Categories: SecurityWorkspace

Hackers Steal Kickstarter Passwords

Crowdfunding service Kickstarter has told its users to change their passwords, after a breach saw protected logins compromised.

Kickstarter was alerted to the hack by law enforcement on Wednesday and discovered two customer accounts had been tampered with but no credit card information had been accessed.

Usernames, email addresses, mailing addresses, phone numbers and encrypted passwords were compromised, however.

Kickstarter sorry

“We’re incredibly sorry that this happened. We set a very high bar for how we serve our community, and this incident is frustrating and upsetting,” Kickstarter CEO Yancey Strickler wrote in a blog post.

“We have since improved our security procedures and systems in numerous ways, and we will continue to do so in the weeks and months to come. We are working closely with law enforcement, and we are doing everything in our power to prevent this from happening again.”

Older passwords were salted with SHA-1 multiple times, the firm said, whilst more recent passwords were hashed with bcrypt, which should stand up better to brute force attacks.

Troy Hunt, web security expert and Microsoft Most Valued Professional, said he was impressed by Kickstarter’s response to the breach.

“I think they’re handled it very well… very early communication, very clear about what they know and also very remorseful without trying to throw blame,” Hunt told TechWeekEurope.

“Also, sharing the hashing implementations was a very transparent move, question is whether they were ‘sufficient’.”

Yet Hunt said “the only safe assumption at the moment is that someone has everyone’s passwords”.

Online crooks have become increasingly adept at cracking encrypted passwords, largely because the tools they use get better with each breach, as they learn patterns of people’s password choices.

Are you a security expert? Try our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

View Comments

Recent Posts

Tesla Shares Surge On China Advanced Self-Driving Push

Tesla makes key advances toward advanced self-driving rollout in China as chief Elon Musk meets…

2 hours ago

UK Law Aims To Boost Security For ‘Smart’ Devices

New UK rules bring in basic security requirements for millions of internet-connected devices, aiming to…

4 hours ago

Alphabet Value Surges Over $2tn On Dividend Plan

Google parent Alphabet sees market capitalisation surge over $2tn on plan to over first-ever cash…

10 hours ago

Google Asks US Court To Dismiss Federal Adtech Case

Google asks Virginia federal court to dismiss case brought by US Justice Department and eight…

10 hours ago

Snap Sees Surge In Users, Ad Revenues

Snapchat parent Snap reports user growth, revenues in spite of tough competition, in what may…

11 hours ago

Shein Subject To Most Stringent EU Digital Rules

Quick-growing fast-fashion company Shein must comply with most stringent level of EU digital rules after…

11 hours ago