BreachExchange mailing list archives

An Update on Consumerist Security


From: security curmudgeon <jericho () attrition org>
Date: Tue, 17 Jul 2012 13:07:17 -0500 (CDT)


http://consumerist.com/2012/07/an-update-on-consumerist-security.html


AN UPDATE ON CONSUMERIST SECURITY
July 16, 2012 11:00 PM
Short URL: http://con.st/10100655

As described in yesterday's post, the Consumerist has been dealing with 
security issues that forced us to take the site down twice in the past 
week. Since the last episode ended Saturday night, we have taken certain 
steps that we believe address the problems we experienced.

Because of the nature of the investigation, we cannot . at this time . 
share further details of the specific changes. But we do want you to know 
of two actions we will be taking in the next few days that may affect your 
experience on the site:

***First, we plan to reset all existing passwords. This means that those 
of you who use log-in access at the Consumerist will need to choose a new 
password when you log into the site. We will be sending you an email 
summarizing the same actions described in this post.

***Second, we plan to re-open the Consumerist to comments. As noted 
yesterday, we turned off commenting as part of our initial response to the 
latest security incident.

[..]
_______________________________________________
Dataloss Mailing List (dataloss () datalossdb org)
Archived at http://seclists.org/dataloss/
Unsubscribe at http://datalossdb.org/mailing_list

Supporters:

Risk Based Security (http://www.riskbasedsecurity.com/)
Risk Based Security equips organizations with security intelligence, risk
management services and on-demand security solutions to establish
customized risk-based programs to address information security and
compliance challenges. 

Tenable Network Security (http://www.tenable.com/)
Tenable Network Security provides a suite of solutions which unify real-time
vulnerability, event and compliance monitoring into a single, role-based, interface
for administrators, auditors and risk managers to evaluate, communicate and
report needed information for effective decision making and systems management.


Current thread: