Ranter
Join devRant
Do all the things like
++ or -- rants, post your own rants, comment on others' rants and build your customized dev avatar
Sign Up
Pipeless API
From the creators of devRant, Pipeless lets you power real-time personalized recommendations and activity feeds using a simple API
Learn More
Comments
-
PappyHans61312dThey have to notify all parties involved. Clock is ticking. Big hit in customer trust and possibly hefty fine coming their way
-
Public key authentification should be handled by the browser imo. Just send a token
-
wojtek322113712d@PappyHans For sure. It's an EU company and not a multinational. I hope they play by the rules.
-
wojtek322113712d@antigermanist Their product does not use HTTP or HTTPS but a whole different protocol. I'm not sure how their authentication is done for their devices. Maybe their admin platform that probably uses HTTPS has been hacked. I have no idea about how it happened (yet).
-
@wojtek322 I mean it's good for you somehow but also scary no? You better beef up your opsec just in case.
-
wojtek322113712d@antigermanist We have also detected hacking attempts earlier this week but my colleagues have determined that their attempt was not successfull.
Since we are a direct competitor of them, i assume they have been hacked by the same party and on a very similar way like they attacked us. -
AlgoRythm5024011dWHY did they have passwords stored?? With practices like that, it was only a matter of time.
-
PappyHans61311dHope they have their user passwords hashed and not in plain text when stored. Mind boggling in this day and age there is still companies storing passwords in plain text. How hard it is to use bcrypt
-
wojtek322113711d@AlgoRythm Unsure, that is what the COO told us. He got that email forwarded so not sure if he was exaggerating or really the case (hashed or not). Maybe the password manager was compromised or an exploit was found to bypass the authentication. IDK at this point. They have not yet made a public statement.
Related Rants
Our biggest competitor has just been hacked. All their sensitive data, including passwords and client data, has been compromised.
It is not yet in the news, but someone forwarded their internal communication to us. :D
(fixed mistranslation)
rant
hack