TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Notice of Data Breach

239 pointsby uoflcards22about 7 years ago

34 comments

komali2about 7 years ago
Somebody is about to come across 250 pictures of me in my boxers standing in front of a dirty mirror with my belly popping out. I only hope they don't judge me for the size of my belly not really changing over those 250 days...
评论 #16714574 未加载
评论 #16712144 未加载
评论 #16711954 未加载
tragicabout 7 years ago
&gt; The affected data did not include government-issued identifiers, such as Social Security numbers and driver’s license numbers, information that the <i>app does not collect from users</i><p>Well, I suppose it wouldn&#x27;t, would it? Is this supposed to be impressive?<p>How many more of these before serious legislation gets through?
评论 #16711534 未加载
评论 #16711389 未加载
评论 #16711138 未加载
评论 #16711154 未加载
评论 #16713287 未加载
评论 #16711577 未加载
评论 #16711133 未加载
Someone1234about 7 years ago
That&#x27;s unfortunate.<p>At least we didn&#x27;t get the stereotypical &quot;your passwords are hashed, so nothing to worry about&quot; one liner I&#x27;ve been reading from a lot of companies during disclosures. All they said here is that the passwords are hashed and with a reasonably secure method -- bcrypt (although without knowing work-factor and percentage of passwords, it is hard to know just how strongly).<p>It has become pretty difficult to operate online these days without password managers. Password reuse has become a massive problem that worsens with each breach at a popular service. With a password manager you can just rotate the randomly generated password since you likely didn&#x27;t know your old one anyway.<p>Off Topic: I&#x27;m surprised nobody makes a hardware &quot;pepper&quot;[0] that supports popular algorithms. Meaning you hash the password as you normally would (inc. salt) and then send it through the pepper-ing device for another round before storing it. That way even if someone stole the database, knew the salt, and the hashing algorithm+work-factor, they&#x27;d still lack the hardware pepper making their job significantly harder.<p>[0] <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Pepper_(cryptography)" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Pepper_(cryptography)</a>
评论 #16712006 未加载
评论 #16712649 未加载
评论 #16713824 未加载
评论 #16712336 未加载
propmanabout 7 years ago
Should be a fine every time this happens and a major fine if it was found due to negligence or not having the appropriate security measures aka yahoo. Yahoo leadership new they were understaffed, cut staffing anyways, got rid of any executive who disagreed, and got no penalty for their mistakes.<p>Make it more costly to get fined than it is to get hacked. Or some white collar jail time if it wss negligence or covering it up.
评论 #16712433 未加载
JimDabellabout 7 years ago
The MyFitnessPal database has been compromised for <i>years</i>. I register with a unique email address for every website and app that I use so that I can tell when somebody&#x27;s database gets compromised or they sell my data. I started getting an influx of spam to my MyFitnessPal email years ago. I told them about it at the time but they didn&#x27;t care.
评论 #16714803 未加载
评论 #16715950 未加载
masslessnessabout 7 years ago
Imagine this happening in any other industry.<p>&quot;Oh hi users, the things you gave to us and we were supposed to keep safe, well, someone came and took them.&quot;<p>Say the bank sent all their customers a similar message, how would their customers be expected to react? Why is it any different in the tech industry?<p>Basically these apology messages amount to: &quot;Someone accessed your private stuff, please change the special key you use to access your stuff. End.&quot;<p>Should there be more to this than just that? Yes you&#x27;ll make sure the locks are stronger, but what about that thing I&#x27;ve now lost? What are you going to do about that?
评论 #16715117 未加载
BadassFractalabout 7 years ago
I wonder if the daily progress photos were leaked as well. I imagine most people won&#x27;t be thrilled to have their not-too-flattering progress selfies be out in public for the whole world to see.<p>Side note: MyFitnessPal the app is awful, but many of us still use it because it has the most extensive database of food products out there. Outside of that it has no merit and has felt abandoned in forever. Can someone recommend an actually superior alternative?
评论 #16712007 未加载
评论 #16711416 未加载
jnsaff2about 7 years ago
No info either way about whether peoples very personal fitness data was breached, eating habits, weight, other measurements. Appaling PR speak.
评论 #16711233 未加载
bhoustonabout 7 years ago
MyFitnessPal was horribly written app when I used it. The idea was good but God was it slow as hell when doing simple things.
评论 #16712076 未加载
评论 #16711641 未加载
评论 #16711347 未加载
评论 #16711447 未加载
评论 #16711554 未加载
matt_wulfeckabout 7 years ago
&gt; <i>The affected information included usernames, email addresses, and hashed passwords - the majority with the hashing function called bcrypt used to secure passwords.</i><p>I really appreciate them including this information. It shows they’re following best practices and I don’t need to read the rest of the article with a grain of salt.
评论 #16712554 未加载
iambenabout 7 years ago
No notification via email or app for me as of yet... Seems like the sort of thing I should hear from them first, rather than the Baltimore Sun.
评论 #16711317 未加载
评论 #16712353 未加载
internobodyabout 7 years ago
Perhaps this will also prompt them to start using HTTPS as well?
评论 #16711268 未加载
antonkmabout 7 years ago
This is how transparent an organization should be when breached. Kudos to Under Armour.
评论 #16711420 未加载
评论 #16712469 未加载
laniusabout 7 years ago
Any free MyFitnessPal alternatives with an open API for retrieving diet&#x2F;exercise activity?
评论 #16711978 未加载
PuffinBlueabout 7 years ago
Signed up to MFP yesterday to test it out. Immediately noticed they don&#x27;t use https (though the login forms appear to be submitted over https).<p>I thought to myself - on the face of it they don&#x27;t seem to hot on security, I wonder how long it will be before they get hacked or something?<p>Well, I wasn&#x27;t expecting less than 24 hours.
greggariousabout 7 years ago
This breach notification is very mealy mouthed.<p>&gt;The affected information included usernames, email addresses, and hashed passwords<p>It <i>included</i> usernames, emails, and hashed passwords? So what else was breached? This seems like they are implying nothing serious was stolen without giving specific info.
评论 #16717649 未加载
mvpuabout 7 years ago
&quot;On March 25, 2018, we became aware that during February of this year an unauthorized party acquired data associated with MyFitnessPal user accounts&quot; =&gt; highly likely they stole more than what MFP thinks they stole.. we don&#x27;t know what we don&#x27;t know. Sigh.
loegabout 7 years ago
Ah, I had an account here. Checked Lastpass, and, great! They&#x27;ve got my six character don&#x27;t-care-about-MyFitnessPal-security password. bcrypt will not save its secrecy in any way, but it hardly matters.
评论 #16711764 未加载
daniel_iversenabout 7 years ago
Props for them doing the right thing and hopefully nothing bad comes out of it - looks like they’ve built a useful product. One thing that’s odd to me on many levels though is that it was their Chief Digital Officer signing the announcement and not their head of security. Don’t they have one? Wasn’t this severe enough? I know it’s just perception but still!
Dzidasabout 7 years ago
I wonder, can I get a dump of the data collected on me based on the European Law? Similar, that Facebook provides to everyone.
评论 #16716316 未加载
llccbbabout 7 years ago
Does anyone have a good offline FOSS for macro-nutrient lookup and tracking? Been thinking about starting one for myself.
评论 #16711508 未加载
avivabout 7 years ago
People are so numb to these data breaches, companies will soon report such breaches just for the free press they get.
konceptzabout 7 years ago
The next thing people will check may be insider trading: <a href="https:&#x2F;&#x2F;www.nasdaq.com&#x2F;symbol&#x2F;ua&#x2F;insider-trades" rel="nofollow">https:&#x2F;&#x2F;www.nasdaq.com&#x2F;symbol&#x2F;ua&#x2F;insider-trades</a><p>Can anyone more versed in this do a quick look for abnormal behavior?
urlgreyabout 7 years ago
The breach notice indicates that hashed passwords were compromised but doesn&#x27;t mention whether a salt was used when computing the hashes.<p>Use of a salt makes all the difference, guarding against the use of rainbow tables to look up precomputed hashes of common passwords.
评论 #16711834 未加载
dvcrnabout 7 years ago
Tried to change my password just now but can&#x27;t. Clicking on &#x27;change password&#x27; logs me out again, anyone else?
djflutt3rshyabout 7 years ago
Announcing it after markets close and right before a long weekend (markets are closed on Good Friday). Classy.
tomcooksabout 7 years ago
I assume it&#x27;s a bigger problem for females, because of the different way society perceives female or male sexuality.<p>E.g. I don&#x27;t think i would really care about pics of my dick being made public, but plenty of women get routinely harrassed (often to the point of sexual assault or suicide) because of sexy selfies some idiot shared with friends.
oculusthriftabout 7 years ago
hm anyone know if they are salted as well?
colemannugentabout 7 years ago
Mods, there&#x27;s a better article on Reuters: <a href="https:&#x2F;&#x2F;www.reuters.com&#x2F;article&#x2F;us-under-armour-databreach&#x2F;under-armour-discloses-breach-of-150-million-myfitnesspal-user-accounts-idUSKBN1H532W" rel="nofollow">https:&#x2F;&#x2F;www.reuters.com&#x2F;article&#x2F;us-under-armour-databreach&#x2F;u...</a>
评论 #16714641 未加载
coroboabout 7 years ago
Official release <a href="https:&#x2F;&#x2F;content.myfitnesspal.com&#x2F;security-information&#x2F;notice.html" rel="nofollow">https:&#x2F;&#x2F;content.myfitnesspal.com&#x2F;security-information&#x2F;notice...</a>
评论 #16711391 未加载
getsugablitz2about 7 years ago
I use my Facebook as the login mechanism for MyFitnessPal, I wonder if that means my Facebook password has been stolen as well.<p>Better change it, sigh...
评论 #16711171 未加载
评论 #16711169 未加载
评论 #16711402 未加载
arcbyteabout 7 years ago
Should we actually care? I really didn&#x27;t care even when my OPM info got hacked. Just make this shit public and stop believing in secrets.
评论 #16714544 未加载
graystevensabout 7 years ago
Would be interesting to know how they identified the breach. It is exactly these situations that I produced Breach Insider[0], in the hope to try and reduce the time to detection down from months to days.<p>Those of you affected by this breach, have you noticed any unusual spam&#x2F;emails recently, that may be related to MFP? I’m wondering if they got the tip-off from their users.<p>[0] <a href="https:&#x2F;&#x2F;breachinsider.com" rel="nofollow">https:&#x2F;&#x2F;breachinsider.com</a>
mfp001about 7 years ago
I received an email notification of the MyFitnessPal breach. I don&#x27;t use that package or any other related products or service. Should I be concerned.