

![]() |
| ![]() | |||||||
|
![]() |
| | LinkBack | Thread Tools | Display Modes |
| | #21 (permalink) |
| Name: Andrew Last Online: 11-04-2009 09:48 AM iTrader: (104) Join Date: Feb 2006
Posts: 2,810
DNF$: 550 Location: Canada
Country: | Do you have any type of log files that confirm which customers passwords were taken? or are you assuming that it was only the ones that were posted online?
__________________ Alternative Energy / Green / Eco Domain Sale! |
| | |
| Sponsored Ads |
| | #22 (permalink) |
| Platinum Lifetime Member Last Online: 11-06-2009 03:21 AM iTrader: (1) Join Date: Aug 2005
Posts: 511
DNF$: 950 Location: Everywhere | Equalizer, As I just posted before you, SS numbers were not taken and I believe nobody is taking it lightly. We have had several hundred emails to our support today which we are dealing with on a one to one basis and we as a company are certainly not taking this lightly. Any company operating online operates under these risks and I am shocked that it has happened to us, but nobody is immune, as recent attacks on Godaddy and US banks have proved. We informed the accounts directly affected within 60 minutes of us having this information. Ed
__________________ www.NameDrive.com |
| | |
| | #24 (permalink) |
| Platinum Lifetime Member Name: Mike D Last Online: 02-25-2009 02:42 PM iTrader: (3) Join Date: Nov 2004
Posts: 8
DNF$: 21 Location: San Francisco, CA | NameDrive did NOT properly store passwords in their database. This is made evident by the fact that your reset password is [originalpassword]_[somenumbers]. If they were properly storing passwords (saving a hash and salt), they would not have been able to get your original password to generate the new password with. Note that "encrypting" passwords is useless, because anyone who compromises the database is likely to also get the decryption keys (since the website would have access to them). I pointed this failure out to ND and got a BS response of "we do not comment on the way we encrypt information." Anyone doing the right thing would flat out deny it, not refuse to comment. ![]()
__________________ PM offers for: AmericansInDebt.com BettingInPoker.com CasinosWithPoker.com HandgunLock.com JobsAtAirlines.com |
| | |
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
| |