Canva security breach: hacker claims to have stolen the data of 139M users
zdnet.com
zdnet.com
I wouldn't be surprised if a lot of people just signed up to check it out and if a lot of other users registered multiple times with different emails to have access to the free trial.
Facebook says ~17 million fake account creation attempts per day[1] (that they catch after the fact), so it doesn't seem that unusual.
[1] https://news.ycombinator.com/item?id=20000235 (3B/6 months == ~17M/day)
And even moreover a news story saying that 25,000 users data was stolen is not a big deal. A news story saying that 1 billion users data was stolen is a big deal. And then brings up the obvious question of whether the stolen data is really real in some way.
So we'd expect Canva to have a lot more users than Hootsuite.
Also, they've raised over $80M in multiple rounds from top VCs including Sequoia [3], which would be hard to do if they were bullshitting about their numbers.
[1] https://www.alexa.com/siteinfo/canva.com?ver=classic
[2] https://www.alexa.com/siteinfo/hootsuite.com?ver=classic
[3] https://www.smartcompany.com.au/startupsmart/news/canva-50-9...
Sounds like a good idea. Templates have pretty much taken over web design, it makes sense that it will take over other run-of-the-mill categories of design (where hiring a custom designer doesn't make sense).
Definitely a great service, it doesn't surprise me it has so many users.
https://support.canva.com/contact/customer-support/may-24-se...
> Passwords in their encrypted form were also obtained (for technical people: all passwords were salted and hashed with bcrypt); this means that all Canva user passwords remain unreadable by external parties.
So while I hate the phrasing, this statement seems reasonable for once, if lacking in details how they came to the conclusion:
> There have been no indications that any user designs have been accessed.
Yet again though, bad practical password advice:
> Passwords should be changed frequently (at least every 90 days).
Why exactly? What does rotating passwords "at least every 90 days" buy me, against what threat model? Much better advice would be not to reuse passwords across sites, with links to password managers.
Oh, and from what I could see, they don't offer any kind of 2FA.
As a reminder, NIST 800-63 [0] has some decent guidelines, which they seem roughly to be advocating with the rest of the password advice.
[0] https://pages.nist.gov/800-63-3/sp800-63b.html#memsecret
Of course names and contact details are not great. I get that. But will this even effect Canva?
Were the investors made aware of the hack? I also wonder for how long they've known about it, but decided to keep it secret until they get new investment money.
Does this mean my Facebook and/or Google login details have been compromised?
If you use Facebook or Google to log into Canva, rest assured those credentials are also encrypted and unreadable by external parties, so you do not have to change your password on Facebook or Google.
I find this advice stupid, I know many hackers maintain and run through databases of password+hashes they can fetch original passwords from the hash. Also, Canva hasn't accepted nor denied if their salt was compromised, so without confirming these, I think it's just stupid to falsely assure "Don't change your passwords". Were my designs accessed?
There have been no indications that any user designs have been accessed.
Translation: "We don't know"I mean I'm just supposed to believe you at face value and not change my passwords? You just lost my password..
Exactly the point of a salt, to make it so rainbow tables need to be computed with a salt which ideally is different for every user. The salt being exposed doesn't change that.
Edit: For Google/Facebook sign-in, which I presume is OAuth, it works differently and they're correct in saying your Google or Facebook password is not at risk.
So usually, I'd agree, but in this case it's fairly reasonable to say it's unlikely anything was accessed. Cracking bcrypt takes time. If the hackers wanted to target an individual, they'd just phish them.
Also, they literally say:
> As a precaution, we recommend changing your Canva password.
https://support.canva.com/contact/customer-support/may-24-se...
Microsoft (disclaimer: I work there, but not on this product) is trying to get a decentralized identity thing off the ground[0]. It uses the blockchain, so I was pretty skeptical at first but it's actually pretty well-though-out (including the "unhappy path" where users are unable to identify themselves after losing a key or whatever).
AFAIK, it's assumed that the salt is compromised with the hash - it's stored alongside the hash. The point of the salt is to prevent lookups.
Telling you to change your Facebook/google password _is_ pointless, as they don't have those.
> Translation: "We don't know"
I'm not sure what else they are supposed to say - saying they have could cause unnecessary panic and is probably misleading, but they can't conclusively say no as the evidence may have been hidden.