The Register® — Biting the hand that feeds IT

Feeds

Fasthosts primes another password reset

Third time's the charm

Magic Quadrant for Enterprise Backup/Recovery

Punch drunk Fasthosts customers are set to be hit with a third compulsory password reset next week, as the budget web hosting company scrambles to cope with a major security breach.

The latest system-wide wipe will affect people who run dedicated servers, have bought backup storage at the firm's Gloucester data centre, and who use "peripheral services" such as its SiteBuilder and traffic analytics. Vulnerable customers were told yesterday via email that if they do not change their own passwords by 19 December, they will be automatically replaced.

Unlike with the previous control panel and FTP reset, and this week's email reset, the new keys will be sent electronically "on the same day" rather than in the post.

In a statement to The Register, Fasthosts promised that this will be the last disruption triggered by the hack attack we reported in October.

It wrote: "This is the third and final stage of our security audit. Fasthosts is fully confident that, in completing all remaining password changes, this will prevent any future disruption or concern."

The first poorly-communicated reset and subsequent delays in getting new passwords to customers had the UK webmaster community in fits of rage in our comments section.

Many websites were shut down and small businesses have been put in jeopardy by Fasthosts' actions. It has limited its reparations to apologising for the "inconvenience".

Tales of Fasthosts' blundering were eventually picked up by papers and the BBC, and the firm now has a mountain to climb to restore any hint of a reputation for competence.

This latest round of unilateral resets confirms that Fasthosts suspects every single customer password was compromised by the hackers. Fears that the attackers plundered some "master database" that also contained banking data have not been assuaged by Fasthosts' public statments.

We reported back in October that Fasthosts was working with credit card companies over the breach.

Fasthosts has refused to comment on what data was stolen, saying it would prejudice the criminal investigation being carried out by the high tech crime squad.

Incidents like this, together with the recent focus on government data incompetence, can only add to the clamour for a disclosure law. Several US jurisdictions have enacted legislation that compels companies to tell people when they have lost their information, and what that information is.

Here in the UK, we have the toothless Information Commissioner's Office. ®

Agentless Backup is Not a Myth

Latest Comments

RE: FTP Problems

Could it be they are blocking FTP access so people cannot leave?

0
0

Happy SLAppers

Their press section praising the speed of response of their support team gave my a wry, simple chuckle.

Having support mails answered promptly is good.

Having them answered correctly by someone whose IQ points exceed that of a termite, a non-animated chipmunk or the current US President would be better.

Having them answered by someone who actually knows more than you do about the relevant system, has the right experience to fix the problem, has the right access level and the time to do it promptly would be ideal.

Now if they did THAT, that would be worth a press release.

You may say I'm a dreamer... but I'm not the only one...

0
0

FTP access problems

Anyone still having FTP access problems?

Ever since the forced password re-set I have been unable to access any of my FTP accounts (and one that is hosted with streamline.net). Fasthosts have said it must be at my end but nothing has changed at my end. I've explained to Fasthosts, more that once, that my FTP access has been working for quite a number of years with no problems until the forced password re-set but they keep telling me it must be at my end.

I'm now losing the will to live!!!

0
0

More from The Register

1,000 O2 staff chose redundancy over Capita
Betrayal, or just decent terms?
 breaking news
Pttow! Ofcom kicks hams out of MoD bands
Geet off my land, you, you ... 'secondary user'
 breaking news
Now you can use your phone instead of your wallet at the ATM, too
Blimey, these little paper towels out of the vending machine are really expensive
 breaking news
UK.gov's £530m bumpkin broadband rollout: 'Train crash waiting to happen'
Whitehall whispers of damning watchdog report next month
Google launches broadband balloons, radio astronomy frets
A careless Loon could blind the square kilometre array
 breaking news
MySpace zaps millions of teens' tearful rants, causes wave of angst
'Your crappy redesign SUCKS, I wanna read my blogs' screech users
 breaking news
Microsoft Office 365 on iPhone NOW: No, we're not making this up
Word, Excel, Powerpoint for your pocket-stroker
 breaking news
EU signs off on eCall emergency-phone-in-every-car plan
GPS and a mobe in every car - do you suppose the NSA would fancy that?