Spread Firefox outage and privacy breach notice

Αναδημοσιεύσεις άρθρων και συζητήσεις με θέμα την τεχνολογία.
Post Reply
User avatar
Einherjar
Venus Project Founder
Venus Project Founder
Posts: 3751
Joined: Tue Jan 27, 2004 4:42 pm
Academic status: Alumnus/a
Gender:
Location: Washington DC, USA
Contact:

Spread Firefox outage and privacy breach notice

Post by Einherjar » Sun Jul 17, 2005 8:23 pm

Παραθέτω ένα mail μου μου ήρθε ως μέλος του spreadfirefox.com
On Tuesday, July 12, the Mozilla Foundation discovered that the server hosting Spread Firefox, our community marketing site, had been accessed on Sunday, July 10 by unknown remote attackers who exploited a security vulnerability in the software running the site. This exploit was limited to SpreadFirefox.com and did not affect other mozilla.org web sites or Mozilla software.

We don't have any evidence that the attackers obtained personal information about site users, and we believe they accessed the machine to use it to send spam. However, it is possible that the attackers acquired information site users provided to the site.

As a Spread Firefox user, you have provided us with a username and password. You may also have provided us with other information, including a real name, a URL, an email address, IM names, a street address, a birthday, and private messages to other users.

We recommend that you change your Spread Firefox password and the password of any accounts where you use the same password as your Spread Firefox account. To change your Spread Firefox password, go to SpreadFirefox.com, log in with your current password, select "My Account" from the sidebar, select "Edit Account" from the sidebar, then enter your new password into the Password fields and press the "Save user information" button at the bottom of the page.

The Mozilla Foundation deeply regrets this incident and is taking steps to prevent it from happening again. We have applied the necessary security fixes to the software running the site, have reviewed our security plan to determine why we didn't previously apply those fixes in this case, and have modified that plan to ensure we do so in the future.

Sincerely,
The Mozilla Foundation
και λέω εγώ τώρα:
  1. δεν είχαν κρυπτογραφημένες τις αποθηκευμένες πληροφορίες και ειδικά τα passwords?
  2. γιατί να μην είχαν περασμένα τα τελευταία security fixes?
...λέω εγώ τώρα!
[Better to understand a little than to misunderstand a lot]
User avatar
vangos
Mbyte level
Mbyte level
Posts: 571
Joined: Tue Mar 16, 2004 3:14 pm
Location: Heracleia@UTA

Post by vangos » Sun Jul 17, 2005 10:20 pm

Δεν στέλνεις καλύτερα ένα email να τους τα πεις προσωπικά; Αν και νομίζω ότι θα το έχουν κάνει πολλοί άλλοι. ;)
User avatar
rapadder
Gbyte level
Gbyte level
Posts: 1897
Joined: Thu Jun 17, 2004 7:12 pm
Academic status: Alumnus/a
Gender:

Post by rapadder » Mon Jul 18, 2005 12:01 am

Και μετά σου λένε να χρησιμοποιείς το FireFox και όχι τον Internet Explorer :smt077.
... Γράφτε κώδικα όσο είναι καιρός ...
User avatar
mikem4600
Gbyte level
Gbyte level
Posts: 1363
Joined: Fri Mar 12, 2004 2:00 pm
Academic status: Alumnus/a
Gender:
Location: A Galaxy Far, Far Away
Contact:

Post by mikem4600 » Mon Jul 18, 2005 1:48 am

...για να μην μιλήσουμε για το φιάσκο με τις μεταφρασμένες εκδόσεις του Firefox 1.0.5 (ή το γεγονός ότι αλλάζουν stable APIs)... ;)

http://www.mozillazine.org/talkback.html?article=6950

Γενικά καλό είναι το Mozilla Foundation... Αυτές τις γκάφες μόνο να μην έκανε...
Autocracy hates questions. Anarchy hates answers.
Post Reply

Return to “Τεχνολογικά Νέα”