<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ClickPopMedia &#187; Security</title>
	<atom:link href="http://www.clickpopmedia.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.clickpopmedia.com</link>
	<description>ClickPopMedia is a great little design and illustration firm.</description>
	<lastBuildDate>Thu, 03 Dec 2009 17:28:23 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Mozilla Store got hacked?  Don&#8217;t let it happen to you.</title>
		<link>http://www.clickpopmedia.com/2009/08/05/mozilla-store-got-hacked-dont-let-it-happen-to-you/</link>
		<comments>http://www.clickpopmedia.com/2009/08/05/mozilla-store-got-hacked-dont-let-it-happen-to-you/#comments</comments>
		<pubDate>Wed, 05 Aug 2009 22:16:05 +0000</pubDate>
		<dc:creator>Sean</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Sean]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.clickpopmedia.com/?p=512</guid>
		<description><![CDATA[Unfortunately I have been extremely busy and have been neglecting some of my things which I wanted to do on this here site, primarily my authentication system.  Not too long ago I wrote a post on password security and storage.  I have become very security conscious in the past couple years, staying on top [...]]]></description>
			<content:encoded><![CDATA[<p>Unfortunately I have been extremely busy and have been neglecting some of my things which I wanted to do on this here site, primarily my authentication system.  Not too long ago I wrote a post on <a title="Password information storage and security" href="http://www.clickpopmedia.com/2009/03/26/password-information-storage-and-security/">password security and storage</a>.  I have become very security conscious in the past couple years, staying on top of ways to secure data stored in databases, primarily securing passwords and other sensitive material.  I voiced my opinion that sites should NEVER store passwords in an unencrypted fashion (plain text) or even a form of encryption that is easily undone.  I know this can be a pain in the butt, but unfortunately it&#8217;s a necessity now days to secure your client&#8217;s data.  Today I received an email from the Mozilla Store, warning me that their site had been hacked.  Allow me to share this email with you. (I have highlighted the scariest part in red)</p>
<blockquote><p>
August 05, 2009</p>
<p>Dear Valued Mozilla Customer:</p>
<p>It has been brought to our attention that the Mozilla Store www.store.mozilla.org has had a security breach. We take all security breaches very seriously, and are working hard to determine the extent of the violation. In the meantime, the site has been taken down as a protective measure.  </p>
<p><span style="color: #ff0000;"><strong>At this time we do not believe any credit card information has been compromised.  However, some Mozilla Store customers&#8217; user names and passwords have been exposed.  It is our strong recommendation that all Mozilla Store customers proactively change their user name and passwords for their Mozilla Store account and all other accounts that use the same information.</strong></span>  We will not bring the site back up until we are confident that we have addressed all security issues. A notification will be sent to you when the site goes back up.</p>
<p>GatewayCDI apologizes for any inconvenience this may cause.  We value our customers and their online security is a top priority to our organization.</p>
<p>Sincerely,</p>
<p>Conrad Franey<br />
Chief Marketing Officer<br />
GatewayCDI
</p></blockquote>
<p>There are 3 major things I&#8217;d like to discuss about this.  The first is the obvious, if they had used safe storage techniques; the probability of their password list being compromised would have been practically eliminated.  I cannot stress that enough, if a password is in the database as plain text, it will be compromised, I know that means you can&#8217;t just send a user their password when they forget, but that&#8217;s ok&#8230; it&#8217;s not a huge hassle to change a password.  The second topic is users that &#8220;use the same information&#8221;.  Granted, most of us are guilty of this at some point or another.  We all have favorite passwords that we like to use.  I personally try to make classifications of passwords for different types of sites, but sometimes I find myself using a &#8220;default&#8221; password out of habit.   Please, people, one of the best ways you can protect yourself on the internet is to use different passwords.  If not for everything, don&#8217;t use the same password for sites like facebook, myspace, or twitter that you would use for your bank or email account.  The third MAJOR topic that I feel needs to be discussed is in regard to that first sentence that&#8217;s highlighted in red.  &#8220;At this time we do not believe any credit card information has been compromised.&#8221;  This should not even be a fear.  Under no circumstances should you store your credit card on any sites database, and under no circumstance should any site store it without your asking.  After a transaction is completed, the only thing that should remain is the authorization number, order number, and the last 4 digits of the card.  That is all the bank and the company should EVER need to look up a transaction.  Verifying identity using a credit card number is a terrible thing, and any company that does so should be avoided.  I am hoping that the reason they do not believe any credit card #s were stolen is because they don&#8217;t store them&#8230; but only time will tell.</p>
<p>Ok, enough ranting and raving from me.  I have spoken my mind on this topic, now I will shut up and let you all get back to your days.  Just remember, sites do not always practice safe storage procedures, so the best protection from identity theft is still your common sense, so use it!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.clickpopmedia.com/2009/08/05/mozilla-store-got-hacked-dont-let-it-happen-to-you/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

