Feeds

Fasthosts primes another password reset

Third time's the charm

Boost IT visibility and business value

Punch drunk Fasthosts customers are set to be hit with a third compulsory password reset next week, as the budget web hosting company scrambles to cope with a major security breach.

The latest system-wide wipe will affect people who run dedicated servers, have bought backup storage at the firm's Gloucester data centre, and who use "peripheral services" such as its SiteBuilder and traffic analytics. Vulnerable customers were told yesterday via email that if they do not change their own passwords by 19 December, they will be automatically replaced.

Unlike with the previous control panel and FTP reset, and this week's email reset, the new keys will be sent electronically "on the same day" rather than in the post.

In a statement to The Register, Fasthosts promised that this will be the last disruption triggered by the hack attack we reported in October.

It wrote: "This is the third and final stage of our security audit. Fasthosts is fully confident that, in completing all remaining password changes, this will prevent any future disruption or concern."

The first poorly-communicated reset and subsequent delays in getting new passwords to customers had the UK webmaster community in fits of rage in our comments section.

Many websites were shut down and small businesses have been put in jeopardy by Fasthosts' actions. It has limited its reparations to apologising for the "inconvenience".

Tales of Fasthosts' blundering were eventually picked up by papers and the BBC, and the firm now has a mountain to climb to restore any hint of a reputation for competence.

This latest round of unilateral resets confirms that Fasthosts suspects every single customer password was compromised by the hackers. Fears that the attackers plundered some "master database" that also contained banking data have not been assuaged by Fasthosts' public statments.

We reported back in October that Fasthosts was working with credit card companies over the breach.

Fasthosts has refused to comment on what data was stolen, saying it would prejudice the criminal investigation being carried out by the high tech crime squad.

Incidents like this, together with the recent focus on government data incompetence, can only add to the clamour for a disclosure law. Several US jurisdictions have enacted legislation that compels companies to tell people when they have lost their information, and what that information is.

Here in the UK, we have the toothless Information Commissioner's Office. ®

Seven Steps to Software Security

More from The Register

next story
Auntie remains MYSTIFIED by that weekend BBC iPlayer and website outage
Still doing 'forensics' on the caching layer – Beeb digi wonk
Apple orders huge MOUNTAIN of 80 MILLION 'Air' iPhone 6s
Bigger, harder trouser bulges foretold for fanbois
Bring back error correction, say Danish 'net boffins
We don't need no steenkin' TCP/IP retransmission and the congestion it causes
GoTenna: How does this 'magic' work?
An ideal product if you believe the Earth is flat
Samsung Z Tizen OS mobe is post-phoned – this time for good?
Russian launch for Sammy's non-droid knocked back
Telstra to KILL 2G network by end of 2016
GSM now stands for Grave-Seeking-Mobile network
Seeking LTE expert to insert small cells into BT customers' places
Is this the first step to a FON-a-like 4G network?
Yorkshire cops fail to grasp principle behind BT Fon Wi-Fi network
'Prevent people that are passing by to hook up to your network', pleads plod
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Securing Web Applications Made Simple and Scalable
Learn how automated security testing can provide a simple and scalable way to protect your web applications.