Yes this is a real email from Carbonite. We urge all of our customers to change their passwords as soon as they can.
This
action is being taken proactively and at this time there is no evidence
to indicate that your account or data have been compromised. Your
backups are safe and your regular backup schedule will continue.
|
What Happened
|
As
part of ongoing security monitoring, Carbonite recently became aware of
unauthorized attempts to access a number of Carbonite accounts. This
activity appears to be the result of a third party attacker using
compromised email addresses and passwords obtained from other companies
that were previously attacked. The attackers then tried to use the
stolen information to access Carbonite accounts. Based on our security
reviews, there is no evidence to suggest that Carbonite has been hacked
or compromised.
|
What Information Was Involved
|
While Carbonite will continue to monitor and investigate the matter, we have
determined that some usernames and passwords are involved. Additionally,
for some accounts, other personal information may have been exposed.
|
What Carbonite Is Doing
|
Use
the link that Carbonite emailed to you to reset your password. We highly recommend using
"strong" unique passwords for Carbonite and all online accounts. If you use the same or similar passwords on other online services, we
recommend that you set new passwords on those accounts as well.
|
Based in the historic downtown area of Plymouth, MA, IES is a web design / hosting, computer / IT support, and marketing consulting firm for small to large business, including government & nonprofits. We also sell & service POS equipment, smart systems, CCTV systems, and custom wifi service. IES operates globally via the latest technology.
Showing posts with label passwords. Show all posts
Showing posts with label passwords. Show all posts
Wednesday, June 22, 2016
Carbonite blasts an email for all users to reset their password.
Labels:
Carbonite,
Carbonite attack,
Carbonite hack,
Carbonite password,
cyber,
cyber attack,
password,
passwords,
unsecure passwords
Tuesday, January 19, 2016
The list is in! Here are the top 25 most common / dumbest passwords used in 2015.
People are still using really bad passwords to secure online accounts, despite constant advice to the contrary. As reported by Engadget, SplashData has revealed its list of the worst passwords of 2015, drawn from the 2 million passwords that leaked last year.
This year’s list is very similar to last year’s list:
As these passwords all belonged to accounts that were hacked or otherwise compromised, these are essentially the most popular bad passwords. Suffice to say anyone who wants to stay safe online should avoid using these under any and all circumstances.
Source: Engadget
This year’s list is very similar to last year’s list:
- 123456
- password
- 12345678
- qwerty
- 12345
- 123456789
- football
- 1234
- 1234567
- baseball
- welcome
- 1234567890
- abc123
- 111111
- 1qaz2wsx
- dragon
- master
- monkey
- letmein
- login
- princess
- qwertyuiop
- solo
- passw0rd
- starwars
As these passwords all belonged to accounts that were hacked or otherwise compromised, these are essentially the most popular bad passwords. Suffice to say anyone who wants to stay safe online should avoid using these under any and all circumstances.
Source: Engadget
Labels:
#hack,
bad password,
bad passwords,
choose a password,
funny passwords,
good passwords,
hack,
hacked,
password,
passwords,
secure password,
starwars,
unsecure passwords
Wednesday, April 16, 2014
A tip for a much stronger password.
Use a passphrase: a sentence you can remember. Then replace
each word of the phrase with its initial, a similar digit or symbol, or,
at random, use a whole word.
For example: My Dad Bob Yelled At My Idiot Brother
m d b y @ m ! b
The new password is mdby@m!b.
That may still be tough to remember. If you need to, write a reminder and hide the paper somewhere safe. But write the phrase or a hint, not the password.
Generally, if you have a strong password, you don't need to change it unless you suspect you've been hacked. But don't use the same one for different services.
For example: My Dad Bob Yelled At My Idiot Brother
m d b y @ m ! b
The new password is mdby@m!b.
That may still be tough to remember. If you need to, write a reminder and hide the paper somewhere safe. But write the phrase or a hint, not the password.
Generally, if you have a strong password, you don't need to change it unless you suspect you've been hacked. But don't use the same one for different services.
Labels:
hack,
password,
password hint,
passwords,
secure password,
strong password,
unsecure passwords
Wednesday, August 7, 2013
Do you save passwords in Google Chrome? Maybe you should reconsider...
You might want to think twice before you let someone borrow your computer.
The most obvious risk of allowing someone else access to your desktop is that they can impersonate you, using any app where you’re already signed in. They could send prank messages using your default email client, or profess your undying love for Justin Bieber using your logged-in Twitter account.
That’s annoying, but far from fatal.
But the situation becomes considerably worse if you use Google Chrome to save and sync passwords for easy logins at your favorite websites. An intruder who has unrestricted access to your computer for even a minute can view and copy all of your saved passwords just by visiting an easy-to-remember settings page: chrome://settings/passwords.
That link opens the local copy of your saved password cache, which is synchronized to every machine where you sign in with your Google account.
And the funny thing is, anyone who visits that page can see the plaintext version of every saved password just by clicking a button.
The saved password list shows the web address, username, and password for each saved set of credentials. Initially, the saved password is displayed as a row of asterisks. But if you click the masked password, you see a “Show” button that you can click to immediately display the saved password.
A malicious or spiteful intruder who can lure you away from your computer briefly can see your saved passwords, then close the settings page. And you have no idea that your credentials have been compromised.
Source: ZD Net
The most obvious risk of allowing someone else access to your desktop is that they can impersonate you, using any app where you’re already signed in. They could send prank messages using your default email client, or profess your undying love for Justin Bieber using your logged-in Twitter account.
That’s annoying, but far from fatal.
But the situation becomes considerably worse if you use Google Chrome to save and sync passwords for easy logins at your favorite websites. An intruder who has unrestricted access to your computer for even a minute can view and copy all of your saved passwords just by visiting an easy-to-remember settings page: chrome://settings/passwords.
That link opens the local copy of your saved password cache, which is synchronized to every machine where you sign in with your Google account.
And the funny thing is, anyone who visits that page can see the plaintext version of every saved password just by clicking a button.
The saved password list shows the web address, username, and password for each saved set of credentials. Initially, the saved password is displayed as a row of asterisks. But if you click the masked password, you see a “Show” button that you can click to immediately display the saved password.
A malicious or spiteful intruder who can lure you away from your computer briefly can see your saved passwords, then close the settings page. And you have no idea that your credentials have been compromised.
Source: ZD Net
Labels:
Chrome,
computer security,
Google,
Google Chrome,
online security,
password security,
passwords,
security
Subscribe to:
Posts (Atom)