Yes this is a real email from Carbonite. We urge all of our customers to change their passwords as soon as they can.
This
action is being taken proactively and at this time there is no evidence
to indicate that your account or data have been compromised. Your
backups are safe and your regular backup schedule will continue.
|
What Happened
|
As
part of ongoing security monitoring, Carbonite recently became aware of
unauthorized attempts to access a number of Carbonite accounts. This
activity appears to be the result of a third party attacker using
compromised email addresses and passwords obtained from other companies
that were previously attacked. The attackers then tried to use the
stolen information to access Carbonite accounts. Based on our security
reviews, there is no evidence to suggest that Carbonite has been hacked
or compromised.
|
What Information Was Involved
|
While Carbonite will continue to monitor and investigate the matter, we have
determined that some usernames and passwords are involved. Additionally,
for some accounts, other personal information may have been exposed.
|
What Carbonite Is Doing
|
Use
the link that Carbonite emailed to you to reset your password. We highly recommend using
"strong" unique passwords for Carbonite and all online accounts. If you use the same or similar passwords on other online services, we
recommend that you set new passwords on those accounts as well.
|
Based in the historic downtown area of Plymouth, MA, IES is a web design / hosting, computer / IT support, and marketing consulting firm for small to large business, including government & nonprofits. We also sell & service POS equipment, smart systems, CCTV systems, and custom wifi service. IES operates globally via the latest technology.
Showing posts with label unsecure passwords. Show all posts
Showing posts with label unsecure passwords. Show all posts
Wednesday, June 22, 2016
Carbonite blasts an email for all users to reset their password.
Labels:
Carbonite,
Carbonite attack,
Carbonite hack,
Carbonite password,
cyber,
cyber attack,
password,
passwords,
unsecure passwords
Tuesday, January 19, 2016
The list is in! Here are the top 25 most common / dumbest passwords used in 2015.
People are still using really bad passwords to secure online accounts, despite constant advice to the contrary. As reported by Engadget, SplashData has revealed its list of the worst passwords of 2015, drawn from the 2 million passwords that leaked last year.
This year’s list is very similar to last year’s list:
As these passwords all belonged to accounts that were hacked or otherwise compromised, these are essentially the most popular bad passwords. Suffice to say anyone who wants to stay safe online should avoid using these under any and all circumstances.
Source: Engadget
This year’s list is very similar to last year’s list:
- 123456
- password
- 12345678
- qwerty
- 12345
- 123456789
- football
- 1234
- 1234567
- baseball
- welcome
- 1234567890
- abc123
- 111111
- 1qaz2wsx
- dragon
- master
- monkey
- letmein
- login
- princess
- qwertyuiop
- solo
- passw0rd
- starwars
As these passwords all belonged to accounts that were hacked or otherwise compromised, these are essentially the most popular bad passwords. Suffice to say anyone who wants to stay safe online should avoid using these under any and all circumstances.
Source: Engadget
Labels:
#hack,
bad password,
bad passwords,
choose a password,
funny passwords,
good passwords,
hack,
hacked,
password,
passwords,
secure password,
starwars,
unsecure passwords
Wednesday, April 16, 2014
A tip for a much stronger password.
Use a passphrase: a sentence you can remember. Then replace
each word of the phrase with its initial, a similar digit or symbol, or,
at random, use a whole word.
For example: My Dad Bob Yelled At My Idiot Brother
m d b y @ m ! b
The new password is mdby@m!b.
That may still be tough to remember. If you need to, write a reminder and hide the paper somewhere safe. But write the phrase or a hint, not the password.
Generally, if you have a strong password, you don't need to change it unless you suspect you've been hacked. But don't use the same one for different services.
For example: My Dad Bob Yelled At My Idiot Brother
m d b y @ m ! b
The new password is mdby@m!b.
That may still be tough to remember. If you need to, write a reminder and hide the paper somewhere safe. But write the phrase or a hint, not the password.
Generally, if you have a strong password, you don't need to change it unless you suspect you've been hacked. But don't use the same one for different services.
Labels:
hack,
password,
password hint,
passwords,
secure password,
strong password,
unsecure passwords
Thursday, November 14, 2013
Facebook temporarily disables profiles as it grapples with 150 million hacked Adobe passwords.
Facebook is asking millions of people to change their passwords if
they had an account with Adobe, the content creation and cloud marketing
company. Adobe was hacked recently and up to 150 million passwords were
exposed.
Facebook is taking those exposed passwords and searching its system to find users who may have used the same password for Facebook. Those people will be asked to change their passwords.
The password crisis was triggered because Adobe apparently used only one encryption key for all its stored customer passwords, according to Krebs On Security:
What’s more, experts say Adobe appears to have used a single encryption key to scramble all of the leaked user credentials, meaning that anyone who computes, guesses or acquires the decryption key immediately gets access to all the passwords in the database.
The Adobe password hack is causing a huge headache all across the web. At first, it seemed that just a few million passwords had been stolen. But then that estimate increased to 38 million. And Krebs said the total universe of compromised passwords could be as high as 150 million.
So Amazon, Diapers.com and Microsoft are struggling with the same issue: The Adobe password cache is so massive that there are likely multiple millions of users with accounts at other companies who used identical passwords. Because the hackers can match passwords to IDs (email for instance), anyone who used the same password at Adobe for any other online company is now potentially screwed.
Facebook is taking those exposed passwords and searching its system to find users who may have used the same password for Facebook. Those people will be asked to change their passwords.
The password crisis was triggered because Adobe apparently used only one encryption key for all its stored customer passwords, according to Krebs On Security:
What’s more, experts say Adobe appears to have used a single encryption key to scramble all of the leaked user credentials, meaning that anyone who computes, guesses or acquires the decryption key immediately gets access to all the passwords in the database.
The Adobe password hack is causing a huge headache all across the web. At first, it seemed that just a few million passwords had been stolen. But then that estimate increased to 38 million. And Krebs said the total universe of compromised passwords could be as high as 150 million.
So Amazon, Diapers.com and Microsoft are struggling with the same issue: The Adobe password cache is so massive that there are likely multiple millions of users with accounts at other companies who used identical passwords. Because the hackers can match passwords to IDs (email for instance), anyone who used the same password at Adobe for any other online company is now potentially screwed.
Source: Business Insider
Subscribe to:
Posts (Atom)
