TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

UserVoice Security Incident Notification

8 pointsby RossPabout 9 years ago

3 comments

tempestnabout 9 years ago
Another thread on the incident report here: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=11664713" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=11664713</a> <a href="https:&#x2F;&#x2F;status.uservoice.com&#x2F;incidents&#x2F;fb7ml8b3nphf" rel="nofollow">https:&#x2F;&#x2F;status.uservoice.com&#x2F;incidents&#x2F;fb7ml8b3nphf</a><p>There&#x27;s a bit more info in this one about exactly what was compromised though. While I can understand the abundance of caution in resetting passwords despite only hashes and salts being lost, it is odd that they would &quot;[presume] the attackers may be able to decrypt the passwords,&quot; assuming they&#x27;re using strong encryption.
评论 #11665153 未加载
RossPabout 9 years ago
&quot;In late April, the UserVoice security team learned that an unauthorized party illegally accessed one of UserVoice’s backend reporting systems and was able to view user data on a small subset of users. The user data includes name, email, and a hashed password and salt. Unfortunately, the passwords were hashed with the SHA1 hashing algorithm, which by today’s standards is considered weak. As such, we’re resetting the passwords for all users in our database.&quot;<p>Further information: <a href="https:&#x2F;&#x2F;status.uservoice.com&#x2F;incidents&#x2F;fb7ml8b3nphf" rel="nofollow">https:&#x2F;&#x2F;status.uservoice.com&#x2F;incidents&#x2F;fb7ml8b3nphf</a>
nacsabout 9 years ago
Just got an email from Uservoice about this.<p>Apparently I&#x27;m part of the &quot;0.001%&quot; that was affected in the breach.
评论 #11665217 未加载
评论 #11664777 未加载