ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    Gawker passwords pilfered in server hack

Gawker users are advised to change their passwords following a hack.

By Tom Brewster, 13 Dec 2010 at 11:15

Data security

Gawker Media has admitted passwords were stolen in a hack on its user databases.

Whilst the stored passwords were encrypted, Gawker said, simple ones may still be vulnerable to a brute force attack, where constant attempts to crack the key are made until the hackers are successful.

Users have been advised to change their passwords for Gawker websites and for any other site on which they use that same password.

“We're deeply embarrassed by this breach,” a note on the Gawker website read.

“We should not be in the position of relying on the goodwill of the hackers who identified the weakness in our systems. And, yes, the irony is not lost on us.”

Other Gawker sites include Lifehacker, Gizmodo, Gawker, Jezebel, io9, Jalopnik, Kotaku, Deadspin, and Fleshbot.

“We understand how important trust is on the internet, and we're deeply sorry for and embarrassed about this breach of security - and of trust,” a separate note on Lifehacker read.

“We're working around the clock to ensure our security (and our commenters' account security) moving forward.”

A group going by the name of Gnosis has claimed credit for hacking Gawker’s servers, reportedly posting a file on the Pirate Bay.

The file contained numerous passwords, including those of Gawker founder Nick Denton.

As yet, there has been no definite link between Gnosis and the Anonymous hacker group who have been going after anti-WikiLeaks services.

A related Twitter hack?

Following the Gawker compromise, hundreds of thousands of Twitter accounts were hacked as well.

Del Harvey, Twitter's director of trust and safety, said she suspected these new hacks used the same passwords as those taken from Gawker.

The hacked Twitter accounts have been used by spammers to send messages attempting to direct users to a supposed acai berry diet website.

“Got a Gawker acct that shares a PW w/your Twitter acct? Change your Twitter PW. A current attack appears to be due to the Gawker compromise,” Harvey wrote on her own Twitter page.

“In other words: the acai berry attack looks to be connected w/the Gawker hack rather than a worm.”

Ethical hacker Jason Hart, senior vice president at CRYPTOcard, told IT PRO hacks like the one against Gawker are becoming easier to carry out.

“With the ease of hacking and cracking passwords, there need to be additional layers of security,” Hart said.

“Encrypting passwords does not prevent brute force attacks.”

Sophos has told web users to mix up their passwords for added security.

According to a Sophos poll carried out last year, a third of respondents said they used the same passwords for all of their online accounts.

Just a fifth used different passwords for all their various accounts.

Email to a friend

Print this page

< Previous   File Servers : News Next >

1 comments

You need to Login or Register to comment.

Gawker

All anyone in tech industry is talking about at the moment. I have a video on my company website with a few hints and tips for those using same passwords on all websites. Check it out in the videos How To sections on http://www.f8-it.com

By f8itsolutions on Monday Dec 20

1 people out of 1 found this comment useful.

Did you find it useful?

    You may also like...

 Sponsored Links

advertisement

    You may also like...

    Latest File Servers Analysis & Insight

Salesforce.com logo

Q&A: Marc Benioff, Salesforce.com

An audience with one of the biggest cloud evangelists in the industry today, Marc Benioff, chairman and chief executive of Salesforce.com.

Read more

 
advertisement

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored Links
Advertisement