Showing posts with label passwords. Show all posts
Showing posts with label passwords. Show all posts
Friday, June 3, 2011
TENNESSEE MAKES IT ILLEGAL TO SHARE YOUR PASSWORD TO MEDIA SITES
One of the perks of having a friend with a Pandora, Rhapsody, or Netflix account is that if they’re really nice to you they may share their password, giving you free access to movies and music. Of course, these companies don’t advertise this as an option, for obvious reasons, but a new law passed in Tennessee is actually making it illegal to share your password. The consequences for being caught are pretty scary.
The bill, initiated by none other than the Recording Industry Association of America, has been approved by the Tennessee governor. The goal of the bill is aimed at stopping the billions of dollars lost in illegal music sharing. RIAA executive president of public policy Mitch Glazier told the AP that the bill is a “necessary protective measure as digital technology evolves.” He said the music industry has seen its domestic revenue fall from $15 billion to $7 billion in the past 10 years.
The RIAA says the bill was geared more towards hackers who sell passwords in bulk, but admits it could be used against people using a friend or relative’s password. The punishment for stealing $500 or less of entertainment would be a misdemeanor and up to a year in jail, as well as a $2,500 fine. Anything higher than $500 would be a felony with more serious penalties.
The RIAA hopes this bill will spread to other states but targeted Tennessee first because of Nashville’s ties to the music industry. It seems that most people sharing passwords within the same house, say between spouses, would be safe. However, if you’re sharing your Netflix password with 10 of your friends, you may be getting more than a slap on the wrist soon.
Thursday, May 19, 2011
SONY'S PLAYSTATION NETWORK PASSWORD RESET PAGE HACKED
According to reports from numerous gaming sites, the password reset page for Sony’s PlayStation Network has been exploited. Sony built the page in an effort to allow users, whose accounts were already compromised during a major security breach last month, to reset their security credentials.
However, hackers who stole the information from Sony can reset users’ passwords by knowing an account holder’s email address and birthday — information they’ve already stolen. Forum members on Nyleveia have suggested that PSN users create a new email address specifically for use with PSN.
Sony has taken the website offline, and said: “Unfortunately this also means that those who are still trying to change their password via PlayStation.com or Qriocity.com will still be unable to do so for the time being.”
Labels:
compromised,
hackers,
passwords,
playstation network,
playstation 3,
ps3,
psn,
Sony,
vulnerability
Thursday, May 5, 2011
LASTPASS POSSIBLY HACKED, URGES USERS TO CHANGE PASSWORD
Free password management program LastPass, a browser extension that manages passwords and automates form filling, has been subjected to an external attack which could see user email addresses, their server salt and salted password hashes stolen by attackers.
Posting on the company blog, the LastPass team explains that evidence of an attack was first noticed on Tuesday after the server logs were checked and anomalies identified and processed. Network traffic, over a period of a few minutes, spiked on one of the non-critical LastPass machines. Not able to identify the cause, the team noticed a similar traffic spike in the opposite direction, suggesting that the data on the machines was somehow accessed.
LastPass explains what it thinks might have been comprised:
We know roughly the amount of data transfered and that it’s big enough to have transfered people’s email addresses, the server salt and their salted password hashes from the database. We also know that the amount of data taken isn’t remotely enough to have pulled many users encrypted data blobs.
Users with a “strong, non-dictionary based password or pass phrase” should not be affected, LastPass believes that to gain access to passwords, attackers will need to brute-force its user’s master passwords to gain access to user data.
LastPass urges all of its users to change their passwords to counter the threat and has brought into place an additional level of security to identify if the user is accessing the site from an IP address they have used before, also requiring email address to be validated.
Labels:
browser extension,
hack,
LastPass,
passwords,
program
Monday, January 31, 2011
SECURITY BUG FOUND IN AMAZON'S LOGIN SYSTEM
Engadgetis reporting Amazon's login system has a bug in it. The Amazon.com login system will actually accept any phrase so long as it begins with your password, such as "password123" when the magic word is simply "password" by itself. That apparently makes it that much easier for a computer to guess your password via brute force methods.
The fix is relatively simple for the end user, change your password. It is suggested you use a combination letters, numbers and symbols.
Thursday, January 27, 2011
FACEBOOK CLOSING SECURITY HOLE SWITCHING TO HTTPS FOR LOGINS
Facebook has at long last offered an option to use the encrypted "HTTPS" protocol, a feature it will begin rolling out today but won't finish for a "few weeks." You should check now if it's available, and sign up as soon as it is enabled for your account.
By default, Facebook sends your access credentials in the clear, with no encryption whatsoever. HTTPS solves this longstanding problem by encrypting your login cookies and other data.
A blogger using a freely available program called Firesheep was able to steal up to 40 Facebook logins in 30 minutes in a New York Starbucks recently.
You can sign up for Facebook HTTPS by going to Account Settings and then selecting "Account Security," third from the bottom. Then click under "Secure Browsing" — if it's there. Facebook says everyone should have this by the end of the day, but in the meantime you might be missing the relevant option toggle.
Subscribe to:
Posts (Atom)



