Stories
Slash Boxes
Comments

SoylentNews is people

posted by Cactus on Sunday February 16 2014, @03:36AM   Printer-friendly
from the hackers-want-crowdfunding-too dept.
stderr writes:

According to a recent announcement, the crowdfunding site Kickstarter has been hacked. Kickstarter states that there was no credit card information stolen and that all unauthorized activity has been limited to only two accounts.

While the passwords are all salted and encrypted (either using SHA-1 or bcrypt), a weak password might still be hacked. Users are strongly advised to change their passwords on Kickstarter and any other site where they use the same passwords.

Further information can be found at the Kickstarter blog.

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 3, Informative) by Khyber on Sunday February 16 2014, @06:31AM

    by Khyber (54) on Sunday February 16 2014, @06:31AM (#213) Journal

    " Kickstarter states that there was no credit card information stolen and that all unauthorized activity has been limited to only two accounts."

    That activity came from my two test accounts. I saw vulnerabilities my old website dealt with two years ago, and tried to harmlessly test them between two of my separate accounts. It worked. KS was notified and advised to stop those two accounts while I tried variations of the PCI-DSS flaw (that they'll ding you for even though it's their security fault.)

    It's not a serious flaw, really. Only deals with non-USD transactions from what I've been able to tell. Not sure if this will affect bitcoin transactions on site or not.

    --
    Destroying Semiconductors With Style Since 2008, and scaring you ill-educated fools since 2013.
    Starting Score:    1  point
    Moderation   +2  
       Informative=2, Total=2
    Extra 'Informative' Modifier   0  

    Total Score:   3  
  • (Score: 1) by Maow on Sunday February 16 2014, @07:17AM

    by Maow (8) on Sunday February 16 2014, @07:17AM (#217) Homepage

    " Kickstarter states that there was no credit card information stolen and that all unauthorized activity has been limited to only two accounts."

    That activity came from my two test accounts. I saw vulnerabilities my old website dealt with two years ago, and tried to harmlessly test them between two of my separate accounts. It worked. KS was notified and advised to stop those two accounts

    That doesn't jive with the link's claim:

    law enforcement officials contacted Kickstarter and alerted us that hackers had sought and gained unauthorized access to some of our customers' data.

    This would seem odd if real hackers were attempting a breach though, which does mesh with your version:

    There is no evidence of unauthorized activity of any kind on all but two Kickstarter user accounts.