Weebly hacked, 43M credentials stolen
techcrunch.com
techcrunch.com
That said, how you respond in this situation can be just as important, and so we are making sure to be incredibly proactive in addressing the situation & transparent in how we communicate the details with our customers. Our top and immediate concern has been our users and the safety of their accounts.
A few days ago we became aware that an unauthorized party obtained email addresses/usernames, last login IP addresses and bcrypt hashed passwords for a large number of customers (anyone who signed up prior to March 1 of this year).
At this point we do not have evidence of any customer website/account being improperly accessed. It's also worth noting that we do not store any full credit card numbers on Weebly servers, so any credit card information was not part of this incident.
We immediately starting working on taking steps to notify our customers, and were able to get this out in a matter of a few days. We're initiating password resets as of this morning, and we've also made several improvements to the application including new password complexity requirements and a new dashboard that gives customers an overview of recent log-in history of their Weebly account to track account activity. We also increased our bcrypt work factor from 8 to 10, and all passwords will be automatically upgraded as of the next time a user logs in.
We've hired an incident response firm who is working with our internal team to complete a full investigation. In the meantime, we're examining our stack top to bottom and taking many steps to enhance our network and application security. This is an area we take very seriously and we'll be putting in tremendous effort to ensure this doesn't happen again.
There is virtually no company which discovers that it has been breached within a short period of time - the nature of a security breach is such that it doesn't generally become apparent until some time later. This pattern continually plays itself out with just about every large breach you can think of.
In that respect, considering Weebly actually hashed their passwords with bcrypt and is reacting to the breach in the same year, they're fairly far ahead of the curve on this one.
6 months is much better than the median :D
It is for everyone who used "weebly" or any of the top 100 most common passwords.
That could mean no less than 82% of users are at risk.
[1] me
as for brute force, yes attackers now know usernames, so can try brute forcing the live sites, or brute forcing each user hash.
Strong brute-force protection (eg block account for exponential times) could mitigate this attack vector.
The attackers have the salts and the hashes, they can brute force the hashes offline with [ocl]hashcat as they wish.
Top 100 passwords * 43M accounts is only ~4B hashes to compute. We don't know what bcrypt parameters they used but we're probably talking a few hours here, maybe only a few minutes.
you are right that it's now very easy to use dictionary attacks now, on all the credentials offline. and those with super weak passwords will have their accounts compromised.
No you have not because then this would not have happened. The only one who should be able to query passwords from the database should be the DBA. Everyone else should only be able to validate against it. So either it's an inside job by your DBA, or you thought your users security was less important then avoiding the friction such high security standards would have introduced in your workflow.
You can parameterize your queries until you're blue in the face, but that won't help you if the right employee is phished (for example). This is an inherently imperfect and chaotic world, and it's unrealistic to assume that you're insulated from these scenarios just because you locked down database access correctly.
Personally, I believe David when he says Weebly takes security very seriously.
First, while there is a recent uptick in breaches, newsworthy ones do not happen every month. There does appear to be something of a clustering effect, which I think is attributable to a number of different causes. [1]
Second, banks, even very large ones like Citigroup and Chase, have been compromised in recent memory. [2] Even the IRS suffered one of the largest breaches ever, just last year. Peripherally "financial" institutions that aren't banks have also suffered breaches, such as every single credit card processor and NASDAQ.
You have a right to be upset about the increasing probability of your passwords being compromised by third parties. As a consumer, you can mitigate the damage of such breaches by 1. using a password manager, 2. using a different password for each and every account you have and 3. generating extremely secure passwords for each account. You can also use services like HaveIBeenPwned [3] to stay ahead of the damage.
However, your indictment here is unreasonable. Like basically everyone else in this thread, you don't have much information to go on yet. Weebly properly hashed and stored their passwords. As far as breaches go, this one is pretty tame. They are reacting responsibly and quickly considering the breach happened this year - normally we'd find out about this in three years. We do not yet know the root cause of the attack, and the criticism you're levying against Weebly is equally applicable to the industries you believe are more safe (they aren't). While many "web 2.0" companies may be rather lax in security, Weebly did not do anything obviously wrong or negligent here.
________________________
1. As data breaches become more of a hot topic, they will be more likely to be reported widely because it guarantees eyeballs. Similarly, it increases scrutiny, which aids in discoverability, and leads to more copycat hackers attempting these breaches for fame or fortune.
Then breaches only reveal emails and a pair of hashes, so to control the account you need to control the email.
Banks get hacked. They just don't tell people about it. The difference is that banks aren't as transparent, not that they're more secure.
And let's not forget that there is a spectrum of value associated with information. On the one hand, I'd rather my bank details and payments weren't publicly released. On the other… IP address, bcrypted password and email address? Minimal relative value.
What was hacked was the bank where the messages were sent from.
https://www.bloomberg.com/news/articles/2016-05-26/swift-hac...
If you read the article (any of the articles) the headlines always talk about the 'swift hack' however it was the _banks_ that were hacked (and the article says so), not swift.
I accept there are costs to jumping the gun and passing out incomplete information, but if I screw up I tell the affected parties that day. Not after a few days of planning how to manage the message.
"Transactional" emails simply have some distinctive elements, such as the first and last name of the customer, which make them less likely to be filtered out.
So, there is obviously a difference in those metrics between simple notification 'your account have been hacked. change password' and 'hey, we haven't seen you for ages'. As email system notice high user involvement it will never ever block such emails. Actually, i think it will increase IP reputation.
This is - at least from a spam filter's perspective - a huge email broadcast, more akin to a news letter mailing or a spam run.
And semantics aside, a lot of those 43M users will consider the email to be unsolicited (didn't remember they signed up, don't care about computer security, etc). They will happily report such an email as spam, adding to the training set.
Sace meta like country and city about the ip and then store the adress unrecoverable. Generally no big eeasons to have the actual ip stiored.
Every day of the week and four times and Tuesday I'd prefer the team that spends their marginal dollar on finding the next marginal reflected XSS bug than the one that wastes it on "two-way encryption of email addresses".
I don't know what Weebly does for appsec (I've never worked with them and probably never will), but if they've spent even $50 on external appsec testing, they're 1000% better than 90% of rest of the applications we all use every day.
What about all those hacked servers that we don't know that are hacked yet?
There are ( and I'm pretty sure ) lots of hackers that do this on a daily basis, but don't try to do anything malicious on a large scale ( like dumping the whole db of customers, DDoS, etc. ). They probably target medium-large or small companies' servers, put a backdoor there and analyze. Either stealing some business secrets or leave it like that for one of the dark days when some political-corporate person will need their help.
Having the whole human knowledge on the palm of my hand made also our own lives public-knowledge.
Also in this instance, Weebly, they get an anonymous "hey look, I have all of your data".
So Weebly issues a statement to their customers to reset their passwords (which the hackers knew would be a byproduct) and unbeknownst to them the hackers are now skimming the new passwords off the network.
2nd thing is 2FA. I hope 2FA becomes the standard for all login. Even SMS. ( I know SMS is not save in US, but I am not sure if similar can be said in EU or Japan )
I was not at all shocked by this headline.
I don't want to just single out Weebly here as I discuss these sorts of things with people at different companies all over the bay out of personal interest and anything harder than using something like lastpass to reach production systems is considered too much work. Honestly Google and Facebook are the only large companies I have seen deploy fairly decent security practices out of the dozens I have exposure to. I credit this to the fact the employ teams people who have the specific job of continually auditing and enforcing all available security tools on their systems and fostering a culture that security is everyone's job.
You will pay for security either way. Either up front paying teams of capable people, or in lost customer trust after the fact.
Security apathy in the valley is a cancer impacting companies of all sizes. Sure you can't make anything perfectly secure, but you can at least force your attacker to burn a 0day. Don't make it as easy as spoofing an email and getting an employee to click a malicious link.
If you have any sort if privileged access to PII data of your customers and are not even doing basics like using hardware tokens to gate your server and db access you are one keykogger or XSS away from a serious breach. If you know how to set such things up and still don't do it, you are additionally a terrible person.
At the very least the data required to readily plaintext the passwords is not public in this case which is a lot better off than companies using only simple hashing like md5. Some credit is due here for sure, but I can't help but strongly suspect the issues here and in now countless other orgs are a result of people having access to PII that don't really care about security or respect the privacy of the user data they are responsible for.
How do you know Weebly doesn't do the things you mentioned?
Fact is, you don't and that post was just an ad for your "services" in the form of a thinly veiled critique.
As for making an ad for my "services". My company does not provide security services and I am not looking for a job in this space. Pretty happy where I am. I gain nothing from posting this but to promote discussion I feel is important for our industry.
I do however participate in a not-for-profit community I have funded mostly out of pocket for the last 15 years for helping teach better system admin and security practices. If you can even find it, and want to call this an ad for that ... uh, sure.
It might seem trivial to you, but the last thing I want in a CI/CD pipeline is senior engineers that don't understand the underlying technology.
Believe me, I've interviewed lots of people for senior positions that just haven't had to properly learn revision control. It's not a given.
The only Android related things on the job listing are proficiency with the IDE (Android Studio) and generic "frameworks".
I am an Android engineer, I clicked this job listing earlier today when it was on HN because I was interested in it. From the perspective of a listing that tries to get a good funnel of candidates coming in, it does nothing for me.
Would you apply to that job listing? I spend a lot of my day to day helping companies optimize their job listings, especially when they have high view numbers but low application click through rates, so this is a pet peeve.
Basically I like job listings that include _specific_ information about the role at the company. Maybe that means listing some of the hard challenges the other people on the team have worked on recently, maybe it just means listing the frameworks and libraries they're using, but anything to help me differentiate their Android role from someone else's Android role.
I don't mean to put you down for you requirements but git is really really easy to learn. It would be a shame to miss out on a talented developer for something an otherwise well qualified developer could learn in a weekend.
Learning is not the same as memorising a few commands.
https://www.sequoiacap.com/article/trial-week-our-hiring-sec...
> I tell people that the worst case scenario is that they use a week of vacation, but because of the extra pay they can take a nicer vacation later on.
I mean, how can they, if they've already used their vacation time?