RockYou explains how a hacker stole 32 million passwords — and what it’s doing about it
Social app maker
RockYou confirmed today that it is notifying millions of its users that their usernames and passwords may have been compromised by a hacker who broke into the company’s older applications known as widgets.
In an exclusive interview, RockYou chief technology officer Jia Shen said the company was notified of the SQL injection attack against RockYou.com last week by officials at security firm Imperva. Shen said RockYou shut down the site for its legacy applications — such as slide show widgets — and secured them.
That process took about a day. Then the company began poring through its databases to find any evidence of attack. Shen said the company doesn’t know exactly what the hacker did in the attack. The company is in contact with law enforcement but isn’t saying more.
“But we are assuming the worst,” Shen said. “We checked the activity and it looked like it had been going on a couple of days before we were warned.”
In fact, a hacker posted some of the passwords and usernames that were allegedly stolen. Shen confirmed that those were legitimate passwords from RockYou’s databases, but he does not know exactly how many were stolen. Shen emphasized that RockYou’s current Facebook applications and its ad network were not attacked and are not vulnerable to the same kind of attack. The widgets were RockYou’s main business before it switched to becoming a Facebook app developer.
“We worked on our widgets for a long time and the code base predates the Facebook platform,” Shen said. “We are taking a lot of flak. But I want to make it clear that nothing outside of the RockYou widgets were impacted.”
Nevertheless, Shen said the impact could be serious. For instance, if users keep the same usernames and passwords for every site they use, including their online bank accounts, they could be vulnerable to identity theft.
One user told us some time ago that RockYou was vulnerable to attack, as were other sites. Shen said he did not get warnings about the risk of an SQL injection attack against the widgets before.
“We started off as a small company and today we have a different engineering structure,” he said. “But shame on us. If you make a mistake, then people can get in and it is a big hole.”
Shen acknowledged that the passwords and usernames were stored in a database that was not encrypted, another no-no when it comes to security. That is why the hacker was able to get access to the passwords. The company has begun notifying users but has not finished yet because the process takes a long time. Shen acknowledged the company did not say anything publicly for 10 days, but he said they were busy notifying users and partners during that time.
The company is telling users to change their passwords on the RockYou site and on any other sites where they’ve used the same username or password.
“Locking down everything is complete,” Shen said. “Our security approach in the future will have to be deeper.”
-  การทํา cut down,  การทำ cut down,  capital commitment+ภาระผูกพัน, 
No comments yet.
No trackbacks yet.
LG Cookie PEP Price | LG GD510 Touch Screen Mobile
about 1 week ago - No comments
You must have noticed the new advertisements of LG Cookie Pep starring stars like John, Genelia and Abhay. This new phone from LG is making quite a buzz among the cellphone buyers lately. LG Cookie Pep GD510 is affordable full touchscreen mobile phone, targeted @ young customers and offers combined social media applications and widget [...]
Nokia C5 social smartphone announced
about 2 weeks ago - 1 comment
Nokia today unveiled its first phone from the Cseries family | the Nokia C5. Announced as “a smartphone optimized for social networking and sharing”, you could see Facebook status updates directly from the phonebook.
The C5 candybar measuring over 12mm thin and 46mm across (and 112mm high), packs 2.2 inch QVGA display, S60 3rd edition, HSDPA, [...]
Samsung Caliber (SCH-r860) latest phone with a touch screen available at MetroPCS
about 2 weeks ago - No comments
MetroPCS recently brought new Samsung Caliber (SCH-r860) latest phone with a touch screen for USD250 (no contract required). The Caliber packs3.2″ WQVGA, 262K TFT touchscreen display, TouchWiz interface, full fledged HTML browser, Customizable Widgets, GPS, integrated social networks (Facebook and MySpace), email , advanced voice recognition, 3.0 megapixel camera with flash, MP3 player, Bluetooth, and [...]
Tiger Wood’s Apology VIDEO and Transcript
about 4 weeks ago - No comments
Tiger Woods issued his first public apology for “irresponsible and selfish behavior” standing at the U.S. PGA Tour in Ponte Vedra Beach, Florida on Friday. During the official statement Tiger woods vigorously defended his wife Elin. Here’s the full video from Tiger Woods’ press conference apology:
Good morning, and thank you for joining me. Many [...]
1920 Depression
about 1 month ago - No comments
A lot has been written, talked and compared between the current financial scenario and the 1920 depression. The initial leg down of every crash developing fear that an absolute financial fall down was impending, only to be prevented by colossal liquidity fueling expectation and sanguinity, at least for a petite time. If time gone by [...]
Facebook VP of Product Cox steels employees for redesign reaction
about 1 month ago - No comments
Facebook rolled out a new redesign to 80 million users tonight at its 6th birthday party, and the company’s vice president of product just prepped employees for potential negative reactions by telling the story of the original news feed launch.
After the new features went live, the company showed off streams of real-time reactions to the [...]
Facebook launches Games Dashboard for millions of gamers
about 1 month ago - No comments
With its big redesign, Facebook is rolling out its Games Dashboard for millions of game players today.
“The Games Dashboard will give game applications greater prominence with placement on the home page,” the company said in a blog post today. “While making it even easier for users to have a personalized and social gaming experience. The [...]
Live-blog | A rundown on Facebook’s new redesign
about 1 month ago - No comments
Facebook is rolling out a new redesign live to 80 million users tonight. We’re here at Facebook’s offices with Peter Deng, a product manager, who is explaining the changes.
The left-hand navigation bar of the social network site has been beefed up with a new dashboard for application and games. In the gaming section, Facebook credits [...]
Facebook overhauls search as it crosses 400 million users
about 1 month ago - No comments
On its sixth birthday, Facebook launched a host of new features as it crossed the 400-million user mark.
The most interesting of them may be its revamped search. When you type in names, it auto-completes for people who are the closest to you by social promixity — e.g. the people you share the most mutual friends [...]
Adobe CTO defends Flash
about 1 month ago - No comments
The lack of support for Flash-format media on Apple’s iPad has caused a fresh round of debate about the technology’s value, including a bunch of posts from Flash owner Adobe. The latest is a post from Chief Technology Officer Kevin Lynch laying out his case for Flash’s relevance.
Lynch begins by taking a couple of small [...]





