MusicBrainz Password Leak
pastebin.com
pastebin.com
Yet another company with a far too relaxed approach to security. What bothers me though is that they discovered this 2 weeks ago and I'm only hearing about it now.
The blog post they link to is dated April 5th: http://blog.musicbrainz.org/?p=1844
Their site in general is pretty dumb. I logged in and deleted my account but it didn't log me out, it just changed my name to 'Deleted Editor #XXXXXX' - I can still edit all the account details.
What Data Was Leaked? bcrypt password hashes, with a cost parameter of 8, for all accounts as of March 25th 2013.
Wait, this is fine, isn't it? They did the right thing.
... which helps prevent against the use of existing rainbow tables, as the hash from site A won't be the same as site B, even if the underlying password is the same.
> Yet another company with a far too relaxed approach to security
I don't think we have a relaxed approach to security, we do our best to take it as seriously as possible. Sadly, we have only 3 programmers, a large legacy code base and generally insufficient resources. As we provide public data dumps anyway, it's unfortunate that mistakes can become as magnified as this one, but it did happen. It's not a reason this should of happened, and nor is it meant to be an excuse, but I don't think many people are aware of this.
> What bothers me though is that they discovered this 2 weeks ago and I'm only hearing about it now.
Yes, I've worked night and day to try and get the work necessary to even sand these emails out for the past fortnight. We've never had to do mass mailing like this, so we simply don't have the infrastructure to send the emails. Again, it's not really a reasonable explanation, but that's why it happened.
I'd rather have a single, reliable source of information for this. Also I'd like to see the history of each service before I sign up.