Feeds

A-DOH!-BE hack: Facebook warns users whose logins were spilled

Change up... bitch

Beginner's guide to SSL certificates

Facebook is using a list of hacked Adobe accounts posted by the miscreants themselves to warn its own customers about password reuse.

The social network mined data leaked as the result of the recent breach at Adobe in an effort to provide timely warnings and prompt its users to secure their accounts. Facebook users who used the same email and password combinations on Adobe are required to both change their password and answer additional security questions, investigative reporter Brian Krebs reports.

A screenshot of the warning can be found here.

Facebook spokesman Jay Nancarrow told Krebs that the social network has responded in a similar manner to other high-profile breaches. “We actively look for situations where the accounts of people who use Facebook could be at risk - even if the threat is external to our service,” Nancarrow explained.

Facebook representative Chris Long explained the process to El Reg.

"I work at Facebook on the security team that helped protect the accounts affected by the Adobe breach," Long explained in an email. "Brian’s comment above is essentially spot on. We used the plaintext passwords that had already been worked out by researchers. We took those recovered plaintext passwords and ran them through the same code that we use to check your password at login time.

"Like Brian’s story indicates, we’re proactive about finding sources of compromised passwords on the internet. Through practice, we’ve become more efficient and effective at protecting accounts with credentials that have been leaked, and we use an automated process for securing those accounts."

Anatomy of a car wreck

It's well known in the information security world that password re-use is rife and a major problem because any breach at one online service provider potentially exposes accounts held by the same people at other service providers. It's child play for crooks to try leaked credentials on other (possibly more sensitive sites). Facebook is not saying how many of its users are getting the login credentials re-use warning.

Adobe original said hackers had stolen nearly three million customer credit card records, as well as undetermined volume of user accounts login credentials. The software firm later admitted that the encrypted account data of 38 million users had leaked.

But when a dump of the offending customer database appeared online it contained not online just 38 million, but 150 million credentials. Leaked information includes internal ID, user name, email, encrypted password and password hints.

That alone would be bad enough but Adobe compounded the problem by failing to follow industry best practices about only stored passwords credentials as properly salted hashes.

In particular, Adobe erred in using a single encryption key to encrypt user credentials, as explained in some depth by security veteran Paul Ducklin in a post on Sophos's Naked Security blog. Security researchers have figured out a substantial proportion of the leaked user passwords using a variety of inferences, such as leaked data from other large password breaches.

For example, security researcher Jeremi Gosney of the Stricture Group came across the purloined passwords on one of several online dumps before analysing them to see which passwords are most-used by Adobe customers.

The resulting list of the top 100 most commonly used passwords in the Adobe dump is full of FAIL. "123456" and (of course) "password" are in the top three of the rest are hardly any better.

Gosney worked out that a whopping 1.9 million of Adobe's customers use the string “123456” as their password. We can only hope that the majority of such users didn't reuse these passwords elsewhere on more sensitive sites, such as e-banking, social networking and webmail. It could be that some people who didn't really care about their Adobe account were more careful elsewhere. ®

Protecting users from Firesheep and other Sidejacking attacks with SSL

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
China hacked US Army transport orgs TWENTY TIMES in ONE YEAR
FBI et al knew of nine hacks - but didn't tell TRANSCOM
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Protecting users from Firesheep and other Sidejacking attacks with SSL
Discussing the vulnerabilities inherent in Wi-Fi networks, and how using TLS/SSL for your entire site will assure security.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.