Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

bananas

(27,509 posts)
Sun Aug 23, 2015, 05:41 PM Aug 2015

'Security Was An Afterthought,' Hacked Ashley Madison Emails Show

Source: Motherboard

It's already clear that, despite handling very sensitive data, Ashley Madison did not have the best security. Hackers managed to obtain everything from source code to customer data to internal documents, and the attackers behind the breach, who call themselves the Impact Team, made a mockery of the company's defenses in an interview.

With a huge dump of the company's emails now available on the dark web, it's possible to get a better idea of what was really going through the minds of those responsible for the site's security, and overall it doesn't look good. Ashley Madison seems to have put a heavy emphasis on PR spin, rather than protecting data.

“With what we inherited with Ashley [Madison], security was an obvious afterthought and I didn't focus on it either,” the company's founding CTO Raja Bhatia wrote at the beginning of 2012. “I am pretty sure we stored passwords without any cryptography so a database leak would expose all account credentials,” he continued. The email was in response to the news that the data of 100,000 Grindr users had been obtained by hackers.

Bhatia was also fully aware of the potential of attacks on Avid Life Media (ALM), the parent company of Ashley Madison. “There will be an eventual security crisis amongst one of your properties and the media will leap on it as they always do,” he wrote.

<snip>

Read more: http://motherboard.vice.com/en_ca/read/security-was-an-afterthought-hacked-ashley-madison-emails-show

9 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
'Security Was An Afterthought,' Hacked Ashley Madison Emails Show (Original Post) bananas Aug 2015 OP
Let the lawsuits begin... n/t PoliticAverse Aug 2015 #1
Isn't it Hillary's fault they were hacked? DURHAM D Aug 2015 #2
It is? I'd better alertthe media! Elmer S. E. Dump Aug 2015 #7
more a 'homeland security' BIG FAILURE for the 10,000 DOTgov persons using gov computers. Sunlei Aug 2015 #3
Good Lord. Erich Bloodaxe BSN Aug 2015 #4
It's crazy how big this is. SansACause Aug 2015 #5
Real people are often hurt by the consequences of their own choices and actions. LanternWaste Aug 2015 #8
I expect more of these types of hacks to occur YoungDemCA Aug 2015 #6
"Security was an afterthought." Psephos Aug 2015 #9

Sunlei

(22,651 posts)
3. more a 'homeland security' BIG FAILURE for the 10,000 DOTgov persons using gov computers.
Sun Aug 23, 2015, 06:18 PM
Aug 2015

our homeland security costs billions and they don't even notice what government computers are used for.

Erich Bloodaxe BSN

(14,733 posts)
4. Good Lord.
Sun Aug 23, 2015, 06:20 PM
Aug 2015

I worked for a tiny startup for a decade, and we encrypted from day 1. Hell, we even used a custom encryption scheme before we ran things through the standard encryption protocols. So if anyone HAD unencrypted our stuff, it STILL would have looked like garbage chars. And the database was behind a couple of levels of firewalls and another machine. You would have had to hack all those first, just to get near the data, then have figured out the passwords on the database itself as well once you'd hacked the database server.

And none of us were really security pros, we just did our homework, and made sure we complied with industry practices for safekeeping hardware and software touching credit card info, and paid a security firm for the quarterly scans done to make sure we hadn't left any holes open.

AM had the money, they could have had REAL security folks onstaff.

SansACause

(520 posts)
5. It's crazy how big this is.
Sun Aug 23, 2015, 07:09 PM
Aug 2015

I was at a party yesterday of maybe 20 people, and this morning I looked at the AM dump that's out there, and five people who were at that party are directly impacted by this. It's ugly. What Impact Team did was not heroic. Real people are getting hurt by this. Running everyone's dirty laundry up a flagpole is nothing admirable.

 

LanternWaste

(37,748 posts)
8. Real people are often hurt by the consequences of their own choices and actions.
Mon Aug 24, 2015, 09:58 AM
Aug 2015

"Real people are getting hurt by this..."

Real people are often hurt by the negative consequences of their own choices and their own actions. Blaming anyone else for those actions and choices is simply a rationalization.

Latest Discussions»Latest Breaking News»'Security Was An Aftertho...