It seems that you're using an outdated browser. Some things may not work as they should (or don't work at all).
We suggest you upgrade newer and better browser like: Chrome, Firefox, Internet Explorer or Opera

×
Sheesh does this mean I am going to another bunch of online casino spam in my spambox
lol kickstarter finally got kicked
Kickstarter sent me an email about the breach 4 and a half hours ago. I wonder what's taking them so long to notify everyone.
avatar
Nirth: While it doesn't help the fact they handle their security poorly I will still recommend password managers because it's easy to track unique passwords so they can't access anything else if find one plus it's dead easy to change them, nothing new to remember too.
I agree with the password manager, and I will add that if you go this route and use a password gen, be sure to back up the data base (preferably on something like a flash drive, which has added bonuses if you use portable programs such as KeePass if you tend to bounce around from one machine to another).

My two cents.
avatar
Darvond: Why does nobody seem to bother with server security until they get hit?
Selling the database to the highest spam bidder whilst blaming it on a hacker attack? I never understood why would a hacker bother getting into trouble and always leave the credit card data section untouched...
Thanks for the incoming spam, Kickstarter :-P
Not sure what the implications could be for the rest of my personal info.

And in typical Kickstarter fashion of keeping anything unpleasant or negative away from the public eye and selectively present only what they want from their POV (which usually is just template PR stuff), they have disabled the comments on that blog entry.

I (finally) dismissed Kickstarter a year ago for a number of reasons, but if I hadn't, this would have definitely been enough reason to do so now. For all their boasting about their growth and financial success, they sure have a very poor security level and conscience, they didn't even noticed the bridge themselves - I assume that if law enforcement officials tracked it down and alerted them, then it's serious business (who the hackers and their intentions are).


avatar
Momo1991: Because they're lying on their PCI DSS questionnaires cause actually doing what it really requires to keep data safe is expensive.
All more reason to make the on-site data security assessment mandatory when personal info and transactions data are stored.


avatar
nadenitza: Selling the database to the highest spam bidder whilst blaming it on a hacker attack? I never understood why would a hacker bother getting into trouble and always leave the credit card data section untouched...
But then, we only have Kickstarter CEO's word that credit card data was not stolen, i.e. the word of a company that had to be alerted that they had been hacked (according to their own statement again).
This was so frustrating. Of course Kickstarter is saying nothing important was hacked:

http://www.zdnet.com/kickstarter-hacked-change-your-password-now-7000026388/

I hope it's not like the Target hacking in December, where the swore nothing was compromised and then
having to back-pedal when more information breaches came out.