TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Zappos.com customer database compromised

199 pointsby clamstarover 13 years ago

12 comments

IgorPartolaover 13 years ago
LastPass FTW! The attacker will reverse my password just to find a bunch of unusable bits :). What would be even cooler is an API on top of LastPass that sites like Zappos could hook into to force a behind-the-scenes change of passwords, similar to revoking a compromised certificate. Essentially, since there is some lead time after the breach is discovered and before the attacker manages to crack the long, random passwords, their efforts would be futile by the time they are done since all LastPass passwords would have already been changed.<p>Or we could just stop using passwords everywhere and not have this problem again. Anybody? Anybody?<p>Disclosure: I have no affiliation with LastPass beyond being a satisfied user.
评论 #3470477 未加载
评论 #3469215 未加载
评论 #3469305 未加载
评论 #3469438 未加载
jjacobsonover 13 years ago
Zappos developer here. I'll answer any questions that I legally can or help get customer problems passed onto people that can help.
评论 #3469127 未加载
评论 #3469251 未加载
评论 #3469588 未加载
评论 #3469139 未加载
评论 #3469116 未加载
评论 #3472325 未加载
评论 #3469539 未加载
评论 #3471321 未加载
评论 #3469465 未加载
评论 #3469202 未加载
评论 #3471227 未加载
评论 #3469314 未加载
评论 #3469494 未加载
skrishover 13 years ago
+1 for not storing clear text passwords.<p>I like the tone of the blog &#38; how forthright they have been with dealing with the issue.
评论 #3469478 未加载
评论 #3469158 未加载
评论 #3469164 未加载
评论 #3471066 未加载
Wilyaover 13 years ago
Page gives me : "We are so sorry – we are currently not accepting international traffic. If you have any questions please email us at help@zappos.com"<p>Anyone could paste/screenshot/... what there is to see ?
评论 #3469020 未加载
评论 #3469717 未加载
davepeckover 13 years ago
So: "cryptographically scrambled" -- do we believe they use a good hash, and salt? Or... not?
afortyover 13 years ago
I didn't get this notice so that means my information wasn't compromised? Wouldn't bet on it.
评论 #3469445 未加载
评论 #3469034 未加载
imjoelover 13 years ago
Zappos sister site 6pm.com was compromised, too.
评论 #3469439 未加载
vnchrover 13 years ago
My thanks to Zappos for that email. It was enough for me to give my wife necessary suggestions to secure her associated accounts without alarming her.<p>It is probably worthwhile in these situations to provide basic implication info for laymen, i.e. implications of "your cryptographically scrambled password."
leakover 13 years ago
I've been having issues with Zappos for a couple days. I called up support yesterday and they said they were "upgrading the website and had bugs they were trying to get fixed." Not sure if this is related or just a coincidence.
评论 #3469150 未加载
hummerover 13 years ago
Good thing they didn't store passwords in clear-text!
评论 #3469257 未加载
评论 #3470124 未加载
alexlitovover 13 years ago
I didn't get an email, but upon logging in - my password was reset and an email sent with further instructions.
desigoonerover 13 years ago
FWIW, I just got a similar email from 6pm.com (It's a Zappos Affiliate) ..