Adobe hack: At least 38 million accounts breached
bbc.co.uk
bbc.co.uk
As someone dithering about transitioning from Creative Suite to Creative Cloud, receiving Adobe's letter was a slap in the face.
Given that the breach not only included accounts and credit cards, but also source code, I believe it's reasonable to speculate about potential exploits, including exploits in the Creative Cloud deployment mechanism. Going a little further into paranoia, I wonder if running Creative Cloud is potentially equivalent to running a trojan delivery system. I.e., how do we know Adobe's servers are now secure? Adobe is being cagey about the extent of the breach; the breach may have included internal Adobe credentials that can only be solved by a system-wide nuke-and-pave.
I really want to buy Adobe's new software, but they're making it extremely difficult for me.
It's not so much the breach as it is the lackluster response and lack of ownership of the problem that has me ready to cancel the service. Even the original blog post, which reported only 1/10th of the real information leak, started with: "Cyber attacks are one of the unfortunate realities of doing business today. Given the profile and widespread use of many of our products, Adobe has attracted increasing attention from cyber attackers."
Sure those are valid statements, but they don't really help me feel good about the Adobe platform going forward, and they do more to pass responsibility than to claim ownership.
This industry has systematically externalized the cost of these data breaches, and the security systems necessary to try to prevent them, to every other business and end-user in the country.
There are many ways to solve this problem. Europe has largely solved this problem, and using your antiquated American credit card in Europe is not only difficult, but even if possible will elicit crazy looks.
What other industry today would you trust that the only security is a 16 digit number that you repeatedly share with the world and your zip code? And to think this is how we secure our money?
Adobe is offering a service that costs at the least tens of dollars to 38 million people. What is your credit card offering?
The credit card company is offering full fraud protection. So if someone does use your CC for fraud, you're inconvenienced, but not liable. That's far more than what Adobe is required to offer.
I'm quite happy with the American system of "it's the CC provider's responsibility to sort out fraud". It allows commerce to flow, and the backend can figure out fraud most of the time. Putting the burden on a consumer via a PIN system now means consumers have to be more careful, which is bad for consumers and could possibly deter them from using the cards as much.
Edit: The one thing I'd agree on is the broken system of "credit" in the US. Any company can ruin your credit rating based on their own internal policies, and successfully fighting is a major ordeal. All a company has to do for proof is show a bill, which they literally can just make up.
Additionally, requiring an SSN for everything is ridiculous. Cable TV and prepaid T-Mobile even demanded one. In Canada, no company is allowed to refuse service if you decline to provide your SIN.
Source: They just directed me to protectmyid.com and told me to sign up and pay for it myself. Not a great customer service experience.
Wait what does Europe do? Just genuinely curious, and a cursory google search didn't return anything.
Otherwise, offline you place it into a card reader and enter a PIN. The card then authenticates the transaction only if the PIN matches. The card stays within the reader as you enter the PIN.
Further reading,
I can confirm, when I first came to the UK four years ago, only major retailers seemed willing to accept my Canadian CC, and even then, the cashier usually had to call the manager to confirm that it's ok.
Another thing I have to credit Europe with is the lack of proprietary debit card systems like Interac or Plus. It's all done via Visa/Mastercard Debit, so you're never forced to do your online shopping on credit.
However, design involving collaborators, vendors, and professional output often requires standardizing on Adobe software. I'm not happy about it, but it's where the industry currently happens to be. Don't confuse honest pragmatism with some form of stubborn laziness.
In the end it was a pretty cheap lesson in security... I've now changed all my passwords on everything and they're all unique
Thank god I didn't have any credit card info on my Adobe account.
BTW, Adobe seems to be a vulnerable giant to be taken over. Not sure why no startups target them.
Adobe of today is like RIMM in 2007 before the original iPhone was announced.
In the low-end space there was the Aviary suite, which despite really interesting potential seems to have pivoted to mobile. Pixelmator and Paint.NET have done an extremely good job at providing basic layered image editing functionality, but I don't see anything emerging to challenge Adobe yet.
A competitor in the Pro/Prosumer space would need to develop, from scratch, extremely sophisticated, feature-rich applications to replace Adobe's big 4: Image Editing, Vector Graphics, Motion Graphics, and Video Editing. They'd also need to tightly integrate these applications. This would be HARD. I don't think that the effort/risk/reward proposition looks very attractive for startups or their investors. Also, while game programmers might have some useful experience, I think that computer vision programmers would be much more familiar with the problem domain.
Apple, or maybe Corel probably would have done this a long time ago if it was feasible.
Which brings up an interesting question...if After Effects and Premiere have strong competition, why don't Photoshop and Illustrator have equally strong competitors? I've already taken a guess, but I'm interested in other perspectives.
I would much prefer a initial 'massive' breach announcement (when possible), as that would breath a higher a level of transparency and honesty.
In breeches I've been involved with, some companies would prefer to do the full investigation and then present the information to their customers (in accordance with the policy of whatever state they fall under the jurisdiction of). Others would rather let their customers know that there was a breech as soon as possible, while the investigation was ongoing (even if the information may change after the intial communication). It's really hard to say which is the "best" policy, but if it's CC data or PII, personally I would rather hear 2 million... no wait 36 million than not hear anything for days or week while my information is being disseminated.
It's from the same people as http://www.callcredit.co.uk/
Or did you give Adobe your SSN as well?
Not something like - Ohh, your account has been compromised, yours are not, his is... etc