Feeds

Heart Internet spreads the love passwords

Hosting firm suffers security aneurysm

Boost IT visibility and business value

Web hosting outfit Heart Internet has caused security-conscious customers to skip a beat by sending them a handy text file email attachment containing other people's new passwords.

Last week Heart Internet decided to reset a bunch of FTP and eXtend passwords that had not been changed by their account owners for "an extended period".

Its explanatory email said: "Attached to this email is a file list showing all domain names which have had their password changed. The new password is shown next to the domain name." Thing is, the .csv file attached contained not only a list of all the domains affected, but also every new password.

It's unclear how many customers have been affected by the blunder, as Heart Internet has been somewhat shy about discussing it.

According to one Reg reader who asked to remain anonymous, Heart Internet re-sent the email about one hour later, this time with only his new password in the attachment. Stable doors and horses seem apposite.

Nottingham-based Heart Internet was founded by Jonathan Brealey and Tim Beresford, who also set up and flogged major UK hosting players WebFusion and 123-Reg.

The firm's bosses have not returned any of half a dozen calls from El Reg. We can't imagine why. ®

Seven Steps to Software Security

More from The Register

next story
Major problems beset UK ISP filth filters: But it's OK, nobody uses them
It's almost as though pr0n was actually rather popular
Google Nest, ARM, Samsung pull out Thread to strangle ZigBee
But there's a flaw in Google's IP-based IoT system
Orange spent weekend spamming customers with TXTs
Zero, not infinity, is the Magic Number customers want
US freemium mobile network eyes up Europe
FreedomPop touts 'free' calls, texts and data
Apple orders huge MOUNTAIN of 80 MILLION 'Air' iPhone 6s
Bigger, harder trouser bulges foretold for fanbois
'Two-speed internet' storm turns FCC.gov into zero-speed website
Deadline for comments on net neutrality shake-up extended to Friday
Oh girl, you jus' didn't: Level 3 slaps Verizon in Netflix throttle blowup
Just hook us up to more 10Gbps ports, backbone biz yells in tit-for-tat spat
Want to beat Verizon's slow Netflix? Get a VPN
Exec finds stream speed climbs when smuggled out
prev story

Whitepapers

Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.