Feeds

Bitly shortens life of users' passwords after credential compromise

OAuth tentacles mean it's time to change ANOTHER password

Internet Security Threat Report 2014

URL-shortening and online marketing outfit Bit.ly has warned its systems have been accessed by parties unknown and suggested users change their passwords.

In an advisory visible here, the service says "We have reason to believe that Bitly account credentials have been compromised" but that "We have no indication at this time that any accounts have been accessed without permission." The company also swears it has "... already taken proactive measures to secure all paths that led to the compromise and ensure the security of all account credentials going forward."

Don't get too comfortable, though. Bit.ly encourages users to employ OAuth to link their accounts with Facebook and Twitter. The outfit has severed those links to stop account hijacking.

Long story short? It's time to change passwords and even if you can't recall signing up for Bit.ly it may be worth checking to see if you ever linked your social media accounts to the service. OAuth makes it stupidly easy to make such links, and also stupidly easy to forget you ever did so ... until p0wnage like this prods your memory. ®

Remote control for virtualized desktops

More from The Register

next story
UK smart meters arrive in 2020. Hackers have ALREADY found a flaw
Energy summit bods warned of free energy bonanza
DRUPAL-OPCALYPSE! Devs say best assume your CMS is owned
SQLi hole was hit hard, fast, and before most admins knew it needed patching
Feds seek potential 'second Snowden' gov doc leaker – report
Hang on, Ed wasn't here when we compiled THIS document
Mozilla releases geolocating WiFi sniffer for Android
As if the civilians who never change access point passwords will ever opt out of this one
Why weasel words might not work for Whisper
CEO suspends editor but privacy questions remain
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Top 5 reasons to deploy VMware with Tegile
Data demand and the rise of virtualization is challenging IT teams to deliver storage performance, scalability and capacity that can keep up, while maximizing efficiency.
Protecting against web application threats using SSL
SSL encryption can protect server‐to‐server communications, client devices, cloud resources, and other endpoints in order to help prevent the risk of data loss and losing customer trust.