Showing posts with label retail. Show all posts
Showing posts with label retail. Show all posts

Saturday, January 5, 2019

Woesnotgone Meadow; December 10 2018

Woesnotgone Meadow
December 10, 2018
#

All is relatively well here at Woesnotgone Meadow, where everyone has above average bandwidth.

The Meadow has a number of people who enjoy asking questions about the various topics seen across the news channels. These persons are not much for introspection. These topics could be focused on technology, farming, or the new coffee crop.
As the residents ask each other these questions, there is also another source for the back and forth question and answer questions.
Quora, the knowledge sharing website, experienced a minor issue this year. Quora was founded in 2009 by two former Facebook employees and is located in Mountain View, CA.
Compromise
The compromise was manifested by the unauthorized access to one of the Quora systems, discovered on November 30, 2018. There is not a mass amount of information regarding the attack vector or method for others to learn from. Only the general actions were noted. Quora has noted their teams believe they have found the root cause for the breach, and allegedly have taken the appropriate steps to address the issue. The investigation though is still on-going.
Affected Users
This was not a small, incidental compromise. This affected approximately 100M of the Quora users. To remediate this, the company logged out the potentially affected users. Quora also contracted with a leading digital forensics and security firm to assist them with the investigation.
Data Exfiltrated
The attackers were able to secure data from Quora for their uses. This included the name, email address, encrypted password, and user imported data from the linked websites. These were expected to be Facebook and Twitter. The attackers also were able to secure details on the user’s non-anonymous activities on Quora (e.g. questions, answers, and up- and down-votes). Although this data was stolen, most of the data would have been accessible publicly.
As noted, the passwords were encrypted. Seemingly, this would be the perfect situation. Quora however did not detail the format of the encrypted passwords. This could have been weak. These could have been hashed instead, however, this could have been weak or without being salted.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest version.

Resources
Acharya, B. (2018, December 3). Quora says 100 million users hit by security breach. Retrieved from https://www.reuters.com/article/us-quora-cyber/quora-says-100-million-users-hit-by-security-breach

Tuesday, August 21, 2018

Adidas Issues: Breaches Abound

Most people have seen or are aware of the Adidas brand of shoes, clothing, and other products. These are sold in retail establishments and online. Recently Adidas had the opportunity to experience the excitement of a breach with their online venture.

An unauthorized party accessed the Adidas servers. This was unknown to Adidas until they were notified by a third party. The data was exfiltrated on June 26, 2018. This data included the user’s contact information, usernames, and encrypted passwords. Fortunately for the users, their credit card details and health-oriented data was stored elsewhere. With any breach, the vector and method could, in theory, take many forms. In this case, the method is unknown. To understand how this happened, Adidas is working with a security firm and law enforcement.

The affected parties were the Adidas customers purchasing products on the adidas.com/US website. This has affected literally millions of people.

One open question involves the InfoSec in place at Adidas. Seemingly, the security team, the SIEM, or something would have noticed the mass amount of data for millions of clients leaving the organization. Adidas had to learn of this from a third party. Also, the logs would have indicated, unless modified by the attackers, that this area was accessed by a party that was not authorized. There are these and many other questions re: the breach, which hopefully will be answered in the upcoming weeks.

Looking forward, the enterprise should have some form of a monitoring device or staff in place to review anomalies, unusual access, etc. This would have hopefully been able to note there was an issue and begin to limit the damage.

Resources
Adidas. (2018, June 18). Adidas alerts certain consumers of potential data security incident. Retrieved from https://www.adidas-group.com/en/media/news-archive/press-releases/2018/adidas-alerts-certain-consumers-potential-data-security-incident/

Gibson, K. (2018, June 28). Adidas data-security breach could involve “a few million customers”. Retrieved from https://www.cbsnews.com/news/adidas-security-breach-could-involve-a-few-million-customers/

Green, A. (2018, June 1). Adidas website hacked, changes your passwords now. Retrieved from https://www.komando.com/happening-now/468214/adidas-website-hacked-change-your-password-now

Humphries, M. (2018, June 29). Adidas website hacked, millions of US customer details stolen. Retrieved from https://www.pcmag.com/news/362173/adidas-website-hacked-millions-of-us-customer-details-stolen

Jones, R. (2018, June 29). Adidas warns customers of website hack. Retrieved from https://solecollector.com/news/2018/06/adidas-website-hack

Murdoch, J. (2018, June 29). Adidas hack: ‘Millions’ of U.S. website customers warned of cyber theft. Retrieved from http://www.newsweek.com/adidas-breach-hack-us-website-customers-warned-their-data-has-been-hacked-1000974

Sepe, R. (2018, June 29). Adidas US website hit by data breach. Retrieved from https://www.darkreading.com/cloud/adidas-us-website-hit-by-data-breach/d/d-id/1332186