Important Customer Security Announcement
blogs.adobe.com
blogs.adobe.com
Well that's reassuring(!) If these hackers were so "sophisticated" then presumably they could have obtained Adobe's decryption keys too? If not, why not?
Guess I'll have to phone my bank tomorrow... hope they don't charge me for the new card. Oh Adobe...
Edit: It just occurs to me that people with pirated Adobe software aren't having any problems right now. The same argument could be made of any service, of course, but at least with the old way of purchasing Adobe software (vs. Creative Cloud) Adobe didn't have to store your credit card number for an extended period of time. I don't think this excuses piracy, but it's not going to do anything to discourage it.
That sentence is disinformation. It carefully leaves unanswered the question of whether the encryption keys were stored in a location accessible to the attackers. The only reason to use that kind of language is to try and confuse everybody into believing things are not as bad as they would otherwise look.
That sentence also suggests that Adobe DOSE store decrypted credit or debit card numbers, but the hackers did not get to that database... yet.
On first reading I had a split-second where I thought the attackers did everyone a favor by deleting the data; e.g. "drop table customer_financial_data". Unfortunately they meant the ~other~ kind of "removal". I think "obtained" would have been a better word to use here (instead of "removed").
This shit happens. To EVERYBODY, sooner or later. What makes a difference is how to handle it. I say Kudos to Adobe for storing encrypted data, being open and owning it up, and trying to fix what's been messed.
"KrebsOnSecurity first became aware of the source code leak roughly one week ago...with fellow researcher Alex Holden...discovered a massive 40 GB source code trove stashed on a server used by the same cyber criminals believed to have hacked into major data aggregators earlier this year, including LexisNexis, Dun & Bradstreet and Kroll."
"The hacking team’s server contained huge repositories of uncompiled and compiled code that appeared to be source code for ColdFusion and Adobe Acrobat."I'd rather obtain minified javascript.
I feel particularly bad for the design houses that have entrusted Adobe with their intellectual property because it was supposed to be safe who now have to rethink how safe their assets really are.
It's illicit, but it will help free software and reverse engineering in a huge way. Adobe doesn't deserve to manipulate its users with CC like it's doing right now.
And for those who are using Reader, well, they were in for it.
Wonderful.
We can argue as to whether or not we like their products, value their products, or receive in return for payment value greater than or less than the price of their products, but it seems to odd to say they shouldn't be able to make a decision about how they choose to sell them?
This is pretty debatable considering the options which are currently available to consumers. Yes, they have some competition, but it's hardly putting a dent in their bottom line.
It's comparable to the New York Yankees playing in a Juco league. Sure they have "Competition" in the form of other teams, but are those teams really in their league? No.
Is your argument for Adobe monopoly really that "they make really good products and no one comes close to them in quality?" Because if so, then good on Adobe for making good products.
I hope some bold entrepreneur brings out some software to seriously compete with Creative Suite because the market sorely needs it.
You would have to be something of an idiot to look at this if you intend to have anyone ever look at anything you code in the future.
There are classes of products related to this specific task, generally we call them "DLP" or Data [Leak|Loss] Prevention.
What we don't know, is how the information was transferred from the servers, and how much different that traffic looked compared to normal activity. It's easy enough to catch a credit card number flying through a plain HTTP packet over the network in the wrong direction, but it gets much harder when the party trying to transfer that data is intentionally attempting to avoid detection.
> Isn't there some best practice security measures that can prevent of all of these things
Yes, but none of them are perfect, and even if they were, they would require perfection from human operators. (Perfectly configure, maintain, monitor, etc.) And, of course, they assume you can identify a threat before it leads to compromise.
Conflictingly because my CC info has since expired, but other personal data would still be in their records. I wonder how far back they keep those, but I guess I'll find out soon enough if I'm in the lot.
Edit: If anyone is worried about the source getting leaked giving rise to 0-day exploits and the like, you can at least move away from Reader into something like Sumatra PDF (open source). If all you need is a reader, it's a very handy alternative and far more nimble with resources (no I'm not part of their project. I'm just a very happy user)
It would be nice to know how many user accounts Adobe manages, so that I can better estimate the likelihood of my accounts being affected. If they only have 2.9 million accounts, I should be worried; if they have 100 million accounts, I should still worry but perhaps a little less so.
I have not (yet) received an email from Adobe regarding this latest attack, but I have an Adobe Creative Cloud subscription as well as several Typekit accounts. I use 1Password to generate passwords, but of course that doesn’t protect my credit card information.
>Arkin said the company has not yet determined whether the servers that were breached were running ColdFusion, but acknowledged that the attackers appear to have gotten their foot in the door through “some type of out-of-date” software.
I am shocked that most people think it's OK these days to drop the "Oops, nasty baddies bad bad got in and there goes your details, so so sorry, come again."
If this happens to some small startup with the one PHP nerd that doesn't really know what he's doing (and is underpaid anyway) - that's fine. Or at least acceptable. You're living on the edge.
But a Fortune 100 company... COM'ON.
This needs a ladder of shame. If we don't shine the light on this, things just won't get better.
I know Citi Credit card lets you do that.
> and wouldn't work for recurring purchases (like Adobe Creative Cloud)
It could. If I remember correctly, Citi card lets generate three types of Virtual Cards. One based on the expiration (less than a month), another based on the maximum amount/balance (where expiration is about a year) and finally a combination of both.
Virtual credit-cards are real handy especially when trying those 30 day trial services.
Seems that another way to solve this for recurring payments would be to likewise issue a virtual number. But, only the merchant with a particular Merchant ID could apply a charge to that number.
In general, it's actually a strange concept that we walk around with these wide open payment methods that only require that a dishonest person acquire a few bits of information to abuse with impunity.
Very few people used it
But there is an additional problem, from American Express's point of view. Virtual credit card numbers are patented by Orbiscom, which was acquired by MasterCard in 2009.
Pretty ridiculous though.
On a related note, I just came across this:
http://storefrontbacktalk.com/securityfraud/the-big-three-cr...
>Visa, MasterCard and American Express proposed new global standards to replace traditional account numbers with a digital payment “token” for online and mobile transactions.
So, either they are licensing it from Orbiscom, ignoring the patent, or it doesn't apply here.
In any case, it's good news. Looks like some semblance of virtual numbers will return on a standardized, more global basis.
The article talks about replacing 16-digit card numbers with a new payment infrastructure. The Orbiscom technology produces virtual card numbers that are backwards-compatible with existing 16-digit credit card numbers.
Then you go through the requests in your account and allow those you wish.
Like a sort of reverse Direct Debit/ Standing Order.
If say for instance the token you gave to Adobe gets stolen, you or they just disable all tokens or ask for new tokens.
So not only will fraud be more difficult but merchants also will be known who has been compromised. Right now banks won't always tell you what merchant was compromised and causing you to get a new number/card.
New payment systems have this, for instance stripe is built similar to this.
Why do people have to update all their cards with all their merchants after one fails? Getting multiple cards and internet cards sometimes helps compartmentalize but really we need this at least per merchant.
Some banks have this like Bank of America ShopSafe but it should be the new normal.
That's the reason to aim for PCI compliance your self.
I'm sure they aren't happy about the idea, but most of them recognize that lock-in is a reason people don't use their services.
Seriously, I don't get it. At least in the US, card holders have zero liability in these instances.
If your card number got leaked and is used to make a fraudulent purchase, simply report it to your card issuer. They will reverse the charge and issue you a new card number.
The paranoia around card numbers for consumers is crazy. There's literally no risk. It makes sense for merchants because they bear risk, but I don't understand why cardholders get upset.
So I would infer that the attackers obviously had access at a very high level, probably compromising the credentials of someone very senior with very high privileges. Which in turn means they could almost certainly have compromised the encryption keys and would be most likely to do so before downloading the actual CC data.
Somewhere, oclHashcat makes room temperature rise.
Hmm. Maybe the fraudsters literally took the data. As in, Adobe no longer has our email addresses with which to notify us.
It may as well be that ridiculous.
Around November 2011, Apple screwed up one of it's premier softwares (Final cut pro) and Adobe jumped right in and offered a 50% discount to all of its Creative suites (version: 5.5). Their pitch then was - "Apple screwed up, try ours and hey, if you buy the suite, it's yours forever and you get peace of mind". And so I bought the Windows edition of one of their suites. A year later, CS6 was announced and I decided to wait for sometime before upgrading. Just to be clear, I shelled out almost $1000 on the CS 5.5 version.
In the last few months, I made the switch to a Mac and I found out that my license for Windows wouldn't work on a Mac. Fortunately, Adobe seemed to provide a "crossgrade" path, wherein I can just swap my platform at no additional cost. Sounds good? No. Except that you can't swap from an older version (CS 5.5) to a newer version (CS 6). You can only switch between platforms of the two same versions. Okay, that's in a way fair enough, since it's been over a year anyway and it's time to upgrade. So, let me just upgrade to CS6, I thought.
This is where it started to get messy. I searched for links to upgrade to CS6, and I did find a few. But they all re-directed to the stupid Creative Cloud edition. WTF?
[1] http://www.adobe.com/mena_en/products/creativesuite.html
I searched and searched and finally found a link that worked. I placed an order and 24 hours later, my order was cancelled for no reason. I had to search for that link I found earlier, again. After giving up finding the link, upon contacting customer support, I was tried to be pushed into the stupid Creative Cloud platform, again.
Support: Based on what we have discussed I highly recommend that you purchase Creative Cloud which includes Photoshop CC for images, Indesign CC for print design, Illustrator CC for graphics, Flash Pro CC for animations, After effects CC for adding effects and plus more.
Support: Plus you will get all the upgrades and updates for free of cost.
Support: You can install CC on 2 system both on mac/ Windows.
Support: I am sure CC will meet all your requirements.
you: Oh no thank you, please. It doesn't fit my budget. Once I stop paying, everything is gone, unlike in the case of a CS 6 install.
Support: I do understand your concern, however, going forward there is no upgrade path available since CC is replaced by CS6.
(WTF)?
you: Do you mean to say, that I can't upgrade from Cs 5.5 to 6?
Support: The upgrade path from CS6 to CS7 is not available, since CC is replaced by CS7.
you: Yes, I understand that.
you: I don't need CC ma'am, really.
you: It doesn't fit my needs.
Support: That's okay.
Support: Let me provide you with the link to upgrade to CS6 production premium, okay.
(Finally!)It's funny I had to spend so much time with support to purchase CS6, since Adobe clearly conveys that it intends to sell CS6 indefinitely. [2]http://www.adobe.com/products/cs6/faq.html
Even though the support person gave me the link to buy CS6, I thought it would be a good idea to probably re-consider CC again. So I checked on the Creative Cloud page to see if I could just pay $45 for say, about two months and later upgrade to CS6. But, again, Adobe tries to backstab its users. IF you cancel your CC subscription before 1 year, you will be billed 50% of the total amount (50% of ($45x12)) as a penalty. WTF?!! So, basically they want to beat their users to the ground as much as they can.
I decided to try alternatives, because I really wanted only a good Photoshop-like program and nothing else more (at that point). So, I searched, but I couldn't find. Now, this is highly deceptive on Adobe's part because they play a monopoly role clearly and they decided to backstab their users all of a sudden.
There is no easy way to buy CS6, there is no easy way to subscribe to CC for just a few months and the calculations they demonstrate are also deceptive at best. CC is more expensive than the boxed product.
One of my friends is a blogger, he has a huge follower count. Adobe contacted him and gave him a free 1 year subscription to CC. I was curious and I found a lot of bloggers reporting the same. One thing that was common in most of these Adobe contacted bloggers' posts, was how their stress to explain how the CC version was effectively cheaper than their boxed version.
So basically Adobe is indirectly bribing bloggers to write good stuff about their CC subscription.
Adobe's CEO is an incompetent backstabber who is totally fit for nothing. This was the same guy who argued with Steve Jobs that Flash on mobile rocks and later discontinued it. Backstab #1. I was a Flash developer previously. I was even jobless for a few days because I relied so much on this technology.
Adobe's CEO also backstabbed the much capable Flex eco-system. Do you know how many Flex developers are jobless now? Backstab #2.
And the Creative cloud (CC). Backstab #3.
That is why I feel happy that their source code was stolen. I was a genuine customer amongst a million others who just wanted to pay ONCE to use my software. I could have pirated like many others, but I didn't. I trusted them. But they took a U turn and decided to shoot us in the back.
Also, this guy is never straightforward: http://gizmodo.com/5984191/adobes-ceo-completely-refuses-to-...
This guy is incompetent and needs to be replaced. Atleast someone should file a class action suit for abusing their monopoly.
I understand why you would say that, but I don’t agree. At the time, I used Final Cut Pro 7 daily and when Final Cut Pro X was released, I didn’t immediately switch to it. I waited for multicam editing and XML export, and Apple delivered. That’s when I switched to Final Cut Pro X and it was a great improvement over version 7. When Adobe came up with Creative Cloud, I signed up. That meant I got Adobe Premiere as part of the package, but after trying it, I still much preferred Final Cut Pro 7. Comparing Premiere and Final Cut Pro X, for me, it’s not even a contest. With Final Cut Pro X, I’m way more productive than I ever was in FCP 7, Avid, Premiere or Media100.
Apple could’ve done better by offering the first few releases of FCP X as a free beta, but right now, FCP X is a way better product than FCP 7 ever was.
Isn't that what the monthly plan does [0]? $75 / month rather than $50, but with the option to only pay for individual months. I think they said they were originally thinking of freelancers who might only take on work that involved using CC a few times a year.
[0] http://www.adobe.com/products/creativecloud/buying-guide.htm...
For a teen who wants to edit their iPhone photos before uploading to Facebook, $75 per month would be a lot. But that's not Adobe's target market.
For example, assume, depending on where you live, your favorite manufacturer, who is also a monopoly, Volkswagen if you're in Europe, Ford/Chevy if you're in the States sells you cars for a fixed price and you're very happy.
So let's say the price of each car they sell you is $25,000. You pay once and forget and you own the car. Forever. Assume this car is very solid and you plan to own it for a good 5-7 years. For a span of 5 years, that translates to $5000 a year.
Now, suddenly, Volkswagen/Ford/Chevy decide that one time payments suck and you need to pay monthly, say $1000.
Their argument is that for $1000/mo for 2 years you spend $24,000 in total and that is less than what you would pay one time. Well, if you were the kind of person who would upgrade once in every two years, that is fine. It is really a $1000 cheaper. But for the average dude who upgrades his car once in 4-5 years, it's a disaster.
His current car's value reduces drastically because of this monthly scheme. And to access any sort of updates to his car, he needs to pay monthly, and this monthly payment includes a penalty as well, if you decide to cancel sometime in between.
That sucks right? I know people who are still on CS3, CS4, CS5 because it just works for them and fits their needs.Now these manufacturers tell you that you can still buy an older model from their store and make it extremely difficult and dodgy to buy one. That's cheated right? Especially considering the fact that there are a lot of car robbers who rob cars from their factory (but by cloning the car and leaving the original copy behind) and get away without paying anything. Now, how bad would you feel for paying for such a nasty corporation?
That's exactly how I feel right now.
Adobe would say that it might be more comparable to your car manufacturer upgrading your car every time they released a new model.
> His current car's value reduces drastically because of this monthly scheme.
The value of what his current car has reduced because they released a new model, not because of the new scheme (and CS6 hasn't depreciated in price that much!)
> And to access any sort of updates to his car, he needs to pay monthly, and this monthly payment includes a penalty as well, if you decide to cancel sometime in between.
Just like every other 12 month contract ever? It's pretty clearly labelled that it's an annual contract, and that there are recurring monthly contracts available for a higher cost.
> Now these manufacturers tell you that you can still buy an older model from their store and make it extremely difficult and dodgy to buy one.
As MarkMc said, it's not especially hard to buy CS6. All the top search results for "buy cs6" allow me to buy it pretty immediately.
Sure, they definitely upsell CC, but they also see that as their new and better product: is it really dishonest or nasty of them to do so?
> But, again, Adobe tries to backstab its users. IF you cancel your CC subscription before 1 year, you will be billed 50% of the total amount (50% of ($45x12)) as a penalty. WTF?!! So, basically they want to beat their users to the ground as much as they can.
What you call 'beat their users to the ground' I call 'charge fees which maximise their profit'. They are not being deceptive - their price list clearly states, "Requires annual commitment; billed monthly" [1]
> There is no easy way to buy CS6
If you Google "buy adobe cs6" the first result [2] allows you to buy a CS6 'Master Collection' licence for $2,599. Just click 'buy' then 'Add to cart'. Seems pretty easy to me.
> there is no easy way to subscribe to CC for just a few months
Not true - as pointed out by estel, you can easily subscribe for $75 per month. I think by 'easy' you mean 'cheap'
> the calculations they demonstrate are also deceptive at best
Can you provide a link to the deceptive calculations? Because to me the price list [1] seems to be fairly straightforward and honest
> CC is more expensive than the boxed product.
Doesn't that depend on how long you use the software for? You can buy a single month for $75 - I doubt that you can get the boxed product for cheaper than that.
> One thing that was common in most of these Adobe contacted bloggers' posts, was how their stress to explain how the CC version was effectively cheaper than their boxed version.
If it is true that Adobe implicitly says, "write good things about us and we'll give you free stuff" then I agree that this is pretty bad behaviour. (But if they say, "here is some free stuff, please write good things about us" then that would be OK as long as the blogger notes in their review that they had received the free stuff.) The fact that bloggers who received free stuff had previously wrote good things about Adobe is not sufficient to convict Adobe of indirect bribing. It could be that the bloggers who did not receive free stuff also wrote good things about Adobe (ie. their products are generally viewed positively)
> Backstab #1. I was a Flash developer previously. I was even jobless for a few days because I relied so much on this technology…Do you know how many Flex developers are jobless now? Backstab #2.
It sucks to lose your job, but is it really 'backstabbing' for Adobe to drop support for a platform they developed? For all software I expect the companies who develop it to say "this is a great product and we fully support it" right up until they day they drop that support. It's not like Adobe said, "we will support this product until at least 2015".
> [The CEO] is never straightforward...This guy is incompetent and needs to be replaced.
Personally I think it is very straightforward to say, "I refuse to discuss our pricing strategy with you". But in any case the CEO's job is to maximise profits - and using the strength of Adobe's market position to charge nosebleed prices sounds to me like he is doing just that. Not at all incompetent.
> At least someone should file a class action suit for abusing their monopoly.
It's not necessarily illegal to have a monopoly and charge a very high price for your products.
[1] http://www.adobe.com/products/creativecloud/buying-guide.htm...
[2] http://www.adobe.com/products/catalog/cs6._sl_id-contentfilt...
----------
Important Password Reset Information
To view this message in a language other than English, please click here.
We recently discovered that an attacker illegally entered our network and may have obtained access to your Adobe ID and encrypted password. We currently have no indication that there has been unauthorized activity on your account.
To prevent unauthorized access to your account, we have reset your password. Please visit www.adobe.com/go/passwordreset to create a new password. We recommend that you also change your password on any website where you use the same user ID or password. In addition, please be on the lookout for suspicious email or phone scams seeking your personal information.
We deeply regret any inconvenience this may cause you. We value the trust of our customers and we will work aggressively to prevent these types of events from occurring in the future. If you have questions, you can learn more by visiting our Customer Alert page, which you will find here.
Adobe Customer Care
There is tremendous "pain" here (both for vendors and for customers) which, if effectively addressed, could be the next Google or Apple.
Are you saying we need to create a cloud service that is completely secure ( which we know is impossible ). My understanding is that CloudFlare is already tackling the security aspects of hosted services and seem to be doing well.
Im curious; which aspects are they tackling, specifically? Authn, authz, byte validation... Or ?
Sure, and note that my background has included secure systems design work.
Secure systems operate under a couple of constraints. It is as you posit, impossible to make a 'completely secure' system, just as it is impossible to make a 'completely safe' airplane (and the 'impossible' here means that such a system continues to be usable or commercially viable). But generally if you can make a 'secure enough' or 'safe enough' system, then you can still make a business out of it.
Using a fairly simple example, general residences in the US are not secured against experienced thieves, but in general experienced thieves aren't trying to steal things out of random houses, they go for specific houses. So the system "works" because you aren't getting broken into every day. And if the house next door is burglarized your house is no less secure than it was the day before.
But in a cloud system the thieves get tremendous economy of scale, rather than breaking into one house they can break into every house in the city. In that way even if you don't have 'much' if you have anything they can steal it.
Cloud computing both ties together high value and low value targets on the same system, and makes the total return of compromising the system higher in proportion to the number of users of that system. That is a real challenge because now everyone needs really really good locks on their houses, the costs go up and the usefulness goes down.
Reason: Adobe charges basically double the US price in Australia/NZ if you buy from them directly, and I refuse to pay a location tax since it costs them zero dollars extra to send me bytes through CDNs.
Not sure how much localisation is required since Australia, like New Zealand, is an English speaking Western democratic country.
Pretty sure we could understand US vernacular and cultural differences.
Call it what it is: Discriminatory pricing because they think that is what the market will bear. Fine, but I feel free to work around it as well.
After a while on Inkscape I am now running with:
- Sketch (http://www.bohemiancoding.com) as a replacement to Illustrator (vector drawing).
- Acorn (http://flyingmeat.com/acorn/) as an alternative to Photoshop for bitmap design (though it now supports vector drawing, much like Photoshop).
I am not affiliated in any way.
2) Sketch/Acorn are not available on Windows.
Not saying you're wrong; just saying I disagree :)
Time to dust off the ol 'résumé, Brad.
I always get an error message:
The provided email address could not be matched to an account on file. Please try again.
Thanks to 1Password, I am pretty sure that the provided mail address is correct …
This is out of control. The bad guys are winning. Time for a new paradigm.