Showing posts with label Password. Show all posts
Showing posts with label Password. Show all posts

Thursday, May 5, 2011

Possible Security Breach At LastPass

Image representing LastPass as depicted in Cru...Users who manage and store their passwords through password management service LastPass are being forced to change their master passwords after the site noticed an issue this week that raised the spectre of a possible security breach.

LastPass wrote on their blog yesterday that because they can't account for the anomaly they detected in one of the databases, the company made the decision to assume the worst that some of its data had been hacked, even though they say you shouldn't be impacted by this issue if you have a strong, non-dictionary-based password.

LastPass hasn't identified a specific breach, it's erring on the site of caution by now forcing its members to change their master passwords.

LastPass let users create and manage passwords to more easily log in to the vast array of secure Web sites they visit.
Those passwords can be stored on a PC or mobile device as well as online. As one means of protection, LastPass typically urge users to create a single complex master password that can unlock the key to accessing their passwords.
Of course, if that master password is compromised, hackers potentially can gain access to all the individual passwords, one reason why these companies advise users to employ complex master passwords.

In the meantime, LastPass have moved services to other servers for now. They also compared the code on the live servers with code from their repositories to make sure it was not tampered with.
The company is also enhancing the encryption used to protect its data.

Wednesday, April 27, 2011

What You Need To Know Right Now About The Sony PSN Hack

Image representing Sony as depicted in CrunchBaseSony revealed  additional information, about the hack

name, address (city, state/province, zip or postal code), country, email address, birthdate, PlayStation Network/Qriocity passwords and login, handle/PSN online ID.

Note that the email addresses, logins and passwords also have been stolen from Sony

This is going to turn ugly considering that many users on the web use the same email and password combination on a lot of sites.

If you are a customer you need to immediately change your passwords on site where you may have used the same password, and your email account.

Furthermore Sony says that it is possible that profile data may have also been obtained, which would include purchase history and billing address. Worse, they cannot eliminate the possibility that created card data was taken as well.

That’s the worst case scenario, and there is not lot that users of the network can do at this time, but to actively monitor their credit card bills to check for unauthorized payments.

To protect against possible identity theft or other financial loss, remain vigilant to review your account statements and to monitor your credit or similar types of reports.

The data stolen could also be used in custom attacks as the attackers could use the user’s name and other information to make requests look legit.

Sony asks all users to change their PSN passwords as soon as the service goes online again.

A frequently asked questions section has been uploaded to the Playstation website which contains further information and support phone numbers.

With 70 million users, the data alone could be worth a fortune on the black market.



Final note:
1 - PSN users need to change their web account passwords immediately.
2 - You need to change the password of your email accounts if identical
3 - Monitor your credit card statements and account statements to make sure that no unauthorized payments are made from the accounts.