Thursday, July 12, 2012

Social site Formspring hacked, passwords disabled

(AP) ? Social networking site Formspring said Tuesday that it was disabling nearly 30 million registered users' passwords after hundreds of thousands of them were leaked to the Web in their encrypted form.

Formspring said in a blog post that the breach happened after someone hacked into one of the San Francisco-based company's servers.

Spokeswoman Dorothee Fisher said Wednesday the company was alerted Monday that some 420,000 encrypted passwords had showed up on a security forum whose identity she refused to disclose because she did not want to draw attention to it.

Encrypted passwords aren't immediately useable, although they can sometimes be decoded by a savvy attacker.

Fisher said there was no evidence that any accounts had been tampered with.

Formspring founder Ade Olonoh said in a blog post that his company had fixed the vulnerability and upgraded its encryption, adding that the company wanted to "play it safe" and had asked all users to reset their passwords.

"We take this matter very seriously and continue to review our internal security policies and practices to help ensure that this never happens again," he said.

Formspring launched in 2009 as a crowd-powered question-and-answer site. Last month, the company announced a major revamp intended to shift the site's focus toward users' interests.

Associated Press

Source: http://hosted2.ap.org/APDEFAULT/cae69a7523db45408eeb2b3a98c0c9c5/Article_2012-07-11-Formspring-Hacking/id-73051e91c58c454aa6224fa9e468cb51

ice t downton abbey new york knicks president day lin j.r. smith espn jeremy lin

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.