the company. Within about 24 hours, it has disclosed the breach, started to contact users and forced password resets for affected accounts.

Within the last day, Hunt has also added databases for breaches from Bit.ly and Kickstarter to his site, and he says he has three more to go. HIBP is a free service that collects the databases of account information stolen by hackers and will let you know if your information is among those affected -- signing up is probably a good idea.

If you have an account with one of the services that have been pwned, then besides needing to reset your password there, you could have a problem if a password is shared across accounts on other websites. If you've reused a password elsewhere, then it's time to change it everywhere, which is why a password manager (like LastPass or 1Password) to create and manage unique keys is a good idea, as well as enabling two-factor authentication wherever you can.

All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission.
Comment
Comments
Share
685 Shares
Share
Tweet
Share

Popular on Engadget

'Metro Exodus' and 'Gylt' are February's free Stadia Pro games

'Metro Exodus' and 'Gylt' are February's free Stadia Pro games

View
FDA clears algorithms that detect heart murmurs and AFib

FDA clears algorithms that detect heart murmurs and AFib

View
Get ready to eat bugs if you want to live beyond 2050

Get ready to eat bugs if you want to live beyond 2050

View
This may be Samsung's foldable Galaxy Z Flip

This may be Samsung's foldable Galaxy Z Flip

View
Cadillac will add automated lane changing to its Super Cruise system

Cadillac will add automated lane changing to its Super Cruise system

View

From around the web

Page 1Page 1ear iconeye iconFill 23text filevr