Jump to content

Oops! Mozilla left thousands of email addresses and passwords lying around (again)

RainfallWithin

Original article by Graham Cluley on hotforsecurity.com: http://www.hotforsecurity.com/blog/oops-mozilla-left-thousands-of-email-addresses-and-passwords-lying-around-again-10013.html

 

For second time in a month, Mozilla – famous for the Firefox web browser – has had to warn that thousands of email addresses and passwords were left lying around on a server that the public could easily access.
 
At the beginning of August members of the Mozilla developer community were warned that approximately 76,000 email addresses and 4,000 encrypted passwords had been left on a publicly accessible server for 30 days.
 
<EDIT: Text has been cut to shorten the article>
 
Because Mozilla announced this week a second accidental disclosure of email addresses and encrypted passwords – this time affecting roughly 97,000 users.
 
Not only is that more people than were affected by the previous incident, but also the data was exposed for a longer period of time – three months.
 
In this case, the 97,000 users affected were testers of early builds of the Bugzilla bug tracking software, and information became exposed during a server migration.
 
"One of our developers discovered that, starting on about May 4th, 2014, for a period of around 3 months, during the migration of our testing server for test builds of the Bugzilla software, database dump files containing email addresses and encrypted passwords of roughly 97,000 users of the test build were posted on a publicly accessible server. As soon as we became aware, the database dump files were removed from the server immediately, and we’ve modified the testing process to not require database dumps."

It’s not known, of course, that anyone with malicious intent has accessed the leaked databases. But if they had, even if they weren’t able to decrypt the (hopefully stored as salted hashes) passwords, criminals might be able to cause trouble.
 
For instance, tens of thousands of email addresses are useful for spammers and fraudsters who might use them to launch malicious campaigns, or attempt to phish information from users in carefully-crafted attacks.
 
The Mozilla Foundation is pinning its hopes on its testers not having used the same passwords as ones they might not use elsewhere on the net.
 
"Generally, developers who use our test builds have told us they understand that these builds are insecure and may break, so they do not use passwords they would reuse elsewhere."

I do hope that Mozilla is right about that. Because I think it’s human nature to be lazy and sloppy, and I can easily imagine that many people (even the technical dudes who have accounts on the Bugzilla testing server) might easily make the mistake of reusing passwords.
 
Mozilla says it is “deeply sorry for any inconvenience” and has informed users who are affected by the disclosure, advising them to change “any similar passwords that they might be using.”
 

<EDIT: Text has been cut to shorten the article>

 

Personal Thoughts

It appears that Mozilla have found this issue after searching for more security problems after discovering a mistake early in August 2014. To clarify, this only affected testers of early builds of the Bugzilla bug tracking software.

 

This topic was well explained by Luke on 5th September 2014 WAN Show: http://youtu.be/it5bE6cPz6U?t=29m23s

Link to comment
Share on other sites

Link to post
Share on other sites

WHAT?!?!?!?!?!

 

 

 

I'M SWITCHING TO CHROME RIGHT FUCKING NOW

 

 

edit: chrome is garbage :( heeeeeeeeeeeeelp

 

 

 

 

ps: was waterfox affected? because I'd like to use that instead of this POS called chrome

 

 

edit: and the problems start...

JZJelZw.jpg

BGbsfYc.jpg

Link to comment
Share on other sites

Link to post
Share on other sites

At least they didn't leave the stove on...or did they? DUN DUN DUN

"How hard can it be?" - Jeremy Clarkson

"Speed has never killed anyone. Suddenly becoming stationary, that's what gets you." - Jeremy Clarkson

 

"There's an old saying that God exists in your search for him. I just want you to understand that I ain't looking." - Leslie Nielsen

 

Link to comment
Share on other sites

Link to post
Share on other sites

WHAT?!?!?!?!?!

 

 

 

I'M SWITCHING TO CHROME RIGHT FUCKING NOW

 

 

edit: chrome is garbage :( heeeeeeeeeeeeelp

 

 

 

 

ps: was waterfox affected? because I'd like to use that instead of this POS called chrome

Opera is pretty good.

Link to comment
Share on other sites

Link to post
Share on other sites

Opera is pretty good.

Slick keeps ranting about how bad it is though?

Link to comment
Share on other sites

Link to post
Share on other sites

I give firefox one chance to win me back over.. One chance.. And this happens xD

====>The car thread<====>Dark Souls thread<====>Placeholder<====
"Life is like a raging river, Its gonna get rough downstream. And people's gonna piss in it" 

"Who discovered we could get milk from cows, and what did he THINK he was doing at the time?"

Link to comment
Share on other sites

Link to post
Share on other sites

edit: chrome is garbage :( heeeeeeeeeeeeelp

No its not. You just don't know how to use it.

NEW PC build: Blank Heaven   minimalist white and black PC     Old S340 build log "White Heaven"        The "LIGHTCANON" flashlight build log        Project AntiRoll (prototype)        Custom speaker project

Spoiler

Ryzen 3950X | AMD Vega Frontier Edition | ASUS X570 Pro WS | Corsair Vengeance LPX 64GB | NZXT H500 | Seasonic Prime Fanless TX-700 | Custom loop | Coolermaster SK630 White | Logitech MX Master 2S | Samsung 980 Pro 1TB + 970 Pro 512GB | Samsung 58" 4k TV | Scarlett 2i4 | 2x AT2020

 

Link to comment
Share on other sites

Link to post
Share on other sites

As a chrome user I must say...

 

Nelson_Ha-Ha.jpg

Intel 4790k | Asus Z97 Maximus VII Impact | Corsair Vengeance Pro Series 16 GB 1866Mhz | Asus Strix GTX 980 | CoolerMaster G550 |Samsung Evo 250GB | Synology DS215j (NAS) | Logitech G502 |

 

Link to comment
Share on other sites

Link to post
Share on other sites

ps: was waterfox affected? because I'd like to use that instead of this POS called chrome

I give firefox one chance to win me back over.. One chance.. And this happens xD

I'm sorry, who here actually READ THE POST? These were users of their beta bug tracking software, not people using their browser.

 

No its not. You just don't know how to use it.

 

You edited your post. Before it was this: "No its not. It's your PC that is garbage."

Christ, you're arrogant. Did you look at his profile? The dude has a 3570K with 16GB of RAM and an HD 7970. You'll edit that now and switch to a different attack.

 

Chrome is nothing special. They introduced literally nothing special with it, they just forked WebKit and added a simple UI. 

"You have got to be the biggest asshole on this forum..."

-GingerbreadPK

sudo rm -rf /

Link to comment
Share on other sites

Link to post
Share on other sites

 

Enjoy your safari ;)

NEW PC build: Blank Heaven   minimalist white and black PC     Old S340 build log "White Heaven"        The "LIGHTCANON" flashlight build log        Project AntiRoll (prototype)        Custom speaker project

Spoiler

Ryzen 3950X | AMD Vega Frontier Edition | ASUS X570 Pro WS | Corsair Vengeance LPX 64GB | NZXT H500 | Seasonic Prime Fanless TX-700 | Custom loop | Coolermaster SK630 White | Logitech MX Master 2S | Samsung 980 Pro 1TB + 970 Pro 512GB | Samsung 58" 4k TV | Scarlett 2i4 | 2x AT2020

 

Link to comment
Share on other sites

Link to post
Share on other sites

Enjoy your safari ;)

Uses the exact same rendering engine as Chrome. THE EXACT SAME!

"You have got to be the biggest asshole on this forum..."

-GingerbreadPK

sudo rm -rf /

Link to comment
Share on other sites

Link to post
Share on other sites

updated my post

I see. It seems like an issue with your graphics card...

I would try deactivating hardware acceleration in your chrome settings. That should fix it.

NEW PC build: Blank Heaven   minimalist white and black PC     Old S340 build log "White Heaven"        The "LIGHTCANON" flashlight build log        Project AntiRoll (prototype)        Custom speaker project

Spoiler

Ryzen 3950X | AMD Vega Frontier Edition | ASUS X570 Pro WS | Corsair Vengeance LPX 64GB | NZXT H500 | Seasonic Prime Fanless TX-700 | Custom loop | Coolermaster SK630 White | Logitech MX Master 2S | Samsung 980 Pro 1TB + 970 Pro 512GB | Samsung 58" 4k TV | Scarlett 2i4 | 2x AT2020

 

Link to comment
Share on other sites

Link to post
Share on other sites

I'm sorry, who here actually READ THE POST? These were users of their beta bug tracking software, not people using their browser.

 

I read the post. It's just that i did not hear anything about any major mistakes on their end.. Until i installed it and started using it.. And now this popped up xD 

====>The car thread<====>Dark Souls thread<====>Placeholder<====
"Life is like a raging river, Its gonna get rough downstream. And people's gonna piss in it" 

"Who discovered we could get milk from cows, and what did he THINK he was doing at the time?"

Link to comment
Share on other sites

Link to post
Share on other sites

Uses the exact same rendering engine as Chrome. THE EXACT SAME!

Then why do the benchmarks look different?

browser-performance-test-google-chrome-m

NEW PC build: Blank Heaven   minimalist white and black PC     Old S340 build log "White Heaven"        The "LIGHTCANON" flashlight build log        Project AntiRoll (prototype)        Custom speaker project

Spoiler

Ryzen 3950X | AMD Vega Frontier Edition | ASUS X570 Pro WS | Corsair Vengeance LPX 64GB | NZXT H500 | Seasonic Prime Fanless TX-700 | Custom loop | Coolermaster SK630 White | Logitech MX Master 2S | Samsung 980 Pro 1TB + 970 Pro 512GB | Samsung 58" 4k TV | Scarlett 2i4 | 2x AT2020

 

Link to comment
Share on other sites

Link to post
Share on other sites

Uses the exact same rendering engine as Chrome. THE EXACT SAME!

My god, you get defensive quickly when it comes to Apple.

Link to comment
Share on other sites

Link to post
Share on other sites

Lets face it all the browsers are really shit. All I want is a browser that is simple and does everything I need it to which isn't much other than HTML5 support and thats it. I really hate using Chrome but I am so integrated into it.

 (\__/)

 (='.'=)

(")_(")  GTX 1070 5820K 500GB Samsung EVO SSD 1TB WD Green 16GB of RAM Corsair 540 Air Black EVGA Supernova 750W Gold  Logitech G502 Fiio E10 Wharfedale Diamond 220 Yamaha A-S501 Lian Li Fan Controller NHD-15 KBTalking Keyboard

Link to comment
Share on other sites

Link to post
Share on other sites

Slick keeps ranting about how bad it is though?

 

It's actually a very good browser!

phanteks enthoo pro | intel i5 4690k | noctua nh-d14 | msi z97 gaming 5 | 16gb crucial ballistix tactical | msi gtx970 4G OC  | adata sp900

Link to comment
Share on other sites

Link to post
Share on other sites

Then why do the benchmarks look different?

That benchmark is ancient. That's Safari 4 and Chrome 10. What kind of scheme are you trying to pull?

 

My god, you get defensive quickly when it comes to Apple.

No, I get defensive when people are wrong. Enderman is very often wrong so I get very defensive around him.

"You have got to be the biggest asshole on this forum..."

-GingerbreadPK

sudo rm -rf /

Link to comment
Share on other sites

Link to post
Share on other sites

"In this case, the 97,000 users affected were testers of early builds of the Bugzilla bug tracking software"

 

nobody ever fucking reads...

 

Uses the exact same rendering engine as Chrome. THE EXACT SAME!

 

No it does not. Safari uses WebKit, Chrome uses Blink which  while derived from WebKit is different.

 

 

The stone cannot know why the chisel cleaves it; the iron cannot know why the fire scorches it. When thy life is cleft and scorched, when death and despair leap at thee, beat not thy breast and curse thy evil fate, but thank the Builder for the trials that shape thee.
Link to comment
Share on other sites

Link to post
Share on other sites

No, I get defensive when people are wrong. Enderman is very often wrong so I get very defensive around him.

Holy crap you seriously need to grow up. We don't need people like you on this forum saying "i'm always right and you're always wrong"

You always start arguments when there is no need to. Please just stop derailing threads for no reason.

 

@Builder PS maybe you need glasses... that's safari 5 and chrome 12... lol fail

NEW PC build: Blank Heaven   minimalist white and black PC     Old S340 build log "White Heaven"        The "LIGHTCANON" flashlight build log        Project AntiRoll (prototype)        Custom speaker project

Spoiler

Ryzen 3950X | AMD Vega Frontier Edition | ASUS X570 Pro WS | Corsair Vengeance LPX 64GB | NZXT H500 | Seasonic Prime Fanless TX-700 | Custom loop | Coolermaster SK630 White | Logitech MX Master 2S | Samsung 980 Pro 1TB + 970 Pro 512GB | Samsung 58" 4k TV | Scarlett 2i4 | 2x AT2020

 

Link to comment
Share on other sites

Link to post
Share on other sites

My god, you get defensive quickly when it comes to Apple.

He's like that. He told me (huge summary here) to go buy a console if I only use my PC for gaming.

Someone told Luke and Linus at CES 2017 to "Unban the legend known as Jerakl" and that's about all I've got going for me. (It didn't work)

 

Link to comment
Share on other sites

Link to post
Share on other sites

That benchmark is ancient. That's Safari 4 and Chrome 10. What kind of scheme are you trying to pull?

 

No, I get defensive when people are wrong. Enderman is very often wrong so I get very defensive around him.

 

 

Holy crap you seriously need to grow up. We don't need people like you on this forum saying "i'm always right and you're always wrong"

You always start arguments when there is no need to. Please just stop derailing threads for no reason.

Everyone calm your tits please

 

Spoiler

i5 4670k, GTX 970, 12GB 1600, 120GB SSD, 240GB SDD, 1TB HDD, CM Storm Quickfire TK, G502, VG248QE, ATH M40x, Fractal R4

Spoiler

i5 4278U, Intel Iris Graphics, 8GB 1600, 128GB SSD, 2560x1600 IPS display, Mid-2014 Model

Spoiler

All the parts are here, just need to get customized cords to connect the motherboard to the front panel.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×